CHAPTER 11: RISK MANAGEMENT AND DPIAs

The Regulation notes that controllers and processors “should evaluate the risks inherent in the processing and implement measures to mitigate those risks”.193 This same consideration is mentioned several times throughout the Regulation, requiring the controller and the processor to take risks into account at many stages throughout the lifecycle of the personal data in question. Although it stops short of saying that the organisation should have an explicit risk management programme, it is clear that a systematic and comprehensive approach is the best way to ensure compliance.

Risk management is now a near-universal expectation of corporate management and, although smaller organisations might manage risk relatively ...

Get EU General Data Protection Regulation (GDPR) – An implementation and compliance guide, fourth edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.