L 119/18
EN
Official Journal of the European Union
4.5.2016
protection impact assessment should also be made where personal data are processed for taking decisions
regarding specific natural persons following any systematic and extensive evaluation of personal aspects relating
to natural persons based on profiling those data or following the processing of special categories of personal
data, biometric data, or data on criminal convictions and offences or related security measures. A data protection
impact assessment is equally required for monitoring publicly accessible areas on a large scale, especially when
using optic-electronic devices or for any other operations where the competent supervisory authority considers
that the processing is likely to result in a high risk to the rights and freedoms of data subjects, in particular
because they prevent data subjects from exercising a right or using a service or a contract, or because they are
carried out systematically on a large scale. The processing of personal data should not be considered to be on a
large scale if the processing concerns personal data from patients or clients by an individual physician, other
health care professional or lawyer. In such cases, a data protection impact assessment should not be mandatory.
(92)
There are circumstances under which it may be reasonable and economical for the subject of a data protection
impact assessment to be broader than a single project, for example where public authorities or bodies intend to
establish a common application or processing platform or where several controllers plan to introduce a common
application or processing environment across an industry sector or segment or for a widely used horizontal
activity.
(93)
In the context of the adoption of the Member State law on which the performance of the tasks of the public
authority or public body is based and which regulates the specific processing operation or set of operations in
question, Member States may deem it necessary to carry out such assessment prior to the processing activities.
(94)
Where a data protection impact assessment indicates that the processing would, in the absence of safeguards,
security measures and mechanisms to mitigate the risk, result in a high risk to the rights and freedoms of natural
persons and the controller is of the opinion that the risk cannot be mitigated by reasonable means in terms of
available technologies and costs of implementation, the supervisory authority should be consulted prior to the
start of processing activities. Such high risk is likely to result from certain types of processing and the extent and
frequency of processing, which may result also in a realisation of damage or interference with the rights and
freedoms of the natural person. The supervisory authority should respond to the request for consultation within
a specified period. However, the absence of a reaction of the supervisory authority within that period should be
without prejudice to any intervention of the supervisory authority in accordance with its tasks and powers laid
down in this Regulation, including the power to prohibit processing operations. As part of that consultation
process, the outcome of a data protection impact assessment carried out with regard to the processing at issue
may be submitted to the supervisory authority, in particular the measures envisaged to mitigate the risk to the
rights and freedoms of natural persons.
(95)
The processor should assist the controller, where necessary and upon request, in ensuring compliance with the
obligations deriving from the carrying out of data protection impact assessments and from prior consultation of
the supervisory authority.
(96)
A consultation of the supervisory authority should also take place in the course of the preparation of a legislative
or regulatory measure which provides for the processing of personal data, in order to ensure compliance of the
intended processing with this Regulation and in particular to mitigate the risk involved for the data subject.
(97)
Where the processing is carried out by a public authority, except for courts or independent judicial authorities
when acting in their judicial capacity, where, in the private sector, processing is carried out by a controller whose
core activities consist of processing operations that require regular and systematic monitoring of the data subjects
on a large scale, or where the core activities of the controller or the processor consist of processing on a large
scale of special categories of personal data and data relating to criminal convictions and offences, a person with
expert knowledge of data protection law and practices should assist the controller or processor to monitor
internal compliance with this Regulation. In the private sector, the core activities of a controller relate to its
primary activities and do not relate to the processing of personal data as ancillary activities. The necessary level
of expert knowledge should be determined in particular according to the data processing operations carried out