Prior Consultation with the Supervisory Authority When Necessary, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 35(9).

Assessment Step

1
Prior Consultation with the Supervisory Authority When Necessary (PriorConsultationwiththeSupervisoryAuthorityWhenNecessary)
If a data protection impact assessment indicates that the processing would result in a high risk in the absence of mitigating measures, does the entity consult the supervisory authority prior to commencing the processing?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Prior Consultation with the Supervisory Authority When Necessary
The data controller must consult the supervisory authority prior to processing if a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken to mitigate the risk.
Citation
GDPR
Art. 35(9), Recital 94