UK GDPR (UK General Data Protection Regulation)
Chapter IV: Controller and processor – UK GDPR (UK General Data Protection Regulation)

UK GDPR (UK General Data Protection Regulation) Art.35: Article 35 Data protection impact assessment

Before processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 12 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 1.11 1.11 DPIA before high-risk monitoring, DPO advice recorded, workers informed before start, ICO consulted if high risk remains
  • 1.18 1.18 Seek and document the views of workers or their representatives (such as trade unions) before introducing monitoring
  • 3.1 3.1 Remote and home working: factor higher privacy expectations and family capture into the DPIA
  • 3.4(a) 3.4(a) Email and message monitoring: a clear, necessary purpose, workers told, and a DPIA
  • 3.5(a) 3.5(a) Video monitoring of workers: DPIA, targeted at risk areas with low privacy expectations, workers and others informed, footage redactable
  • 4.1 4.1 Biometric access and time control: document why biometrics are necessary and why alternatives are inadequate, in the DPIA
  • 4.3 4.3 Biometric identification of workers always needs a DPIA before processing, discussed with workers
  • A.4 A.4 DPIA before surveillance likely to be high risk (most cases), evidence-based, with alternatives considered; consult the ICO if high risk remains
  • P.7(a) P.7(a) Workplace surveillance: consult the workforce (staff or trade unions) in the DPIA, notify employees, and inform visitors and customers
  • T.1 T.1 ANPR: genuine need, DPIA, minimum and justified cameras, road-safe signage, accurate matching data, short retention for vehicles not of interest
  • T.2 T.2 Body worn video: DPIA, recording switched on only when justified, audio and video controlled separately, people told, secure devices and storage policy
  • T.3 T.3 Drones: genuine need, DPIA for collateral intrusion, CAA registration, trained operators, public information, recording not continuous

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV: Controller and processor – UK GDPR (UK General Data Protection Regulation)

Query this from an agent

The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.