No. 24 of 2019
Data Protection
[Subsidiary]
PART VIII – DATA PROTECTION IMPACT ASSESSMENT
49. Processing activities requiring data protection impact assessment
(1) For the purpose of section 31 (1) of the Act, processing operations considered to
result in high risks to the rights and freedoms of a data subject include —
(a)
automated decision making with legal or similar significant effect that includes
the use of profiling or algorithmic means or use of sensitive personal data as
an element to determine access to services or that results in legal or similarly
significant effects;
(b)
use of personal data on a large-scale for a purpose other than that for which
the data was initially collected;
(c)
processing biometric or genetic data;
(d)
where there is a change in any aspect of the processing that may result in
higher risk to data subjects;
(e)
processing sensitive personal data or data relating to children or vulnerable
groups;
(f)
combining, linking or cross-referencing separate datasets where the data sets
are combined from different sources and where processing is carried out for
different purposes;
(g)
large scale processing of personal data;
(h)
a systematic monitoring of a publicly accessible area on a large scale;
(i)
innovative use or application of new technological or organizational solutions;
or
(j)
where the processing prevents a data subject from exercising a right.
(2) A data processor or data controller shall, prior to processing data under subregulation (1) conduct a data protection impact assessment.
50. Conduct of data protection impact assessment
(1) Where a data protection impact assessment is required, a data controller or data
processor may conduct the assessment through a template set out in the Third Schedule.
(2) Despite sub-regulation (1), a format of the data protection impact assessment may
be varied by the Data Commissioner through guidance notes as may be issued from time
to time.
51. Prior consultation
(1) In accordance with section 31 (3) of the Act, where a data controller or a data
processor is required to consult the Data Commissioner on the data protection impact
assessment prior to processing, such consultations shall be done within sixty days from the
date of the receipt of the impact statement report.
(2) In making a request under sub-regulation (1), the data controller or data processor
shall provide—
(a)
the data protection impact assessment prepared under section 31(1) of the
Act; and
(b)
where applicable, the respective responsibilities of the data controller or data
processors involved in the processing.
(3) Where the Data Commissioner considers that the intended processing is likely to
infringe on the Act or these Regulations, the Data Commissioner may issue such advice to
the data controller or the data processor, in writing.
52. Consideration of the data protection impact assessment report
(1) In conducting a data protection impact assessment, a data controller or a data
processor may consult the Office for advice on whether risks identified and mitigation
measures suggested are viable in the outlined circumstances.
36