EvidenceSheet

Art.35 Data protection impact assessment

Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural p

5
artefacts
0
held by a system
4
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • Completed assessments checked against the four minimum content elements Article 35(7) requires · Document repository
  • The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval · Document repository
  • Where the views of data subjects were sought, the record of what was asked and what came back, or the reasoning for not seeking them · Document repository
  • Review records showing assessments were revisited when the processing or its risk changed, with the date and the trigger · Document repository

governing documentDocuments that govern the control

  • The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones · HR system / LMS

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

Art.34 Communication of a personal data breach to the data subject · Art.36 Prior consultation