No. 24 of 2019 Data Protection [Subsidiary] PART VIII – DATA PROTECTION IMPACT ASSESSMENT 49. Processing activities requiring data protection impact assessment (1) For the purpose of section 31 (1) of the Act, processing operations considered to result in high risks to the rights and freedoms of a data subject include — (a) automated decision making with legal or similar significant effect that includes the use of profiling or algorithmic means or use of sensitive personal data as an element to determine access to services or that results in legal or similarly significant effects; (b) use of personal data on a large-scale for a purpose other than that for which the data was initially collected; (c) processing biometric or genetic data; (d) where there is a change in any aspect of the processing that may result in higher risk to data subjects; (e) processing sensitive personal data or data relating to children or vulnerable groups; (f) combining, linking or cross-referencing separate datasets where the data sets are combined from different sources and where processing is carried out for different purposes; (g) large scale processing of personal data; (h) a systematic monitoring of a publicly accessible area on a large scale; (i) innovative use or application of new technological or organizational solutions; or (j) where the processing prevents a data subject from exercising a right. (2) A data processor or data controller shall, prior to processing data under subregulation (1) conduct a data protection impact assessment. 50. Conduct of data protection impact assessment (1) Where a data protection impact assessment is required, a data controller or data processor may conduct the assessment through a template set out in the Third Schedule. (2) Despite sub-regulation (1), a format of the data protection impact assessment may be varied by the Data Commissioner through guidance notes as may be issued from time to time. 51. Prior consultation (1) In accordance with section 31 (3) of the Act, where a data controller or a data processor is required to consult the Data Commissioner on the data protection impact assessment prior to processing, such consultations shall be done within sixty days from the date of the receipt of the impact statement report. (2) In making a request under sub-regulation (1), the data controller or data processor shall provide— (a) the data protection impact assessment prepared under section 31(1) of the Act; and (b) where applicable, the respective responsibilities of the data controller or data processors involved in the processing. (3) Where the Data Commissioner considers that the intended processing is likely to infringe on the Act or these Regulations, the Data Commissioner may issue such advice to the data controller or the data processor, in writing. 52. Consideration of the data protection impact assessment report (1) In conducting a data protection impact assessment, a data controller or a data processor may consult the Office for advice on whether risks identified and mitigation measures suggested are viable in the outlined circumstances. 36

Select target paragraph3