Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP Exam CIPM Topic 2 Question 75 Discussion

Actual exam question for IAPP's CIPM exam
Question #: 75
Topic #: 2
[All CIPM Questions]

The first step an organization should take when considering the use of a third-party's AI-based resume ranking tool is to?

Show Suggested Answer Hide Answer
Suggested Answer: D

Under the General Data Protection Regulation (GDPR), the obligations of a processor that engages a sub-processor are to obtain the consent of the controller and ensure the sub-processor complies with data processing obligations that are equivalent to those that apply to the processor. The GDPR defines a processor as a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. A sub-processor is a third party that is engaged by the processor to carry out specific processing activities on behalf of the controller. The GDPR requires that the processor does not engage another processor without prior specific or general written authorization of the controller. In the case of general written authorization, the processor must inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes. The processor must also ensure that the same data protection obligations as set out in the contract or other legal act between the controller and the processor are imposed on that other processor by way of a contract or other legal act under Union or Member State law, .Reference:[GDPR Article 28], [CIPM - International Association of Privacy Professionals]


Contribute your Thoughts:

Lauran
2 days ago
But we also need to consider privacy and regulation, so conducting an assessment is crucial.
upvoted 0 times
...
Melodie
2 days ago
I think B is the correct answer. Assessing the tool's impact on privacy and AI regulations is crucial before implementation.
upvoted 0 times
...
Oneida
5 days ago
I agree with Jess, it's important to make sure the tool meets the organization's requirements.
upvoted 0 times
...
Jess
7 days ago
I think the first step should be to secure stakeholder buy-in.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77