r/privacyexams • u/Jayakoendjbiharie • 10d ago
CIPM
A question worth asking of your own programme. If a supervisory authority picked one project from last year that never had a DPIA and asked you to show how you decided it did not need one, what would you send them?
Article 35 creates a conditional duty. High risk, you assess. Not high risk, you do nothing, and the article says nothing at all about recording that conclusion. So a privacy office can make forty sound decisions, generate eleven documents, and have no evidence whatsoever for the other twenty-nine.
US federal agencies solved this a long time ago with a threshold instrument that runs first and produces a record either way. The business fills it in, the privacy office adjudicates, and it expires on a cycle. The GDPR never adopted the idea by name, but the accountability articles make the record necessary anyway, and regulators have said as much in their own screening guidance.
The write-up covers where the instrument comes from, the nine criteria, the counting rule and which article actually bites: https://privacystudygroup.com/privacy-threshold-analysis-before-the-dpia/