Article 35 of the GDPR lays down the legal obligation of data controllers to execute a Data Protection Impact Assessment (DPIA) when processing activities are likely to pose a significant risk to individual rights and freedoms. The GDPR outlines only the fundamental requirements for performing a DPIA, without detailing the process for its execution. Moreover, while National Privacy Authorities globally (such as CNIL, ICO., etc.) have issued guidelines for (D)PIAs, these primarily take the form of checklists and lack a full-fledged framework for step-by-step implementation of a DPIA and for evaluating the overall maturity level of an organization. This chapter introduces a novel, multi-faceted approach to privacy maturity that serves as a mechanism for the assessment and management of data protection risks. The methodology is designed to unlock the full potential of DPIAs in safeguarding fundamental rights as envisaged by the GDPR and to act as an all-encompassing instrument for legal compliance. This is achieved by integrating the GDPR’s legal requirements and best practices, with a qualitative and quantitative methods of analysis drawn from the field of information security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

EU Digital Law in the Artificial Intelligence (AI) Era: Towards a New Privacy Maturity Methodology

  • Kosmas Pipyros

摘要

Article 35 of the GDPR lays down the legal obligation of data controllers to execute a Data Protection Impact Assessment (DPIA) when processing activities are likely to pose a significant risk to individual rights and freedoms. The GDPR outlines only the fundamental requirements for performing a DPIA, without detailing the process for its execution. Moreover, while National Privacy Authorities globally (such as CNIL, ICO., etc.) have issued guidelines for (D)PIAs, these primarily take the form of checklists and lack a full-fledged framework for step-by-step implementation of a DPIA and for evaluating the overall maturity level of an organization. This chapter introduces a novel, multi-faceted approach to privacy maturity that serves as a mechanism for the assessment and management of data protection risks. The methodology is designed to unlock the full potential of DPIAs in safeguarding fundamental rights as envisaged by the GDPR and to act as an all-encompassing instrument for legal compliance. This is achieved by integrating the GDPR’s legal requirements and best practices, with a qualitative and quantitative methods of analysis drawn from the field of information security.