GDPR: all pages

GDPR · the impact assessment

The impact assessment: due or not, and written

Three questions from Article 35(3) decide whether an assessment is due; the four elements of Article 35(7) are the assessment, written below with the point behind each, to copy or download.

Does one of the three named cases apply?

A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:

35(3)(a) a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
35(3)(b) processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
35(3)(c) a systematic monitoring of a publicly accessible area on a large scale.

1. Whether the assessment is due

Answer the three questions above; the reading follows, and the assessment below if one is due.

2. The assessment, element by element

The assessment shall contain at least: 0 of 4 elements written.

ISO 27701, StandardOS's reading: A.7.2.5, A.7.2.1

ISO 27701, StandardOS's reading: A.7.2.5, A.7.4.1

ISO 27701, StandardOS's reading: A.7.2.5

ISO 27701, StandardOS's reading: A.7.2.5, A.7.4.2

After the measures, does a high residual risk remain?

If the risks of element (c) are not brought down by the measures of element (d), Article 36(1) requires consultation of the supervisory authority before the processing starts.

The document

# Data protection impact assessment

Written on  with the free page at getstandardos.com; the elements are Article 35(7) of Regulation (EU) 2016/679 as the Official Journal words them.

## 1. Whether the assessment is due

Answer the three questions above; the reading follows, and the assessment below if one is due.

## 2. The assessment, element by element

> The assessment shall contain at least:

### (a) a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;

Not stated.

ISO 27701, StandardOS's reading: A.7.2.5, A.7.2.1

### (b) an assessment of the necessity and proportionality of the processing operations in relation to the purposes;

Not stated.

ISO 27701, StandardOS's reading: A.7.2.5, A.7.4.1

### (c) an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and

Not stated.

ISO 27701, StandardOS's reading: A.7.2.5

### (d) the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.

Not stated.

ISO 27701, StandardOS's reading: A.7.2.5, A.7.4.2

## 3. Prior consultation

Residual risk not yet assessed.

Where appropriate, the controller seeks the views of data subjects or their representatives (Article 35(9)) and, where a data protection officer is designated, seeks the officer's advice (Article 35(2)). This is the assessment's frame, not legal advice. Generated by StandardOS.

One assessment per activity, reviewed when the risk changes

StandardOS keeps the assessment as a record on the processing activity it belongs to, with the measures of element (d) as the controls that evidence them and a review date, next to the record of processing and the breach clock.

The cases and elements are Article 35(3) and 35(7), read from the Official Journal, never typed on this page. The 'likely to result in a high risk' judgement of Article 35(1) and the supervisory authorities' lists under 35(4) are the company's own reading. This is a document, not legal advice.