A DPIA is a legal requirement before processing likely to result in high risk, which covers most video surveillance, including large-scale systematic monitoring of publicly accessible places. It must set out what the processing is, its scope, context and purposes, weigh necessity and proportionality and the compliance measures, identify and rate the risks to people, and set out further measures to reduce them; a decision not to do one must be documented and justified. The organisation should consider lawfulness and transparency, whether the system is necessary and proportionate and actually solves the problem on reliable evidence, and less intrusive alternatives; if high residual risk remains it must consult the ICO and not proceed until it has. Failing to do a required DPIA is itself an infringement.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.