
{"id":16255,"date":"2021-01-25T10:54:02","date_gmt":"2021-01-25T09:54:02","guid":{"rendered":"https:\/\/www.rosello-mallol.com\/?p=16255"},"modified":"2022-06-30T13:00:01","modified_gmt":"2022-06-30T12:00:01","slug":"data-protection-impact-assessment","status":"publish","type":"post","link":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/","title":{"rendered":"Data protection impact assessment"},"content":{"rendered":"\n<p>The data protection impact assessment is one of the \u201cnew\u201d obligations of the GDPR and, although it was introduced more than two and a half years ago, there is still some confusion so we have decided to write about this in this first post of the year.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What is it?<\/strong><\/h3>\n\n\n\n<p>This assessment is an additional measure that must be carried out on a mandatory basis by certain companies or organisations that carry out data processing that is considered high risk.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>It should not be confused with risk analysis, which is an obligation for any company or organisation that processes personal data, without exception.<\/li><li>One of the phases of the risk analysis is precisely to determine whether any of the processes analysed require a data protection impact assessment and, to ascertain which processes are subject, there are two main sources.<\/li><li>Art. 35 of the GDPR that includes three types of processing that require a data protection impact assessment:<\/li><\/ul>\n\n\n\n<p><em>a) systematic and exhaustive evaluation of personal aspects of natural persons based on automated processing, such as profiling, and on the basis of which decisions are made that produce legal effects for natural persons or that significantly affect them in a similar way;<\/em><\/p>\n\n\n\n<p><em>b) large-scale processing of the special categories of data referred to in article 9, paragraph 1, or of personal data relating to convictions and criminal offenses referred to in article 10, or<\/em><\/p>\n\n\n\n<p><em>c) systematic observation on a large scale of a public access area.<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The list of processes that require this assessment, as<a href=\"https:\/\/www.aepd.es\/sites\/default\/files\/2019-09\/listas-dpia-es-35-4.pdf\"> published<\/a> by the Spanish Data Protection Agency (AEPD).<\/li><\/ul>\n\n\n\n<p>In either of the two cases, these are processes that can objectively involve a high risk to the people subject to it.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>To decide whether or not a process requires Impact Assessment, you can also consult the list of processes that DO NOT require it, which is also published by the AEPD.<\/li><li>The data protection impact assessment must be performed before processing begins, which makes all the sense in the world because, if the assessment concludes that the processing is intrusive to people and that it is already being carried out, this makes little sense.<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What does a data protection impact assessment include?<\/strong><\/h3>\n\n\n\n<p>The GDPR itself details the minimum content of the assessment, which must at least include:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>A definition of the processing carried out and their purposes.<\/li><li>A justification that the processing is necessary to achieve such purposes.<\/li><li>Details of the risks for those affected or data owners.<\/li><li>Measures to mitigate or eliminate said risks.<\/li><\/ol>\n\n\n\n<p>Only those processes that have passed the data protection impact assessment may be carried out, in other words when the measures to mitigate or eliminate said risks have been implemented.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Who should conduct a data protection impact assessment?<\/strong><\/h3>\n\n\n\n<p>Those obliged to carry out this impact assessment are responsible for the processing involved. Where applicable, the data protection officer must also take part, when consulted. Where whoever has access to data is considered to be the controller, they are not obliged to carry out the impact assessment, but to participate in it if it is required by a controller on behalf of the processor. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How does the AEPD work?<\/strong><\/h3>\n\n\n\n<p>At present, the AEPD has limited itself to educational work in relation to said impact assessment, with the publication of a<a href=\"https:\/\/www.aepd.es\/sites\/default\/files\/2019-09\/guia-evaluaciones-de-impacto-rgpd.pdf\"> guide<\/a> for this purpose and a<a href=\"https:\/\/gestiona.aepd.es\/\"> online tool<\/a> so that those responsible can decide whether or not to do it.<\/p>\n\n\n\n<p>There are currently no penalties for not carrying out the impact assessment in Spain, although in some EU countries, such as Norway or Finland, some penalties have been imposed. We will see whether this is the next step of the AEPD&#8230;<\/p>\n\n\n\n<p>If you have any questions about this or any other legal aspect, contact us<a href=\"https:\/\/www.rosello-mallol.com\/en\/contact\/\" target=\"_blank\" rel=\"noreferrer noopener\"> here<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-contact-form-7-contact-form-selector\">\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f13645-o1\" lang=\"en-US\" dir=\"ltr\" data-wpcf7-id=\"13645\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/16255#wpcf7-f13645-o1\" method=\"post\" class=\"wpcf7-form init\" aria-label=\"Contact form\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"13645\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.6\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"en_US\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f13645-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<p><label> Name (required) <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required uk-input\" aria-required=\"true\" aria-invalid=\"false\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span> <\/label>\n<\/p>\n<p><label> Email (required) <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email uk-input\" aria-required=\"true\" aria-invalid=\"false\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span> <\/label>\n<\/p>\n<p><label> Contact phone (telephone contact) <span class=\"wpcf7-form-control-wrap\" data-name=\"telefon\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text uk-input\" aria-invalid=\"false\" value=\"\" type=\"text\" name=\"telefon\" \/><\/span> <\/label>\n<\/p>\n<p><label> Message <span class=\"wpcf7-form-control-wrap\" data-name=\"your-message\"><textarea cols=\"40\" rows=\"5\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea uk-textarea\" aria-invalid=\"false\" name=\"your-message\"><\/textarea><\/span> <\/label>\n<\/p>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"aceptacion-RGPD\"><span class=\"wpcf7-form-control wpcf7-acceptance\"><span class=\"wpcf7-list-item\"><label><input type=\"checkbox\" name=\"aceptacion-RGPD\" value=\"1\" aria-invalid=\"false\" \/><span class=\"wpcf7-list-item-label\">I read and accept the <a href=\"https:\/\/www.rosello-mallol.com\/en\/policy-privacy\/\" target=\"_blank\">Privacy Policy<\/a><\/span><\/label><\/span><\/span><\/span><br \/>\n<label><br \/>\n<span class=\"wpcf7-form-control-wrap\" data-name=\"acceptance-360\"><span class=\"wpcf7-form-control wpcf7-acceptance optional\"><span class=\"wpcf7-list-item\"><label><input type=\"checkbox\" name=\"acceptance-360\" value=\"1\" aria-invalid=\"false\" \/><span class=\"wpcf7-list-item-label\">I agree to receive the newsletter.<\/span><\/label><\/span><\/span><\/span><br \/>\n<input class=\"wpcf7-form-control wpcf7-submit has-spinner uk-button uk-button-primary\" type=\"submit\" value=\"Send\" \/><\/label>\n<\/p><p style=\"display: none !important;\" class=\"akismet-fields-container\" data-prefix=\"_wpcf7_ak_\"><label>&#916;<textarea name=\"_wpcf7_ak_hp_textarea\" cols=\"45\" rows=\"8\" maxlength=\"100\"><\/textarea><\/label><input type=\"hidden\" id=\"ak_js_1\" name=\"_wpcf7_ak_js\" value=\"70\"\/><script>\ndocument.getElementById( \"ak_js_1\" ).setAttribute( \"value\", ( new Date() ).getTime() );\n<\/script>\n<\/p><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<\/div>\n\n\n\n<h6 class=\"wp-block-heading\">Information on data protection<\/h6>\n\n\n\n<p><small><strong>Company name<\/strong><br>LEGAL IT GLOBAL 2017, SLP<br><strong>Purpose<br><\/strong>Providing the service.<br>Sending the newsletter.<br><strong>Lawful basis<br><\/strong>Compliance with the service provision.<br>Consent.<br><strong>Recipients<\/strong><br>Your data will not be shared with any third party, except service providers with which we have signed a valid service agreement.<\/small><br><small><strong>Rights<\/strong><br>You may access, rectify or erase your data and exercise the rights indicated in our Privacy Policy.<\/small><br><small><strong>Further information<\/strong><br>See the&nbsp;Privacy Policy.<\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The data protection impact assessment is one of the \u201cnew\u201d obligations of the GDPR and, although it was introduced more than two and a half years ago, there is still some confusion so we have decided to write about this in this first post of the year. What is it? This assessment is an additional [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":16283,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_joinchat":[],"footnotes":""},"categories":[246],"tags":[496,497,449,498,394],"class_list":["post-16255","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-aepd-2","tag-assessment","tag-data-protection","tag-obligation","tag-rgpd-es-en"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.3 (Yoast SEO v27.7) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Data protection impact assessment | Rosell\u00f3 Mallol<\/title>\n<meta name=\"description\" content=\"Data protection impact assessment is one of the \u201cnew\u201d obligations of the GDPR and, in this post, we explain you what it is all about.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection impact assessment\" \/>\n<meta property=\"og:description\" content=\"The data protection impact assessment is one of the \u201cnew\u201d obligations of the GDPR and, although it was introduced more than two and a half years ago,\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/\" \/>\n<meta property=\"og:site_name\" content=\"Rosell\u00f3 Mallol\" \/>\n<meta property=\"article:published_time\" content=\"2021-01-25T09:54:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-06-30T12:00:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/evaluacio-impacte-proteccio-dades.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Marketing\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@vic_rosello\" \/>\n<meta name=\"twitter:site\" content=\"@vic_rosello\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Marketing\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Data protection impact assessment | Rosell\u00f3 Mallol","description":"Data protection impact assessment is one of the \u201cnew\u201d obligations of the GDPR and, in this post, we explain you what it is all about.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/","og_locale":"en_US","og_type":"article","og_title":"Data protection impact assessment","og_description":"The data protection impact assessment is one of the \u201cnew\u201d obligations of the GDPR and, although it was introduced more than two and a half years ago,","og_url":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/","og_site_name":"Rosell\u00f3 Mallol","article_published_time":"2021-01-25T09:54:02+00:00","article_modified_time":"2022-06-30T12:00:01+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/evaluacio-impacte-proteccio-dades.jpg","type":"image\/jpeg"}],"author":"Marketing","twitter_card":"summary_large_image","twitter_creator":"@vic_rosello","twitter_site":"@vic_rosello","twitter_misc":{"Written by":"Marketing","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/#article","isPartOf":{"@id":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/"},"author":{"name":"Marketing","@id":"https:\/\/www.rosello-mallol.com\/en\/#\/schema\/person\/54fe3a9119386ad1ec22a0f09bc21147"},"headline":"Data protection impact assessment","datePublished":"2021-01-25T09:54:02+00:00","dateModified":"2022-06-30T12:00:01+00:00","mainEntityOfPage":{"@id":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/"},"wordCount":701,"publisher":{"@id":"https:\/\/www.rosello-mallol.com\/en\/#organization"},"image":{"@id":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/#primaryimage"},"thumbnailUrl":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/evaluacio-impacte-proteccio-dades.jpg","keywords":["AEPD","Assessment","Data Protection","obligation","RGPD"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/","url":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/","name":"Data protection impact assessment | Rosell\u00f3 Mallol","isPartOf":{"@id":"https:\/\/www.rosello-mallol.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/#primaryimage"},"image":{"@id":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/#primaryimage"},"thumbnailUrl":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/evaluacio-impacte-proteccio-dades.jpg","datePublished":"2021-01-25T09:54:02+00:00","dateModified":"2022-06-30T12:00:01+00:00","description":"Data protection impact assessment is one of the \u201cnew\u201d obligations of the GDPR and, in this post, we explain you what it is all about.","breadcrumb":{"@id":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/#primaryimage","url":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/evaluacio-impacte-proteccio-dades.jpg","contentUrl":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/evaluacio-impacte-proteccio-dades.jpg","width":1280,"height":853,"caption":"Data Protection Impact Assessment"},{"@type":"BreadcrumbList","@id":"https:\/\/www.rosello-mallol.com\/en\/data-protection-impact-assessment\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Inici","item":"https:\/\/www.rosello-mallol.com\/en\/"},{"@type":"ListItem","position":2,"name":"Data protection impact assessment"}]},{"@type":"WebSite","@id":"https:\/\/www.rosello-mallol.com\/en\/#website","url":"https:\/\/www.rosello-mallol.com\/en\/","name":"Rosell\u00f3 Mallol","description":"Despatx advocats experts en TIC i Protecci\u00f3 de dades","publisher":{"@id":"https:\/\/www.rosello-mallol.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.rosello-mallol.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.rosello-mallol.com\/en\/#organization","name":"Rosell\u00f3 Mallol - Advocats especialistes en dret digital","url":"https:\/\/www.rosello-mallol.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.rosello-mallol.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/logo-definitiu-web.png","contentUrl":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/logo-definitiu-web.png","width":4000,"height":736,"caption":"Rosell\u00f3 Mallol - Advocats especialistes en dret digital"},"image":{"@id":"https:\/\/www.rosello-mallol.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/vic_rosello","https:\/\/www.instagram.com\/rosellomallol\/","https:\/\/www.linkedin.com\/in\/victorrosello\/","https:\/\/www.youtube.com\/channel\/UCxcqAdksWzsEaZ5UYoFJd0Q\/featured"]},{"@type":"Person","@id":"https:\/\/www.rosello-mallol.com\/en\/#\/schema\/person\/54fe3a9119386ad1ec22a0f09bc21147","name":"Marketing","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/337d1590ee4f05238bd6449f6d1442bd1df14a6fdeceb5aaa29f47c8a4598d96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/337d1590ee4f05238bd6449f6d1442bd1df14a6fdeceb5aaa29f47c8a4598d96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/337d1590ee4f05238bd6449f6d1442bd1df14a6fdeceb5aaa29f47c8a4598d96?s=96&d=mm&r=g","caption":"Marketing"},"url":"https:\/\/www.rosello-mallol.com\/en\/author\/marketing\/"}]}},"jetpack_featured_media_url":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/evaluacio-impacte-proteccio-dades.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/posts\/16255","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/comments?post=16255"}],"version-history":[{"count":0,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/posts\/16255\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/media\/16283"}],"wp:attachment":[{"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/media?parent=16255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/categories?post=16255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/tags?post=16255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}