Consultation of the Data Protection Officer in the DPIA Process, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 35(2).

Assessment Step

1
Consultation of the Data Protection Officer in the DPIA Process (ConsultationoftheDataProtectionOfficerintheDPIAProcess)
When conducting a data protection impact assessment, does the entity seek the advice of its data protection officer, where one has been designated?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Consultation of the Data Protection Officer in the DPIA Process
The data controller must seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
Citation
GDPR
Art. 35(2), Recital 84