Art.35 Data protection impact assessment
Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural p
5
artefacts
0
held by a system
4
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Completed assessments checked against the four minimum content elements Article 35(7) requires · Document repository
- The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval · Document repository
- Where the views of data subjects were sought, the record of what was asked and what came back, or the reasoning for not seeking them · Document repository
- Review records showing assessments were revisited when the processing or its risk changed, with the date and the trigger · Document repository
governing documentDocuments that govern the control
- The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones · HR system / LMS
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out
- Necessity and proportionality asserted in a sentence, with all the substance of the assessment sitting in the security measures
- Risk assessed to the organisation rather than to the rights and freedoms of the individuals the processing affects
- Screening applied only to new projects, so material change to existing high risk processing never triggers an assessment
- The data protection officer asked to approve the assessment rather than to advise on it, which compromises the independence Article 38(3) requires
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetArt.34 Communication of a personal data breach to the data subject · Art.36 Prior consultation