Correct answer: B
The data inventory (ROPA under GDPR) must reflect all active processing activities. When a new SaaS system goes live, updating the ROPA is the first internal governance step, it captures the data category (IP addresses, clickstream), the lawful basis, the retention period, and the vendor as a processor. This update is required before the system processes live data, not retroactively. All downstream obligations (DPA execution, TIA if applicable, privacy-notice update) depend on the inventory accurately reflecting the new processing activity. Chapter 9 states the exam anchor: "When a new system goes live, the first artifact to update is the data inventory."
- AUpdating the external privacy notice may be required, but it is a disclosure obligation that flows downstream from the internal inventory and DPA. Updating the inventory comes first.
The CIPM guide explains every answer.