Procedure
The data protection impact assessment
An impact assessment under Art. 35 GDPR is not a formality at the end of a project. It comes before the means of processing are determined, and the decision against it has to be documented just as its performance would be. What is assessed is the risk to the data subjects and not the risk to the organisation.
The choice is made, the assessment is missing
The department presents a new recruitment system. The choice has been made, the contract is ready for signature, the launch date is set. The question asked is whether anything speaks against it from a data protection point of view.
The decision against an assessment also needs reasons
What decides whether an impact assessment is required is set out in Art. 35(1) GDPR. The trigger is a likely high risk to the rights and freedoms of natural persons, and paragraph 3 names three standard cases.
The three standard cases in Art. 35(3) GDPR
Systematic and extensive evaluation of personal aspects
What is required is automated processing including profiling which in turn forms the basis for decisions producing legal effects or similarly significant effects. Pre-selection of applicants by a scoring system falls within this as soon as the selection follows the score.
Processing on a large scale of special categories
Special categories under Art. 9(1) GDPR or data on criminal convictions under Art. 10 GDPR. Large scale is not a fixed number but a question of volume, duration, geographical extent and the number of data subjects.
Systematic monitoring of publicly accessible areas on a large scale
The camera surveillance case, once it is systematic and covers a publicly accessible area. A customer area is publicly accessible even where it is private property.
The standard cases are not exhaustive. Alongside them stands the list each supervisory authority publishes under Art. 35(4) GDPR, and the binding one is the list of the authority competent for your own establishment.
Beforehand means before the means are determined
When in a project the assessment has to take place follows from two provisions. Art. 35(1) GDPR requires it prior to the processing. Art. 25(1) GDPR fixes the moment more precisely, namely at the time of determining the means of processing, and thus before the system is chosen.
Four moments, and only the first is the right one
The need is settled
Purpose, categories of data and data subjects are known, the system is not. Here the impact assessment shapes the requirements list.
Vendor selected
The impact assessment can still influence the configuration and the contract. The shape of the processing is already fixed.
Contract signed
From here what remains are measures that cost nothing. Changing vendor is out of the question in commercial terms.
System live
If the impact assessment takes place only after the fact, it merely describes the current state. Its power to shape the project is lost.
A late assessment is still better than none. It closes the gap in accountability and provides the basis for updating once something about the project changes.
What is assessed is the risk to the data subjects
Whose risk the assessment measures is regularly confused in practice. Art. 35(7)(c) GDPR names the risks to the rights and freedoms of data subjects. Downtime, fines and reputational loss for the organisation are a different subject.
Two notions of risk that do not coincide
| Risk to the data subject | Merkmal | Risk to the organisation |
|---|---|---|
| Rights and freedomsDiscrimination, identity theft, financial loss, damage to reputation, loss of confidentiality. | Subject matter | Operations and balance sheetDowntime, recovery costs, fines, standing. |
| Likelihood and severityFrom the perspective of the person who would be affected. | Yardstick | Loss amount and frequencyFrom the perspective of the organisation doing the processing. |
| Lowers it considerablyThe data stays unreadable if it leaks. | Effect of encryption | Barely lowers itThe system still goes down. |
| Barely lowers itA copy does not help against unauthorised disclosure. | Effect of a backup | Lowers it considerablyOperations resume after a short time. |
The last two rows show why the confusion matters. The same measure works in opposite directions in the two assessments, so an assessment written from the operational perspective recommends the wrong measures.
If the risk stays high, the project goes to the supervisory authority
What follows where the risk remains high despite the measures envisaged is governed by Art. 36(1) GDPR. The controller then consults the supervisory authority prior to processing. The consultation is not an approval procedure, and silence from the authority is not clearance.
What the consultation requires
Liste zu erledigender Punkte
- The respective responsibilities of the controllers and the processors involved, in particular within a group of undertakings
- The purposes and means of the intended processing
- The measures and safeguards envisaged
- The contact details of the data protection officer
- The impact assessment itself
The authority responds within up to eight weeks, extendable by six. It may exercise its powers under Art. 58 GDPR, which include limiting and banning the processing.
How we support you with the impact assessment
The threshold assessment works best where new procedures are reviewed or released anyway. With little effort, it clarifies whether a data protection impact assessment is required. The information it needs already sits in the record of processing activities.
Frequently asked questions
When is an impact assessment required?
Where the processing is likely to result in a high risk, Art. 35(1) GDPR. Paragraph 3 names three standard cases, namely systematic and extensive evaluation of personal aspects, processing on a large scale of special categories, and systematic monitoring of publicly accessible areas on a large scale. Alongside these stands the list published by the competent supervisory authority under paragraph 4.
Does it have to be documented that no assessment was needed?
Yes. Accountability under Art. 5(2) GDPR covers the outcome of the check and not only its performance. A one-page threshold assessment suffices if it names the criteria considered and the result.
How long does a consultation under Art. 36 GDPR take?
The supervisory authority responds within up to eight weeks of receiving the request, extendable by six weeks for complex projects. The period is suspended while requested information is outstanding.
Can one assessment cover several systems?
Art. 35(1) sentence 2 GDPR allows a single assessment for a set of similar processing operations that present similar high risks. The test is the similarity of the operations and not whether they belong to the same system.
More questions from this area
We are planning something
Data protection belongs in a new project from the outset and not in the acceptance test.
Automated individual decisions
Pre-selection is not a preliminary stage of the decision where the selection follows it to a significant degree.
Special categories of data
Art. 9(1) GDPR prohibits the processing, and a permission under paragraph 2 sits alongside the legal basis in Art. 6 GDPR rather than replacing it.
Transfer impact assessment
The regulation does not know the term transfer impact assessment.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.