Short Reads

Countdown 8 weeks until GDPR : Will organizations be required to undertake Privacy Impact Assessments when conducting personal data processing?

Stibbe - Will organizations be required to undertake DPIA?

Countdown 8 weeks until GDPR : Will organizations be required to undertake Privacy Impact Assessments when conducting personal data processing?

29.03.2018 EU law

Only 8 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

Will organizations be required to undertake Privacy Impact Assessments when conducting any kind of personal data processing?

Privacy Impact Assessments or Data Protection Impact Assessments (“DPIA”) are only required in the exceptional situation in which the processing is likely to result in a high risk to the rights and freedoms of natural persons. Whether the processing entails such a high risk will depend on the presence of one or more of the following factors: automated decision-making, evaluation or scoring, systematic monitoring, sensitive data, scale of processing, vulnerable data subjects, data transfers outside the EU, etc. In particular, a DPIA will be required if the processing entails: (i) any systematic and extensive evaluation of personal aspects of natural persons based on automated processing or profiling upon which decisions are based; (ii) processing of so-called “sensitive” categories of personal data on a large scale; or (iii) a systematic monitoring of a publicly accessible area on a large scale. National supervisory authorities are moreover required to establish a list of the types of processing operations that require a DPIA, which is what Belgium has already done, for example.

Conversely, a DPIA is not required if the processing is not likely to result in a high risk. Moreover, other scenarios in which a DPIA is not required are (i) if a DPIA has already been carried out for very similar processing activities or (ii) if the processing has a legal basis under EU law or Member State law and a DPIA has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis. National supervisory authorities may also draw up a list of the kinds of processing operations for which no DPIA is required.

Furthermore, the Article 29 Working Party has clarified in the meantime that DPIAs are only required for processing operations that have been initiated after the GPDR applies effectively on 25 May 2018 or that change significantly after that date. In addition, it is recommended, thus not mandatory, to also carry out DPIAs for processing operations already underway prior to May 2018 if there is a change to the risk represented by the processing operation or if the organizational or societal context of the processing activity has changed.

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

26.02.2020 BE law
18 March 2020: Erik Valgaeren sheds a light on the legal perspectives of industrial data during a Beltug conference

Speaking slot - In this era of digitisation, data is often called the 'new gold' or 'oil'.  In our aim to gain more insights that will lead us to higher revenue, new market opportunities or new regions, we are analysing data at full throttle. But it needs to be handled with care, using a data architecture that follows your general strategy while ensuring solid security, quality, etc.

Read more

16.01.2020 BE law
24 January 2020: Carol Evrard participates in a panel session on Global Compliance at the CPDP conference in Brussels

Speaking slot - Stibbe is a long standing partner of the International Computers, Privacy and Data Protection Conference (CPDP) which takes place in Brussels between 22 and 24 January 2020 This year's theme is “Data protection and Artificial intelligence”. Carol Evrard, associate in our TMT team, participates in a panel organised by TrustArc (a privacy compliance technology company based in San Francisco, California) on "Changing Technology and Laws: Can Accountability be a Key to Global Compliance?"

Read more

21.02.2020 NL law
Podcast: Data en financiële instellingen

Short Reads - In deze podcast praten Roderik Vrolijk en Frederiek Fernhout van Stibbe in Amsterdam en Joran Iedema van Stibbe StartsUP-deelnemer Dyme over Fintech, PSD2 en het gebruik van data door financiële instellingen. Aan de ene kant biedt nieuwe regelgeving zoals PSD2 nieuwe mogelijkheden, aan de andere kant neemt de regeldruk en het toezicht op bescherming van persoonsgegevens toe.

Read more

15.01.2020 NL law
Consultatiereactie 'Wet plan van aanpak witwassen'

Short Reads - Soeradj Ramsanjhal, Karlijn van den Heuvel, Djoe Kuils, Rogier Raas, Judica Krikke en Muriël Rosing hebben een reactie ingediend op het concept wetsvoorstel ‘Wet plan van aanpak witwassen’. Dit wetsvoorstel is 2 december 2019 in consultatie gegaan en bevat verschillende voorgestelde wijzigingen van de Wet ter voorkoming van witwassen en financieren van terrorisme en de Wet op de economische delicten. 

Read more

This website uses cookies. Some of these cookies are essential for the technical functioning of our website and you cannot disable these cookies if you want to read our website. We also use functional cookies to ensure the website functions properly and analytical cookies to personalise content and to analyse our traffic. You can either accept or refuse these functional and analytical cookies.

Privacy – en cookieverklaring