Albania Law No. 124/2024 on Personal Data Protection
Part II Chapter III: controller and processor obligations, security, breach, impact assessment, DPO, codes and certification (Articles 22 to 38) – Albania Law No. 124/2024 on Personal Data Protection

Albania Law No. 124/2024 on Personal Data Protection 31: Article 31: data protection impact assessment for high-risk processing

Before processing likely to result in a high risk to rights and freedoms, particularly with new technologies, the controller must assess the impact of the envisaged operations (one assessment may cover similar high-risk operations; none is needed where a law defining the processing was adopted with an impact assessment). The assessment contains at least a systematic description of the operations and purposes (including any legitimate interest), an assessment of necessity and proportionality, an assessment of the risks, and the measures, safeguards and security mechanisms to address them and demonstrate compliance. The DPO must be consulted, data subjects' views sought where appropriate, codes of conduct taken into account, and the assessment reviewed at least when the risk changes. It is required in particular for systematic and extensive evaluation by automated processing including profiling with legal or similarly significant effects, large-scale processing of sensitive data or criminal records, and large-scale systematic monitoring of publicly accessible areas; the Commissioner publishes lists of operations that do and do not need one.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part II Chapter III: controller and processor obligations, security, breach, impact assessment, DPO, codes and certification (Articles 22 to 38) – Albania Law No. 124/2024 on Personal Data Protection

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.