Prior Consultation with the Supervisory Authority When Necessary, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 35(9).
Assessment Step
1
Prior Consultation with the Supervisory Authority When Necessary (PriorConsultationwiththeSupervisoryAuthorityWhenNecessary)
If a data protection impact assessment indicates that the processing would result in a high risk in the absence of mitigating measures, does the entity consult the supervisory authority prior to commencing the processing?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Prior Consultation with the Supervisory Authority When Necessary
The data controller must consult the supervisory authority prior to processing if a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken to mitigate the risk.
Citation
GDPR
Art. 35(9), Recital 94
|