Rina Steenkamp - Privacy and technology

My annotated General Data Protection Regulation

Chapter IV Controller and processor

Section 3 Lifecycle data protection management

Article 32a Respect to risk

October 2013

Article 32a(1)

1. The controller, or where applicable the processor, shall carry out a risk analysis of the potential impact of the intended data processing on the rights and freedoms of the data subjects, assessing whether its processing operations are likely to present specific risks.

Article 32a(2)

2. The following processing operations are likely to present specific risks:

Article 32a(3)

3. According to the result of the risk analysis:

Article 32a(4)

4. The risk analysis shall be reviewed at the latest after one year, or immediately, if the nature, the scope or the purposes of the data processing operations change significantly. Where pursuant to paragraph 3 (c) the controller is not obliged to carry out a data protection impact assessment, the risk analysis shall be documented.

[Source: October 2013]