10. Data Protection Impact Assessment

Where the firm will be undertaking a new activity that involves a high risk to the rights and freedoms of a data subject, the firm is required to undertake a data protection impact assessment.

Some examples of high-risk activities are large-scale processing, large-scale systematic monitoring and so on.

More information on Data Protection Impact Assessments is available on the  and from the European Data Protection Board: 

 

Return to GDPR Guidance and templates >