CASE STUDY
Please use the following to answer the next question:
A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.
All of the following are obligations of the company as a data controller when implementing its AI system EXCEPT?
- Ensuring that third-party processors are based in the same country as the company.
- Allowing data subject access requests (DSARs).
- Implementing technical and organizational measures.
- Conducting a Data Protection Impact Assessment (DPIA) / Privacy Impact Assessment (PIA).
Answer(s): A
Explanation:
While the company must ensure data protection compliance, it is not required that third-party processors be located in the same country; instead, adequate data protection measures and legal safeguards must be in place.
Show Answer Next Question