Data protection impact assessment guidelines in the context of the general data protection regulation

dc.contributor.authorGrütter, Bodo Jeremy
dc.contributor.authorSchneider, Bettina
dc.contributor.editorDermol, Valerij
dc.date.accessioned2024-04-19T05:22:43Z
dc.date.available2024-04-19T05:22:43Z
dc.date.issued2019
dc.description.abstractThe European General Data Protection Regulation (EU GDPR) requires companies to carry out a so-called Data Protection Impact Assessment (DPIA) if the processing of personal data is likely to result in a high risk to the rights and freedoms of individuals. But how can it be determined whether a risk should be considered ‘high’ and thus makes a DPIA necessary? Furthermore, if a DPIA is required, how exactly should this be performed? In response to these questions, various guidelines concerning DPIA have been published. The aim of this paper is to give those affected by the new Data Protection law an insight into three current DPIA guidelines and to support them in implementing a GDPR-compliant impact assessment. To this end, each of the selected guidelines will be described, and evaluated in terms of GDPR compliance and DPIA feasibility, i.e. on the one hand, whether the guideline complies with the relevant GDPR articles, and on the other hand what tools are provided to facilitate the operational execution of a DPIA. The study results in an overall evaluation matrix, which shows that all three guidelines have different strengths and propose differing methods for DPIA implementation.
dc.description.urihttps://toknowpress.net/proceedings/978-961-6914-25-3/
dc.eventMakeLearn & TIIM International Conference 2019
dc.event.end2019-05-17
dc.event.start2019-05-15
dc.identifier.isbn978-961-6914-25-3
dc.identifier.urihttps://irf.fhnw.ch/handle/11654/42575
dc.identifier.urihttps://doi.org/10.26041/fhnw-6540
dc.language.isoen
dc.relation.ispartofThriving on Future Education, Industry, Business and Society. Proceedings of the MakeLearn and TIIM International Conference
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.spatialPiran
dc.subject.ddc330 - Wirtschaft
dc.titleData protection impact assessment guidelines in the context of the general data protection regulation
dc.type04B - Beitrag Konferenzschrift
dspace.entity.typePublication
fhnw.InventedHereYes
fhnw.ReviewTypeAnonymous ex ante peer review of a complete publication
fhnw.affiliation.hochschuleHochschule für Wirtschaft FHNWde_CH
fhnw.affiliation.institutInstitut für Wirtschaftsinformatikde_CH
fhnw.openAccessCategoryGold
fhnw.pagination261-270
fhnw.publicationStatePublished
relation.isAuthorOfPublication323b0cdd-bdb9-4cf1-ac09-730804daff93
relation.isAuthorOfPublication464101a1-e779-4cf9-9eaf-4e49af32283a
relation.isAuthorOfPublication.latestForDiscovery464101a1-e779-4cf9-9eaf-4e49af32283a
Dateien

Originalbündel

Gerade angezeigt 1 - 1 von 1
Vorschaubild
Name:
Gruetter_Schneider_Data_protection_impact_assessment_guidelines_2019.pdf
Größe:
1001.75 KB
Format:
Adobe Portable Document Format

Lizenzbündel

Gerade angezeigt 1 - 1 von 1
Kein Vorschaubild vorhanden
Name:
license.txt
Größe:
1.36 KB
Format:
Item-specific license agreed upon to submission
Beschreibung: