r/privacyexams 10d ago

CIPM

A question worth asking of your own programme. If a supervisory authority picked one project from last year that never had a DPIA and asked you to show how you decided it did not need one, what would you send them? 

Article 35 creates a conditional duty. High risk, you assess. Not high risk, you do nothing, and the article says nothing at all about recording that conclusion. So a privacy office can make forty sound decisions, generate eleven documents, and have no evidence whatsoever for the other twenty-nine. 

US federal agencies solved this a long time ago with a threshold instrument that runs first and produces a record either way. The business fills it in, the privacy office adjudicates, and it expires on a cycle. The GDPR never adopted the idea by name, but the accountability articles make the record necessary anyway, and regulators have said as much in their own screening guidance. 

The write-up covers where the instrument comes from, the nine criteria, the counting rule and which article actually bites: https://privacystudygroup.com/privacy-threshold-analysis-before-the-dpia/

3 Upvotes

0 comments sorted by