Question 1 of 30
\"GlobalTech Solutions,\" a multinational corporation headquartered in Germany, is implementing a new AI-powered HR analytics system to process employee data across its global offices. The system will collect and analyze sensitive employee data, including performance reviews, health records, and disciplinary actions, to optimize workforce management and identify potential skill gaps. Before the system is rolled out, the Chief Information Security Officer (CISO), Ingrid Schmidt, is evaluating the organization\'s obligations under ISO 27701:2019 and the GDPR.\n\nWhich of the following scenarios would most likely trigger the *mandatory* requirement for GlobalTech Solutions to conduct a Data Protection Impact Assessment (DPIA) *prior* to the system\'s implementation, according to ISO 27701:2019 and GDPR Article 35, even if no data breach has yet occurred?
The processing of sensitive employee data on a large scale using innovative AI technology, which is likely to result in a high risk to the rights and freedoms of natural persons.
The company has over 250 employees and processes personal data, thus automatically requiring a DPIA regardless of the nature of the processing.
A similar AI system implemented by a competitor resulted in a data breach affecting a small number of employees, suggesting a potential risk.
The organization is headquartered in Germany, and German law mandates DPIAs for all processing activities involving employee data, irrespective of the risk level.

Preparing for ISO 39001:2012 Internal Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free