{"id":13338,"date":"2023-01-09T08:00:00","date_gmt":"2023-01-09T08:00:00","guid":{"rendered":"https:\/\/letslaw.es\/?p=13338"},"modified":"2024-09-06T11:50:15","modified_gmt":"2024-09-06T11:50:15","slug":"how-to-make-your-impact-evaluation-successful","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/how-to-make-your-impact-evaluation-successful\/","title":{"rendered":"How to make your impact evaluation successful"},"content":{"rendered":"<p>The GDPR introduced the concept of a Data Protection Impact Assessment (DPA). From that moment on, <strong>it is mandatory for the Supervisory Authorities<\/strong> to establish indicative lists of processing operations that do or do not require impact assessments, as well as processing operations that do require impact assessments.<\/p>\n<h2>What is an impact assessment and what is it for?<\/h2>\n<p>The Data Protection Impact Assessment (DPA) is a crucial tool in the field of privacy and data protection. Its main objective is to carry out a comprehensive and <strong>early assessment of the risks that may affect personal data in a specific project<\/strong>.<\/p>\n<p>By conducting a PIA, it seeks <strong>to identify and understand<\/strong> the potential risks associated with the processing of personal data, with the purpose of taking preventive and corrective measures to mitigate them.<\/p>\n<p>In practical terms, the PIA enables data controllers to make informed risk management decisions. By analysing the information system, product or service involved, the PIA helps to determine whether the processing activities comply with existing data protection regulations and policies.<\/p>\n<p>It is essential that the DPA is carried out systematically and objectively by lawyers who are knowledgeable about data protection. <strong>This should consider both the type of personal data being processed<\/strong> and the nature and context of the processing.<\/p>\n<p>It is also important to assess the likelihood and severity of the potential risks, as well as the impact they would have on the individuals whose data are being processed.<\/p>\n<p>Once risks have been identified, the PIA becomes a tool to guide the <strong>adoption of appropriate measures<\/strong>. These may include implementing technical and organisational measures to reduce data exposure, reviewing information security policies, training staff involved in data processing, or even reconsidering certain practices or services that may present a high risk without clear justification.<\/p>\n<h2>Steps and requirements for a successful impact assessment<\/h2>\n<p>The requirements for a proper impact assessment are that it is carried out when required by the GDPR, i.e. when the processing <strong>is likely to result in a high risk to the rights and freedoms of individuals<\/strong>.<\/p>\n<p>In this regard, it is important to note that the performance of a PIA <strong>is not mandatory in all cases<\/strong>, although it is advisable in many situations where data processing takes place. As we have indicated, it is only mandatory when this processing may entail a high risk for the rights and freedoms of users.<\/p>\n<p>In particular, it will be mandatory when it involves the systematic and exhaustive evaluation of personal aspects of an individual, including profiling, when large-scale processing of sensitive data is carried out, and when large-scale systematic observation of a public area is carried out.<\/p>\n<h2>How to implement an impact assessment step by step<\/h2>\n<p>There are several steps in conducting a PCIA:<\/p>\n<h3>1. Need for a DPA<\/h3>\n<p>In this initial phase, an assessment is carried out to determine whether a Data Protection Impact Assessment is necessary.<\/p>\n<p>It is essential to identify the data processing operations, through data protection lawyers, that will be carried out in the specific project and to analyse whether they may entail a high risk to the rights and freedoms of the data subjects. If so, the EIPD is initiated.<\/p>\n<h3>2. Description of the project and information flows<\/h3>\n<p>At this stage, a thorough analysis of the project or activity that will involve the processing of personal data is carried out. It identifies the categories of data that will be processed, examines the information flows, the technologies and systems used, as well as the processes related to the data processing.<\/p>\n<p>This step provides a detailed overview of the scope of the PIA and allows a full understanding of the context in which the data processing will take place.<\/p>\n<h3>3. Risk identification and assessment<\/h3>\n<p>In this step, potential data protection risks to the data subjects concerned by the processing are identified and assessed. It analyses how the processing activities may affect the rights and freedoms of data subjects, considering aspects such as confidentiality, integrity, availability and the likelihood of security incidents. The assessment of these risks enables prioritisation of efforts to adopt appropriate mitigation measures.<\/p>\n<h3>4. Measures to guarantee the privacy of personal data<\/h3>\n<p>Once the risks have been identified, this phase involves identifying and proposing measures to eliminate, mitigate, transfer or assume the risks detected. These measures may include the implementation of technical, organisational or legal controls to protect the privacy of personal data. It is essential to ensure that these measures are effective and provide an adequate level of data protection.<\/p>\n<h3>5. Final report<\/h3>\n<p>At this stage, a detailed report is prepared that includes the analysis of the identified risks, the proposed measures and recommendations for the proper management of personal data privacy. The final report becomes a key tool to demonstrate the company&#8217;s compliance with data protection regulations and to provide transparency to stakeholders.<\/p>\n<h3>6. Review<\/h3>\n<p>The review is a continuous and dynamic stage of the DPOI process. It allows verifying the effectiveness of the measures implemented, as well as detecting new risks or changes in the environment that may affect data protection. It is essential to keep the EIPD updated, carrying out periodic reviews and adapting the protection measures as necessary.<\/p>\n<p>At <strong>Letslaw<\/strong> our team of <a title=\"data protection lawyers\" href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/\">data protection lawyers<\/a> will advise you on your impact assessment and at all stages of its development.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/13338#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>The GDPR introduced the concept of a Data Protection Impact Assessment (DPIA). From that moment on, it is mandatory for the Control Authorities to establish indicative lists of data processings that do not require impact assessments, as well as processings that do require their performance.<\/p>\n","protected":false},"author":45,"featured_media":13412,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[258],"tags":[],"class_list":["post-13338","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/13338","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/45"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=13338"}],"version-history":[{"count":12,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/13338\/revisions"}],"predecessor-version":[{"id":16640,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/13338\/revisions\/16640"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/13412"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=13338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=13338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=13338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}