UK GDPR (UK General Data Protection Regulation)
Chapter IV: Controller and processor – UK GDPR (UK General Data Protection Regulation)

UK GDPR (UK General Data Protection Regulation) Art.36: Article 36 Prior consultation

Where a DPIA shows processing would result in high risk without mitigating measures, the controller must consult the Commissioner before processing, providing the responsibilities of those involved, purposes and means, safeguards, DPO contact details, the DPIA and any other information requested. The Commissioner gives written advice within eight weeks, extendable by six, and may use its Article 58 powers. Government must also consult the Commissioner on legislative proposals relating to processing.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 1.11 1.11 DPIA before high-risk monitoring, DPO advice recorded, workers informed before start, ICO consulted if high risk remains
  • A.4 A.4 DPIA before surveillance likely to be high risk (most cases), evidence-based, with alternatives considered; consult the ICO if high risk remains

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV: Controller and processor – UK GDPR (UK General Data Protection Regulation)

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.