Consultation of the Data Protection Officer in the DPIA Process, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 35(2).
Assessment Step
1
Consultation of the Data Protection Officer in the DPIA Process (ConsultationoftheDataProtectionOfficerintheDPIAProcess)
When conducting a data protection impact assessment, does the entity seek the advice of its data protection officer, where one has been designated?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Consultation of the Data Protection Officer in the DPIA Process
The data controller must seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
Citation
GDPR
Art. 35(2), Recital 84
|