EU General Data Protection Regulation (GDPR): An Implementation and Compliance Guide - Second edition
by ITGP Privacy Team
CHAPTER 5: REQUIREMENTS FOR DATA PROTECTION IMPACT ASSESSMENTS
The data protection impact assessment (DPIA) is one of the specific processes mandated by the GDPR. Many organisations will be required to conduct DPIAs and, in many instances, an organisation may find it a valuable process even when a DPIA is not required by the Regulation.
DPIAs are used to identify specific risks to personal data as a result of processing activities and the significance of their role in a PIMS could be compared to that of the information security risk assessments required by ISO/IEC 27001 and described in ISO/IEC 27005 (see Chapter 6). DPIAs naturally have a greater focus on data protection and privacy, of course, so a more focused model is valuable. The Regulation ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access