Minimum Content Requirements for a DPIA, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 35(7).
Assessment Step
1
Minimum Content Requirements for a DPIA (MinimumContentRequirementsforaDPIA)
Does the entity's data protection impact assessment include: a systematic description of processing operations and purposes (including legitimate interest, if applicable); an assessment of necessity and proportionality; an assessment of risks to rights and freedoms; and the measures to address those risks and demonstrate compliance?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Minimum Content Requirements for a DPIA
The data controller must ensure that the data protection impact assessment includes at least the following elements: a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued; an assessment of the necessity and proportionality of the processing operations; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address the risks, including safeguards, security measures, and mechanisms to ensure protection of personal data and demonstrate compliance with the GDPR.
Citation
GDPR
Art. 35(7), Recital 90
|