L 119/54
7.
EN
Official Journal of the European Union
4.5.2016
The assessment shall contain at least:
(a) a systematic description of the envisaged processing operations and the purposes of the processing, including, where
applicable, the legitimate interest pursued by the controller;
(b) an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
(c) an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
(d) the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the
protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and
legitimate interests of data subjects and other persons concerned.
8.
Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors
shall be taken into due account in assessing the impact of the processing operations performed by such controllers or
processors, in particular for the purposes of a data protection impact assessment.
9.
Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended
processing, without prejudice to the protection of commercial or public interests or the security of processing
operations.
10. Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the
Member State to which the controller is subject, that law regulates the specific processing operation or set of operations
in question, and a data protection impact assessment has already been carried out as part of a general impact assessment
in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be
necessary to carry out such an assessment prior to processing activities.
11. Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with
the data protection impact assessment at least when there is a change of the risk represented by processing operations.
Article 36
Prior consultation
1.
The controller shall consult the supervisory authority prior to processing where a data protection impact
assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken
by the controller to mitigate the risk.
2.
Where the supervisory authority is of the opinion that the intended processing referred to in paragraph 1 would
infringe this Regulation, in particular where the controller has insufficiently identified or mitigated the risk, the
supervisory authority shall, within period of up to eight weeks of receipt of the request for consultation, provide written
advice to the controller and, where applicable to the processor, and may use any of its powers referred to in Article 58.
That period may be extended by six weeks, taking into account the complexity of the intended processing. The
supervisory authority shall inform the controller and, where applicable, the processor, of any such extension within one
month of receipt of the request for consultation together with the reasons for the delay. Those periods may be
suspended until the supervisory authority has obtained information it has requested for the purposes of the
consultation.
3.
When consulting the supervisory authority pursuant to paragraph 1, the controller shall provide the supervisory
authority with:
(a) where applicable, the respective responsibilities of the controller, joint controllers and processors involved in the
processing, in particular for processing within a group of undertakings;
(b) the purposes and means of the intended processing;
(c) the measures and safeguards provided to protect the rights and freedoms of data subjects pursuant to this
Regulation;
(d) where applicable, the contact details of the data protection officer;