GDPR发布以后,DPIA(Data Protection Impact Assessment)是数据控制者Data Controller 必须履行的一项安全职责(详见GDPR第35条)。
一、触发的时机:
DPIA应当前置评估,在如下这些场景实施前:
-
使用新技术:If you’re using new technologies
-
处理地理位置和行为信息(地理位置很容易理解,行为信息包括电子设备上的访问浏览行为信息):
If you’re tracking people’s location or behavior
-
大规模系统地监控公众空间(如:商场/街区/公共交通等公众空间的人脸监控、视频监控、智能监控等场景):
If you’re systematically monitoring a publicly accessible place on a large scale
-
处理个人相关数据(如:种族宗教、政治观点、生物遗传数据、健康和性取向数据等):
If you’re processing personal data related to “racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation”
-
自动化决策:If your data processing is used to make automated decisions about people that could have legal (or similarly significant) effects
-
处理儿童数据:If you’re processing children’s data
-
泄漏对人身安全造成隐患的:
If the data you’re processing could result in physical harm to the data subjects if it is leaked
Notice
GDPR 生效日期(2018年5月28日)前的项目/数据处理过程是否需要DPIA?
“法不溯既往”,针对生效前的项目/活动不强制要求进行DPIA,但对一些可能造成high risk的数据处理活动仍然是建议的;此外下列这些情况也是建议执行DPIA的:
- 在GDPR生效后数据处理操作发生了significant 的变化,使用了新技术、数据处理目的发生了变化, etc;
- 风险/风险等级发生变化,如:data, supporting assets, risk sources, etc 发生变化带来的变化;
- 组织或社会环境发生了变化:自动化决策影响的加剧(如:对信贷活动)、对社会相关群体造成了歧视、数据传输至脱欧国家(如:英国)。
最佳实践建议,每3年进行一次DPIA评估,活动、目的、环境等发生变化后需要重新进行DPIA。
二、How To
1、评估要点包括:
-
系统描述业务流程、目的和合法利益(业务的正当性):
A systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller
-
处理流程的必要性和相称性(必要、不过量的信息):
An assessment of the necessity and proportionality of the processing operations in relation to the purposes
-
评估可能对数据主体权益造成损害的风险(如:数据泄漏、数据滥用,对财产、名誉、隐私等造成的危害):
An assessment of the risks to the rights and freedoms of data subjects
-
给出安全措施、证明满足GDPR要求:
The measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with the GDPR, taking into account the rights and legitimate interests of data subjects and other persons concerned.
2、评估步骤:
- Identifying whether a DPIA is required.
- Defining the characteristics of the project to enable an assessment of the risks to take place.
- Identifying data protection and related risks.
- Identifying data protection solutions to reduce or eliminate the risks.
- Signing off on the outcomes of the DPIA.
- Integrating data protection solutions into the project.
官方文档模板:https://gdpr.eu/wp-content/uploads/2019/03/dpia-template-v1.pdf
3、哪些情况需要咨询DPC(监管机构)
- 已识别的风险无法管理,并且剩余风险仍然很高;
- 即使在前置工作流程中未咨询DPIA,在后续的审计或者调查过程中,DPC仍然可以查看企业DPIA及其过程信息。