CHAPTER 11: RISK MANAGEMENT AND DPIAs

The Regulation notes that controllers and processors “should evaluate the risks inherent in the processing and implement measures to mitigate those risks”.196 This same consideration is mentioned several times throughout the Regulation, requiring the controller and the processor to take risks into account at many stages throughout the lifecycle of the personal data in question. Although it stops short of saying that the organisation should have an explicit risk management programme, it is clear that a systematic and comprehensive approach is the best way to ensure compliance.

Risk management is now a near-universal expectation of corporate management and, although smaller organisations might manage risk relatively ...

Get EU General Data Protection Regulation (GDPR), third edition - An Implementation and Compliance Guide now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.