The Information Commissioner’s Office (ICO) has recently updated its guidance on conducting DPIAs following guidance and recommendations from the European Data Protection Board.
A DPIA is mandatory if you are carrying out processing which is likely to result in a high risk to individuals. The GDPR requires controllers to go through a DPIA process if they plan to:
- use systematic and extensive automated processing (i.e. profiling) with legal or other significant effects;
- process special category or criminal offence data on a large scale; or
- carry out large scale systematic monitoring of a publicly accessible place.
But, the three examples of high risk processing identified in the GDPR are not exhaustive. The ICO’s newly updated guidance is helpful in determining whether those processing operations that do not fit neatly into one or more of the three categories above warrant a DPIA because they are high risk.
The ICO directs those who are assessing whether or not their processing is high risk to consider the guidelines on DPIAs (WP248 rev 01) adopted by the Article 29 Working Party and endorsed by the European Data Protection Board (the “European guidelines”). The European guidelines contain nine criteria for assessing high risk processing operations, summarised here:
- Evaluation or scoring, including profiling and predicting, especially from aspects concerning the data subject’s performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements.
- Automated-decision making with legal or similar significant effect.
- Systematic monitoring: processing used to observe, monitor or control data subjects, including data collected through networks or a systematic monitoring of a publicly accessible area.
- Sensitive data or data of a highly personal nature.
- Data processed on a large scale.
- Matching or combining datasets.
- Data concerning vulnerable data subjects e.g. children or employees.
- Innovative use or applying new technological or organisational solutions.
- When the processing in itself “prevents data subjects from exercising a right or using a service or a contract” e.g. screening or eligibility checks.
If your processing covers two or more of these criteria then the European guidelines state that a DPIA will be required in most cases but beware too that processing including only one of the criteria can also be high risk and require a DPIA. The European guidelines also contain useful examples as to how the criteria can be used effectively.
The ICO guidelines then provide a further list of processing operations in respect of which the ICO requires a DPIA:
- using innovative technology (in combination with any of the criteria from the European guidelines);
- using profiling or special category data to decide on access to services;
- profiling individuals on a large scale;
- processing biometric data (in combination with any of the criteria from the European guidelines);
- processing genetic data (in combination with any of the criteria from the European guidelines);
- matching data or combining datasets from different sources;
- collecting personal data from a source other than the individual without providing them with a privacy notice (‘invisible processing’);
- tracking individuals’ location or behaviour;
- profiling children or target marketing or online services at them; or
- processing data that might endanger the individual’s physical health or safety in the event of a security breach.
The ICO has to a certain degree relaxed its own criteria for determining high risk processing, in that a DPIA is now only mandatory for the use of biometric data, genetic data or innovative technology when combined with one of the criteria from the European guidelines.
Finally, a brief reminder as to why it is important to make the correct decision when it comes to DPIAs: failure to carry out a mandatory DPIA may result in enforcement action, including an administrative fine of up to €10 million, or 2% of global annual turnover if higher. So, it can’t be wrong to carry out a DPIA, the consequences can be serious if you are required to undertake a DPIA but fail to do so.
Sian Barr is a Senior Associate in the commerce & technology team at City law firm Fox Williams LLP and can be contacted at firstname.lastname@example.org