Municipalities regularly find themselves asking which processing operations require a data protection impact assessment (DPIA) and when. Article 35 (Data Protection Impact Assessment) of the AVG describes when a DPIA must be conducted. To provide more interpretation of the requirements in Article 35, the Working Party of European Privacy Supervisors (WP29) has drafted additional frameworks that are also published on the site of the Autoriteit Persoonsgegevens (AP).

The Data Privacy Impact Analysis Checklist is derived from these frameworks and serves as a guide for determining when it is mandatory to conduct a DPIA.
Click on the link below to view the Data Privacy Impact Analysis Checklist.
source: IBD
