WP29 Issues Revised Guidelines on Data Protection Impact Assessment (DPIA)




In April 2017, the Article 29 Working Party (WP29) released guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a “high risk” in an effort to help companies understand the new Data Protection impact assessment requirement introduced by the GDPR in Article 35 and Regulation 2016/679. The guidelines were open for public comments until 23 May 2017 and the revised version was published a few days ago.

Overall, the revised version does not contain any major changes from the original one and most of the changes are no more than language tweaks. However, there are a few noticeable ones (detailed below):

WP29 Reinforces the Importance of the Risk-based Approach in Data Protection Frameworks

Section III of the guidelines now starts with a half-page long emphasis on risks in the context of data protection. The obligation for controllers to conduct a DPIA should be understood “against the background of their general obligation to appropriately manage risks” to the rights and freedoms of individuals. Rights and freedoms of data subjects concerns primarily the rights to data protection and privacy but also involve other fundamental rights such as freedom of speech, freedom of thought, freedom of movement, prohibition of discrimination, right to liberty, conscience and religion. Controllers must continually assess the risks associated to a particular processing activity in order to identify when it may result in a high risk. The risks for each processing operation have to be identified, analysed, estimated, evaluated and mitigated and controllers cannot escape their responsibility by covering risks under insurance policies.

Changes to the Criteria to Consider when Determining Whether a Processing Operation is Likely to Result in High Risk

In order to help companies determine whether a particular processing operation is likely to result in a high risk, the Article 29 Working Party provides a list of criteria to consider. The list went from 10 criteria down to nine and some of the criteria have been specified: “Sensitive data” is now “Sensitive data or data of highly personal nature,” thus expanding the scope of this criterion. The new guideline adds for this criterion that “beyond the provisions of the GDPR, some categories of data can be considered as increasing the possible risk to the rights and freedoms of individuals. These personal data are considered as sensitive (as this term is commonly understood) because they are linked to household and private activities (such as electronic communications whose confidentiality should be protected), or because they impact the exercise of a fundamental right (such as location data whose collection questions the freedom of movement) or because their violation clearly involves serious impacts in the data subject’s daily life (such as financial data that might be used for payment fraud)”. It is interesting to note that the criterion that was removed is “data transfer across borders outside the European Union.”

Additional practical examples

Below the list of criteria, the guidelines include a table with examples of processing and the possible relevant criteria to consider for each. The revised version now offers additional examples:

Example of Processing 1

Possible Relevant Criteria

Example of Processing 2

Possible Relevant Criteria

Example of Processing 3

Possible Relevant Criteria

DPIAs are required in some circumstances for existing processing operations

While the first version of the guidelines stated that the requirement to carry out a DPIA applies to processing operations meeting the criteria in Article 35 and initiated after the GDPR takes effect on 25 May 2018, the new version now mentions that the requirement to carry out a DPIA applies to existing processing operations likely to result in a high risk to the rights and freedoms of natural persons and for which there has been a change of the risks, taking into account the nature, scope, context and purposes of the processing. It also adds that a DPIA is not needed for processing operations that have been checked by a supervisory authority or the data protection official, in accordance with Article 20 of Directive 95/46/EC, and that are performed in a way that has not changed since the prior checking.

The explicit three-year re-assessment requirement removed

While there is no change in position regarding the fact that a DPIA, in order to serve its purpose, must be continuously carried out on existing processing activities so as to identify potential changes that would result in a high risk, it is interesting to note that the requirement to re-assess each DPIA after three years is no longer included in the October version, which now only states that as a matter of good practice, a DPIA should be continuously reviewed and regularly re-assessed.

Bigger role given to the CISO

A minor, but nonetheless significant, change appeared in the recommendation to define and document specific roles and responsibilities within the organisation, depending on internal policy, processes and rules. In the new guidelines, the Chief Information Security Officer (CISO) – if appointed – could suggest that the controller carries out a DPIA on specific processing operation, and should help the stakeholders on the methodology, help to evaluate the quality of the risk assessment and whether the residual risk is acceptable, and to develop knowledge specific to the data controller context. Only the DPO was included for this task in the previous version.