GDPR · the impact assessment
The impact assessment: due or not, and written
Three questions from Article 35(3) decide whether an assessment is due; the four elements of Article 35(7) are the assessment, written below with the point behind each, to copy or download.
Does one of the three named cases apply?
A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
1. Whether the assessment is due
Answer the three questions above; the reading follows, and the assessment below if one is due.
2. The assessment, element by element
The assessment shall contain at least: 0 of 4 elements written.
ISO 27701, StandardOS's reading: A.7.2.5, A.7.2.1
ISO 27701, StandardOS's reading: A.7.2.5, A.7.4.1
ISO 27701, StandardOS's reading: A.7.2.5
ISO 27701, StandardOS's reading: A.7.2.5, A.7.4.2
The document
# Data protection impact assessment Written on with the free page at getstandardos.com; the elements are Article 35(7) of Regulation (EU) 2016/679 as the Official Journal words them. ## 1. Whether the assessment is due Answer the three questions above; the reading follows, and the assessment below if one is due. ## 2. The assessment, element by element > The assessment shall contain at least: ### (a) a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller; Not stated. ISO 27701, StandardOS's reading: A.7.2.5, A.7.2.1 ### (b) an assessment of the necessity and proportionality of the processing operations in relation to the purposes; Not stated. ISO 27701, StandardOS's reading: A.7.2.5, A.7.4.1 ### (c) an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and Not stated. ISO 27701, StandardOS's reading: A.7.2.5 ### (d) the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned. Not stated. ISO 27701, StandardOS's reading: A.7.2.5, A.7.4.2 ## 3. Prior consultation Residual risk not yet assessed. Where appropriate, the controller seeks the views of data subjects or their representatives (Article 35(9)) and, where a data protection officer is designated, seeks the officer's advice (Article 35(2)). This is the assessment's frame, not legal advice. Generated by StandardOS.
One assessment per activity, reviewed when the risk changes
StandardOS keeps the assessment as a record on the processing activity it belongs to, with the measures of element (d) as the controls that evidence them and a review date, next to the record of processing and the breach clock.
The cases and elements are Article 35(3) and 35(7), read from the Official Journal, never typed on this page. The 'likely to result in a high risk' judgement of Article 35(1) and the supervisory authorities' lists under 35(4) are the company's own reading. This is a document, not legal advice.