Prior Consultation with the Supervisory Authority Based on DPIA Outcome, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 36(1).
Assessment Step
1
Prior Consultation with the Supervisory Authority Based on DPIA Outcome (PriorConsultationwiththeSupervisoryAuthorityBasedonDPIAOutcome)
When a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of mitigating measures, does the entity consult the supervisory authority before beginning the processing?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Prior Consultation with the Supervisory Authority Based on DPIA Outcome
The data controller must consult the supervisory authority prior to processing when a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the data controller to mitigate the risk.
Citation
GDPR
Art. 36(1), Recital 94
|