Data Protection Impact Assessments (DPIAs) enable organisations to assess potential risks to individuals at the design stage of a new system or activity involving the use of personal data. Such risks can then be addressed within the development of the system or activity, rather than being a “bolt-on” after implementation (when it may be too late to address all the concerns, at least without significant cost implications).
DPIAs are required under the UK GDPR where the use of personal data is likely to result in a high risk to individuals. They are also an important part of data protection by design and by default, and may be a useful tool for lower-risk activities. Different approaches and levels of assessment can be undertaken depending on the nature of the system/activity and the risks involved.
This course gives practical guidance on conducting DPIAs, and includes:
- what is a DPIA, and when should one be carried out
- the ICO’s guidance and requirements for conducting DPIAs
- stages of a DPIA and what to do in practice: initial assessment, describing processing activities, assessing and addressing risks and compliance, recording outcomes, implementing solutions, and carrying out regular reviews
- other building blocks of DPIAs: the role of the DPO and processors, consultation with data subjects and (where needed) the ICO
- risk and compliance areas to consider
- a case study to put it into practice
Delegates who have attended this course will be fully equipped to conduct Data Protection Impact Assessments within their organisations.
Attendance on the Classroom and Virtual(Teams) formats of this course can be used as credit towards gaining the Practitioner Certificate in Data Protection.
“I found this course informative, detailed and helpful to my understanding of this subject.”