CAS-004 Governance, Risk, and Compliance Practice Question
A global pharmaceutical company must comply with the EU GDPR for clinical trial data. The Data Protection Officer is reviewing the data protection impact assessment (DPIA) process. Which of the following situations requires a DPIA under GDPR?
⚠ Common exam trap
The trap here is assuming that any processing of personal data requires a DPIA, when in fact it is only required for high-risk processing involving special categories at scale or systematic monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting a clinical trial that involves large-scale processing of genetic data and health data.
A DPIA is mandatory under GDPR when processing is likely to result in a high risk to data subjects, particularly when it involves large-scale processing of special categories of data such as genetic and health data. Clinical trials often involve such data and are conducted on a large scale, making a DPIA a legal requirement. Other scenarios described are routine and low risk, so they do not trigger the mandatory DPIA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Collecting employee emergency contact information for HR records.
Why it's wrong here
Collecting emergency contact details is a routine HR activity with minimal privacy impact. It does not involve large-scale processing of special categories or systematic monitoring. The risk to data subjects is low, so a DPIA is not required. This is a common administrative process that falls outside the DPIA triggers.
- ✗
Processing personal data for routine patient billing using a standard software platform.
Why it's wrong here
Routine patient billing is a standard administrative activity that typically does not involve high risk to data subjects' rights and freedoms. It is unlikely to meet the GDPR's criteria for a DPIA, such as systematic monitoring, large-scale processing of special categories, or innovative technology. Therefore, a DPIA is not mandatory for this scenario.
- ✓
Conducting a clinical trial that involves large-scale processing of genetic data and health data.
Why this is correct
GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to data subjects, especially when using new technologies and processing special categories of data on a large scale. Clinical trials involving genetic and health data on a large scale clearly meet this threshold. Genetic data and health data are special categories under Article 9, and large-scale processing triggers the DPIA requirement.
- ✗
Using CCTV cameras in a single office lobby for physical security.
Why it's wrong here
While CCTV involves personal data, a single office lobby is not considered large-scale systematic monitoring. A DPIA might be advisable if the monitoring is extensive or covers public areas, but typically a small-scale installation does not mandate a DPIA. The GDPR's DPIA requirement targets high-risk processing, which this scenario does not clearly present.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.