Walkthroughs · 3.2

Run an impact assessment

A Data Protection Impact Assessment under Article 35, from scope to a frozen baseline.

When one is needed

Article 35 asks for an assessment where processing is likely to result in a high risk to people. Prudence raises this as a gap on activities that are in use, and does not block the activity from being in use while the assessment is prepared.

The assessment page of a processing activity, where screening and the assessment are recorded.
The assessment page of a processing activity, where screening and the assessment are recorded.

Steps

The assessment is guided in six stages. Scope is inherited from the processing activities in use, so you do not restate it.

  1. 01ScopeConfirm the processing activities the assessment covers. An assessment cannot be scoped to activities that are not in use.
  2. 02RisksIdentify the risks to the rights and freedoms of people, and match each one to the activities it arises from, or create it here.
  3. 03TreatmentFor each risk, state the measure that addresses it, the owner of that measure, the deadline, the evidence it will leave, the effect expected and the rating that remains. A risk rated high may not be carried untreated.
  4. 04ConsultationRecord the advice of the Data Protection Officer, the views of data subjects or the reason they were not sought, and any advice that was not followed with the justification.
  5. 05DecisionRecord the decision of the controller, who took it, the date, and the position on prior consultation with the supervisory authority under Article 36.
  6. 06BaselineFreeze the version. Later changes to the scoped activities are reported as drift against this baseline.
The treatment stage. Each risk is matched to measures, with an owner, a deadline, evidence and a residual rating.
The treatment stage. Each risk is matched to measures, with an owner, a deadline, evidence and a residual rating.