The Data Protection Impact Assessment (DPIA) is a significant new burden on data controllers under GDPR. As many have noted, GDPR does not clearly outline when a DPIA is required, instead referring to processing “likely to result in a high risk to the rights and freedoms of natural persons.” Article 35(4) charges supervisory authorities with developing a list of processing operations that will require a DPIA. Recently, Poland became the first country to publish its draft list. While the document is written in Polish, two Polish attorneys published an unofficial English translation
here. When reading this list, there are two items to keep in mind: 1 | The list is in draft and applies only to companies with Polish operations. The final version may differ based on public comment. Further, other EU jurisdictions will develop their own lists; 2 | Performing the types of processing included on the list is not prohibited; you can process data in these contexts as long as your DPIA indicates residual risk to the rights and freedoms of data subjects (after application of mitigating measures) is at a reasonable level. The list of processing operations requiring a DPIA is as follows:
| # | Type of processing | Notable examples | Comment |
| 1 | Evaluation or assessment for purposes that may have negative legal, physical, financial, or other effects on natural persons |
Profiling for (unsolicited) direct marketing purposes, profiling unemployed persons without consent, evaluating credit, assessment of lifestyle or other habits by insurance companies for the purpose of setting prices, or indirect profiling (price differentiation for specific groups) | Very similar to the current definition of automated decision making, but with added clarity |
| 2 | Automated decision making that produces legal, financial or similar material results | Traffic monitoring systems, customer profiling systems (in particular those setting sale prices based on a profile) | Very similar to the current definition of automated decision making, but with added clarity |
| 3 | Systematic large-scale monitoring of publicly accessible places using elements of recognition of features or properties of objects in the monitored space | Time-tracking systems used by employees, tracking of employee activity while on company networks, monitoring purchases and purchasing tendencies such as alcohol or sweets, systems using RFID where tags are assigned to individuals | While large-scale monitoring is identified in GDPR as an operation requiring a DPIA, the scope is more extensive than many had first anticipated |
| 4 | Processing of special categories of personal data concerning convictions and law infringements | Biometric data processing, high-frequency data processing, and portals or systems processing information involving purely personal or household activities | While large-scale monitoring is identified in GDPR as an operation requiring a DPIA, the scope is more extensive than many had first anticipated |
| 5 | Large-scale data processing | Central data repositories, collecting data on user activity | Clarifies GDPR concept of large-scale data processing |
| 6 | Performing comparisons, assessments, or drawing conclusions based on analysis of data collected from various sources | Certain marketing campaigns that combine data from various sources | New category not explicitly covered in GDPR guidance |
| 7 | Processing data concerning persons whose assessment depends on entities or persons which have authoritative and/or assessment-related powers | Candidate matching systems and whistleblowing systems | New category not explicitly covered in GDPR guidance |
| 8 | Innovative use of technological or organizational solutions | Various uses of Internet of Things data, devices transmitting data through telecommunications networks, remote metering systems | Provides clarity with respect to the “new technologies” portion of the DPIA requirement |
| 9 | Cross-border data transmission outside the EU | Central HR processing for international companies, use of third-country cloud providers | Covered in a different section of GDPR, but tied in to DPIAs under this guidance |
| 10 | Data processing that prevents data subjects from exercising their rights or using a service | Customer credit checks, other pre-contract checks processing data from third-party databases | Provides clarity on “decisions that produce legal effects concerning a natural person” |
Philip Brudney
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)