首页> 外文期刊>Computer law & security report >Data Protection Impact Assessment: A tool for accountability and the unclarified concept of 'high risk' in the General Data Protection Regulation
【24h】

Data Protection Impact Assessment: A tool for accountability and the unclarified concept of 'high risk' in the General Data Protection Regulation

机译:数据保护影响评估:一种问责工具和《通用数据保护条例》中未阐明的“高风险”概念

获取原文
获取原文并翻译 | 示例
           

摘要

Article 35 of the GDPR introduces the legal obligation to perform DPIAs in cases where the processing operations are likely to present high risks to the rights and freedoms of natural persons. This obligation is part of a change of approach in the GDPR towards a modified compliance scheme in terms of a reinforced principle of accountability. The DPIA is a prominent example of this approach given that it has an inclusive, comprehensive and proactive nature. Its importance lies in the fact that it forces data controllers to identify, assess and ultimately manage the high risks to the rights and freedoms. However, what is first and foremost important for a meaningful performance of DPIAs, is to have a common and objective understanding of what constitutes a risk in the field of data protection and of how to assess its likelihood and severity. The legislature has approached these concepts via the method of denotation, meaning by giving examples of (highly) risky processing operations. This article suggests a complementary approach, the connotation of these concepts and explains the added value of such a method. By way of a case-study the article also demonstrates the importance of performing complete and accurate DPIAs, in terms of contributing to improving the protection of personal data. (C) 2019 Katerina Demetzou. Published by Elsevier Ltd. All rights reserved.
机译:GDPR第35条规定了在加工操作可能对自然人的权利和自由构成高风险的情况下执行DPIA的法律义务。就加强责任制原则而言,此义务是GDPR朝着修订的合规计划转变方法的一部分。鉴于DPIA具有包容,全面和积极的性质,因此是该方法的一个突出示例。它的重要性在于,它迫使数据控制者识别,评估并最终管理权利和自由的高风险。但是,对于DPIA的有意义的表现而言,最重要的是要对数据保护领域中构成风险的风险以及如何评估其可能性和严重性达成共识。立法机关通过表示方法来处理这些概念,即通过举例说明(高度​​)高风险的处理操作。本文提出了一种补充方法,这些概念的含义并解释了这种方法的附加价值。通过案例研究,该文章还展示了执行完整而准确的DPIA的重要性,这有助于提高对个人数据的保护。 (C)2019卡特琳娜·德梅佐(Katerina Demetzou)。由Elsevier Ltd.出版。保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号