Question 1 of 11
Your project involves collecting personal data from customers in the European Union. A team member suggests skipping a privacy impact assessment to save time. What should you do?
- A.Agree if the project timeline is at risk — compliance can be addressed post-launch
- B.Delegate the decision to the legal team and proceed with development
- C.Conduct the privacy impact assessment as required — regulatory compliance is non-negotiable
- D.Conduct a cost-benefit analysis to decide if the assessment is worth the time
Show answer and explanation
Correct answer: C
GDPR requires a Data Protection Impact Assessment (DPIA) for high-risk personal data processing. Regulatory compliance is not optional. Skipping exposes the organization to fines and reputational damage. Delegating to legal without pausing development creates risk. A cost-benefit analysis is inappropriate for mandatory legal obligations.