Performance of a DPIA Prior to High-Risk Processing, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 35(1).
Assessment Step
1
Performance of a DPIA Prior to High-Risk Processing (PerformanceofaDPIAPriortoHigh-RiskProcessing)
Before initiating any type of processing that is likely to result in a high risk to the rights and freedoms of natural persons, and especially when using new technologies, does the entity carry out a data protection impact assessment that takes into account the nature, scope, context, and purposes of the processing?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Performance of a DPIA Prior to High-Risk Processing
The data controller must carry out a data protection impact assessment before initiating any type of processing that is likely to result in a high risk to the rights and freedoms of natural persons, taking into account the nature, scope, context, and purposes of the processing, especially when using new technologies.
Citation
GDPR
Art. 35(1), Recital 84, 90
|