Risk Assessment & DPIAs

A Risk Assessment should provide you with an idea of the variety of incidents that might occur within your organisation as a result of Business Change. A change in business activities, in systems or processes will introduce a different set of risks which need analysis and mitigation actions.

“Mike had a wide breadth of knowledge around creating and mapping processes which he was happy to share with the team. Also the templates he designed saved many hours of work. Mike was a pleasure to work with”. – Jacquie Borman, GDPR Project, Ambassador Theatre Group, London.

Anatomy of a DPIA

  1. A description of the processing operations, their purposes and applicable legitimate interests.
  2. An assessment of the necessity and proportionality for each purpose.
  3. A risk assessment to the rights and freedoms of the data subjects affected by processing.
  4. Appropriate measures anticipated to mitigates the risks.
  5. Safeguards & security measures to demonstrate compliance.
  6. Retention periods proposed for the data.
  7. A description of security by default and design.
  8. A list of recipients of the personal data especially those outside the organisation.
  9. Compliance with approved conduct codes.
  10. A description of how data subjects are to be informed.

https://ico.org.uk/media/about-the-ico/consultations/2258461/dpia-template-v04-post-comms-review-20180308.pdf