This is conducted in accordance with industry good practice. An enterprise level PIA is strategic in content and focuses on the organisation at a strategic layer. System specific PIA, which is granular in nature and focuses on a specific set of business operations and is targeted with detailed guidance on any remediation activity.
Data Protection Impact Assessment (DPIAs) help you to proactively identify and control GDPR compliance risks and embed Data Protection & Privacy by Design and by Default into all of your personal data processing activities, systems and technologies. Conducting robust DPIAs on your own can be quite a complex task, particularly when the processing activity your business intends to undertake is multifaceted, innovative or inherently privacy invasive.
Our Data Protection Impact Assessment services are designed to provide your business with all of the independent expert advice and support it needs to conduct thorough DPIAs, in compliance with the General Data Protection Regulation (GDPR).
1. We will work closely with you to identify the scope of the DPIA, with particular regard to what your organisation’s intended data processing activities are and the nature of any potential third-party involvement.
2. We will interview those with key responsibilities for the design and delivery of the intended data processing activities and review any associated documented policies, procedures or product/service designs.
3. We will report our findings, setting out any risks that may have been identified that are likely to impact on the individuals whose data you intend to process. Detailing clear recommendations for safeguards that can be implemented to reduce the likelihood and impact of risk.
4. If there are risks identified that cannot be readily mitigated, we will support you through the process of consulting the UK Information Commissioners Office (whom has the power to ban processing activity, if you cannot demonstrate that you have appropriate safeguards in place).