Irish Data Protection Commission Issues Guide To Data Protection Impact Assessments

Fox Rothschild LLP
Contact

Fox Rothschild LLPWe heard recently from French Data Protection Authority CNIL on the topic of Data Protection Impact Assessments (DPIAs). Now, Ireland’s Data Protection Commission has issued its own Guidance Note on DPIAs under The General Data Protection Regulation.

It describes the process in detail and provides lists of risks and mitigation methods. Key takeaways:

  • If you believe that a processing operation requiring a DPIA is not likely to be high risk, you should thoroughly document the reasons for not carrying out a DPIA.
  • It is good practice to carry out a DPIA as early as practical in the design of the processing operation. For some projects it may need to be a continuous process.
  •  Seek the views of data subjects, e.g. through a survey. If your final decision differs from that of data subjects, document this. If you think you don’t need to consult with data subjects, document that too.
  • You may wish to maintain a data protection risk register to describe the risks associated with a project and assess their likelihood and impact. Update this regularly. For small projects this may be more informal.
  • It is good practice to produce a final DPIA report including record keeping from each stage of the DPIA process and the conclusions.
  • You may want to publish your DPIA.

Read the full guide.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Fox Rothschild LLP | Attorney Advertising

Written by:

Fox Rothschild LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide