DSP-09: Is a data protection impact assessment (DPIA) conducted when processing personal
data and evaluating the origin, nature, particularity, and severity of risks according
to any applicable laws, regulations and industry best practices?
Data protection impact assessment, which is essentially risk assessment from a privacy perspective, should be performed by the data controller before processing if such personal data processing is likely to result in a high risk to the rights and freedoms of natural persons.
Control implemented
Control ownership
Description
Conduct a Data Protection Impact Assessment (DPIA) to evaluate the
origin, nature, particularity and severity of the risks upon the processing
of personal data, according to any applicable laws, regulations and industry
best practices.