Prior Consultation with the Supervisory Authority Based on DPIA Outcome, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 36(1).

Assessment Step

1
Prior Consultation with the Supervisory Authority Based on DPIA Outcome (PriorConsultationwiththeSupervisoryAuthorityBasedonDPIAOutcome)
When a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of mitigating measures, does the entity consult the supervisory authority before beginning the processing?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Prior Consultation with the Supervisory Authority Based on DPIA Outcome
The data controller must consult the supervisory authority prior to processing when a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the data controller to mitigate the risk.
Citation
GDPR
Art. 36(1), Recital 94