Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Datenschutz-Folgenabschätzung/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Sala (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „ According to the General Data Protection Regulation, it must be documented and decided for each processing activity whether a data protection impact assessmen…“
 
Isan (Diskussion | Beiträge)
Keine Bearbeitungszusammenfassung
 
(139 dazwischenliegende Versionen von 4 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:


According to the General Data Protection Regulation, it must be documented and decided for each processing activity whether a data protection impact assessment (DPIA) is to be carried out. This is done in the course of a data protection impact assessment requirement assessment.  
According to the General Data Protection Regulation, it must be documented and decided for each processing activity whether a data protection impact assessment (DPIA) is to be carried out. This is done in the course of a data protection impact assessment necessity test.  


Related processing activities may be subject to the same DPIA necessity test to declare that a DPIA is or is not necessary for the processing activity.
Related processing activities may be subject to the same DPIA necessity test to declare that a DPIA is or is not necessary for the processing activity.


A DPIA in HITGuard combines the DPIA requirement check and the subsequent DPIA. First, the requirement check is performed and then, depending on the result of the check, the documentation step can either be completed or a DPIA must consequently be performed and thus documented.
A DPIA in HITGuard combines the DPIA necessity test and the subsequent DPIA. First, the necessity test is performed and then, depending on the result of the test, the documentation step can either be completed or a DPIA must consequently be performed and thus documented.


In HITGuard, these DPIA can be found and managed under the menu item "Privacy → DPIA".
In HITGuard, these DPIA can be found and managed under the menu item "Data protection → DPIA".


There is also the possibility to store existing DPIA documents.
There is also the possibility to store existing DPIA documents.


<b>Important:</b>
<b>Important:</b> A standard DPIA report and likewise a report for the consultation with the data protection authority can be prepared.<p>
A standard DPIA report and likewise a report for consultation with the data protection authority can be prepared.
<u>Note</u>: If you need less help but more space for filling in the DPIA, you can collapse the right part and hide the explanations.
 


<span id="DSFA"></span>
== DPIA ==
== DPIA ==


To create a DPIA, click the "Plus" button in the DPIA overview ("Privacy → DPIA").
To create a DPIA, click the "Plus" button in the DPIA overview ("Data protection → DPIA").


To edit a DPIA, double-click on the desired DPIA.
To edit a DPIA, double-click on the desired DPIA.


In the following picture you can find an overview of all DPIA:
In the following picture you can see an overview of all DPIAs:


[[Datei:DSFA Übersicht.PNG|left|thumb|900px|Overview of the DPIA]]
[[Datei:DSFA Übersicht.PNG|left|thumb|901px|Overview of the DPIAs]]
<br clear=all>
<br clear=all>


<u>Hint</u>: Many of the DPIA's steps offer additional explanatory texts in the right half of the assistant. If you do not need those and wish to hide them, they can be collapsed with the arrow in the top right.
<span id="Überprüfungsdetails"></span>
=== Review details ===
=== Review details ===


The following describes the verification details of a DPIA.
The following describes the review details of a DPIA.


[[Datei:DSFA Schritt 1 Überprüfungsdetails.PNG|left|thumb|900px|Review details]]
[[Datei:DSFA Schritt 1 Überprüfungsdetails.PNG|left|thumb|900px|Review details]]
<br clear=all>
<br clear=all>


<u>Designation:</u>
<u>Name:</u> A name for the DPIA is assigned here.
* A designation for the DPIA is assigned here.


<u>Confirmers:</u>
<u>Confirmer:</u> Owners, directors, officers or other legally appointed corporate officers.
* Owners, directors, officers or other legally appointed corporate officers.


<u>Processors:</u>
<u>Advisor:</u> Those persons who are responsible for the processing activity in the company.
* Those persons who are responsible for the processing activity in the company.


<u>Auditor:</u>
<u>Examiner:</u> The person who processes the DPIA. The user who creates the DPIA in HITGuard is suggested.
* The person who processes the DPIA. The user who creates the DPIA in HITGuard is suggested.


<u>Version date:</u>
<u>Version date:</u> A date for the version of the DPIA <b>must</b> be entered here.
* Here <b>must</b> be entered a date for the version of the DPIA.


<u>Version number:</u>
<u>Version number:</u> A version number for the DPIA <b>must</b> be entered here. This is for historization purposes.
* Here <b>must</b> be entered a version number for the DPIA. This is for historization purposes.


<u>Assigned processing activities:</u>
<u>Assigned processing activities:</u>
* Here, processing activities can be assigned to the DPIA. The DPIA applies to <b>all</b> assigned processing activities.
* Here, processing activities can be assigned to the DPIA. The DPIA applies to <b>all</b> assigned PAs.
* A processing activity can only be assigned to a DPIA if it does not yet belong to any DPIA.
* A PA can only be assigned to a DPIA if it does not yet belong to any DPIA.
* Main processing activity: The data of this processing activity are loaded as a result of the DPIA.
* Main PA: The data of this processing activity are used as the basis for the DPIA and its content, such as linked TOMs, are loaded in. Further PAs can be assigned to the DPIA in order for the DPIA to also apply to them. The further PAs should describe similar processes with similarly high risks. Once at least one PA is linked with the DPIA, one of them must be set as the main PA.
* No deactivated processing activities are available.
* If a processing activity is deactivated, it marked as deactivated here.


=== Necessity test ===
=== Necessity test ===
Zeile 63: Zeile 62:
# It is an exception to the DPIA.
# It is an exception to the DPIA.
# The necessity of the DPIA is specified.
# The necessity of the DPIA is specified.
# A threshold analysis is performed to determine whether a DPIA is necessary.
# A threshold analysis is performed to determine whether a DPIA seems necessary.


A DPIA necessity check or a DPIA may apply to related processing activities. This is the case if the processing activity address a similar risk. Therefore, it is possible to link several processing activities to the DPIA in the verification details. The processing activity marked as "Main processing activity" is the basis from which HITGuard draws the collected information from the processing activity (e.g., data categories, resources used, etc.) in the DPIA steps of the wizard.
A DPIA necessity test or a DPIA may apply to related processing activities. This is the case if the processing activity addresses a similar risk. Therefore, it is possible to link several processing activities to the DPIA in the review details. The processing activity marked as "Main processing activity" is the basis from which HITGuard draws the collected information from the processing activity (e.g., data categories, resources used, etc.) in the DPIA steps of the wizard.


<span id="Ausnahme_von_der_DSFA"></span>
==== Exception to the DSFA ====
==== Exception to the DSFA ====


There are cases in which it is not necessary to conduct a data protection impact assessment. These include, among others:  
There are cases in which it is not necessary to conduct a data protection impact assessment. These include, among others:  


<u>Anticipation:</u>
<u>Anticipation:</u> If the processing activities have been reviewed and approved by the data protection authority before May 2018 and have not changed, the data protection impact assessment may be omitted.
:If the processing activities have been reviewed and approved by the data protection authority before May 2018 and have not changed, the data protection impact assessment may be omitted.


<u>Whitelisting:</u>
<u>Whitelisting:</u> If the processing activity is on the list of types of processing activities that do not require a DPIA that the supervisory authority may establish (Art. 35(5)), the DPIA may be omitted.
:If the processing activity is on the list of types of processing activities that do not require a DPIA that the supervisory authority may establish (Art. 35(5)), the DPIA may be omitted.


<u>Similarity assessment:</u>.
<u>Similarity assessment:</u> If the review of similar processing activities reveals similarly high risks due to their nature, scope, circumstances and purpose, then a data protection impact assessment may be carried out jointly (Art. 35 (1) GDPR).  
:If the review of similar processing activities reveals similarly high risks due to their nature, scope, circumstances and purpose, then a data protection impact assessment may be carried out jointly (Art. 35 (1) GDPR).  


Depending on whether it is an exception or not, this concludes the necessity test and the DPIA is done or continues to the next step.
Depending on whether it is an exception or not, either this concludes the necessity test and the DPIA is completed, or it continues with the next step.


<b>Important:</b>  
<b>Important:</b>  
If "Yes" is selected, reasons must be given as to why no data protection impact assessment is to be carried out!
:* If "Yes" is selected, reasons must be given as to why no data protection impact assessment is to be carried out!
Yes" means that the necessity test has been completed and no further test steps need to be performed.
:* "Yes" means that the necessity test has been completed and no further test steps need to be performed.
:* If "Yes" is selected, step 6 Consultations and step 7 DPIA result are not deactivated, as that information can still optionally be documented for purposes of completeness. In step 7 one would then choose the option showing that the processing activity complies with data protection guidelines.


[[Datei:DSFA Schritt 2.1 Ausnahme.PNG|left|thumb|900px|Exception to the DPIA]]
[[Datei:DSFA Schritt 2.1 Ausnahme.PNG|left|thumb|900px|Exception to the DPIA]]
<br clear=all>
<br clear=all>


<span id="Erforderlichkeit_der_DSFA_vorgegeben"></span>
==== Necessity of the DPIA specified ====
==== Necessity of the DPIA specified ====


Zeile 94: Zeile 93:


There are cases where it is mandatory to perform a data protection impact assessment. These include:  
There are cases where it is mandatory to perform a data protection impact assessment. These include:  
* Art. 35(3) GDPR:
* Art. 35 (3) GDPR: Concerns automated processing including profiling, extensive processing of special categories of personal data or criminal convictions and offences, and systematic, extensive monitoring of publicly accessible areas.
:: Concerns automated processing including profiling, extensive processing of special categories of personal data or criminal convictions and offences, and systematic, extensive monitoring of publicly accessible areas.


* Mention on the blacklist:  
* Mention on the blacklist: The supervisory authority draws up a list of processing activities for which a DPIA must be performed. Once this list has been published, it must be taken into account here.
:: The supervisory authority draws up a list of processing activities for which a DPIA must be performed. Once this list has been published, it must be taken into account here.


Additionally, a rationale for the decision can be recorded.
Additionally, a rationale for the decision can be recorded.


<b>Important:</b>
<b>Important:</b> "Yes" skips the "Threshold analysis" item, as a DPIA is definitely to be performed.
:* "Yes" skips the "Threshold Analysis" item, as DPIA is definitely to be performed.


[[Datei:DSFA Schritt 2.2 Erforderlichkeit.PNG|left|thumb|900px|Necessity of the DPIA specified]]
[[Datei:DSFA Schritt 2.2 Erforderlichkeit.PNG|left|thumb|900px|Necessity of the DPIA specified]]
<br clear=all>
<br clear=all>


<span id="Schwellwertanalyse"></span>
==== Threshold analysis ====
==== Threshold analysis ====


Sofern die Erforderlichkeit einer DSFA nicht durch eine klare Verpflichtung zur Durchführung bzw. Nicht-Durchführung vorgegeben ist, liegt es im Ermessen des Verantwortlichen die Erforderlichkeit der Durchführung der DSFA zu beurteilen.
If the necessity of a DPIA is not specified by a clear obligation to perform or not perform it, it is at the discretion of the examiner to assess the necessity of performing the DPIA.
Dabei helfen die Angaben der Art. 29 Datenschutzgruppe. Die Handhabung der Liste der Kriterien ist wie folgt, mittels einer Faustregel zu empfehlen: Ein hohes Risiko besteht jedenfalls, wenn mindestens zwei der Kriterien erfüllt sind. In diesem Fall sollte eine DSFA durchgeführt werden.
The information provided by the Art. 29 Data Protection Working Party will help in this regard. The handling of the list of criteria is recommended using a rule of thumb as follows: A high risk exists in any case if at least two of the criteria of WP 248 (bottom) or at least one of the criteria of Art. 35 GDPR (top) are met. In this case a DPIA should be carried out.


Um herauszufinden welche Kriterien erfüllt werden, sollte zuerst das Working Paper "248 Kriterien des europäischen Datenschutzausschusses" durchgegangen werden!
In order to find out which criteria are met, the working paper "248 Criteria of the European Data Protection Board" should be reviewed first!


Im Anschluss <b>muss</b> entschieden werden, ob eine DSFA durchzuführen ist. Für diese Entscheidung <b>muss</b> eine Begründung festgehalten werden.
Subsequently, a decision <b>must</b> be made as to whether a DPIA is to be performed. A justification for this decision <b>must</b> be recorded.


[[Datei:DSFA Schritt 2.3 Schwellwertanalyse.PNG|left|thumb|900px|Erforderlichkeit der DSFA vorgegeben]]
[[Datei:DSFA Schritt 2.3 Schwellwertanalyse.PNG|left|thumb|900px|Threshold analysis]]
<br clear=all>
<br clear=all>


=== Vorhandene DSFA  ===
<span id="Vorhandene_DSFA"></span>
=== Existing DPIA ===


Die DSFA-Erforderlichkeitsprüfung sollte zu jeder Verarbeitungstätigkeit durchgeführt werden. Mit HITGuard können diese Überprüfungsschritte nachweislich dokumentiert werden. In manchen Fällen ist die Erforderlichkeitsprüfung für das Verarbeitungsregister zu dokumentieren. Die DSFA wurde aber bereits durchgeführt, wenn diese zum Beispiel gemeinsam mit einem externen Berater erstellt wurde. In diesem Fall möchten Sie ggf. keine weitere DSFA mehr in HITGuard dokumentieren. Für die zentrale Sammlung Ihrer Dokumente im Falle einer behördlichen Kontaktaufnahme möchten Sie alle Dokumente in HITGuard zusammenführen. In diesem Fall können Sie in diesem Schritt kennzeichnen, dass eine DSFA bereits erfolgt ist. Laden Sie den DSFA Bericht hier hoch und legen Sie fest, dass in HITGuard keine weiteren DSFA Dokumentationsschritte mehr durchzuführen sind.
The DPIA necessity test should be performed for every processing activity. With HITGuard, these review steps can be verifiably documented. In some cases, however, the necessity test must be documented for the processing register even though the DPIA has already been performed; for example, it was created together with an external consultant. In this case, you may not want to document another DPIA in HITGuard. For the central collection of your documents in case of contact by the authority, you might like to merge all documents in HITGuard. In this case, you can record that a DPIA has already been performed in this step. Upload the DPIA report here and specify that no further DPIA documentation steps are to be performed in HITGuard.


<b>Wichtig:</b>
<b>Important:</b> Setting the "DPIA already done" will disable the following steps of the DPIA , because the DPIA is already in place.
:* Durch Setzen des "DSFA bereits durchgeführt" werden die nachfolgenden Schritte der DSFA deaktiviert, da die DSFA bereits vorhanden ist.


[[Datei:DSFA Schritt 3 DSFA vorhanden.PNG|left|thumb|900px|Vorhandene DSFA]]
[[Datei:DSFA Schritt 3 DSFA vorhanden.PNG|left|thumb|900px|Existing DPIA]]
<br clear=all>
<br clear=all>


=== Informationen zur Verarbeitung ===
=== Processing information ===
----
----
Wenn eine DSFA in HITGuard durchzuführen ist, sind zunächst die geplanten Verarbeitungstätigkeiten zu beschreiben.
If a DPIA is to be performed in HITGuard, the planned processing activities must first be described.


Art. 35 Abs. 7 (a) DSGVO fordert eine systematische Beschreibung der geplanten Verarbeitungstätigkeiten inkl. dem Zwecke der Verarbeitung.
Art. 35 (7) (a) GDPR requires a systematic description of the planned processing activities including the purpose of the processing.
Dazu wird Ihnen von HITGuard aus der Haupt-Verarbeitungstätigkeit der dort bereits erfasste Zweck der Verarbeitung geladen. Sie können diese Information um zusätzliche Informationen wie Einsatzgebiet, Nutzer, etc. ergänzen.
For this purpose, HITGuard will load the purpose of processing already recorded there from the main processing activity. You can supplement this information with additional information, such as area of application, user, etc.


Auch die Zuständigkeiten für die Verarbeitung, wie den Verantwortlichen der Verarbeitungstätigkeit bzw. etwaige Auftragsverarbeiter und Informationen zur gemeinsamen Verarbeitung werden Ihnen aus der Haupt-VT präsentiert.
The responsibilities for processing, such as the person responsible for the processing activity or any processors and information on joint processing are also presented to you from the main processing activity.


[[Datei:DSFA Schritt 4 Informationen.PNG|left|thumb|900px|Informationen zur Verarbeitung]]
[[Datei:DSFA Schritt 4 Informationen.PNG|left|thumb|900px|Processing information]]
<br clear=all>
<br clear=all>


==== Normen und Standards ====
==== Norms and standards ====
In diesem Punkt sind Normen und Standards anzuführen, die für die Verarbeitung herangezogen werden. Darunter fallen auch Richtlinien  und Datenschutzzertifizierungen (Art. 42 DSGVO) sowie genehmigte Verhaltensregeln (Art 40 DSGVO).
In this item, norms and standards are to be listed which are used for the processing. This also includes guidelines and data protection certifications (Art. 42 GDPR) as well as approved codes of conduct (Art. 40 GDPR).


Genehmigte Verhaltensregeln werden häufig als „Code of Conduct“ bezeichnet. Sie werden von einem Zusammenschluss, z.B. einem Verband oder Verein wie Berufsverbänden oder Kammern veröffentlicht. Der Zusammenschluss gibt die genehmigten Verhaltensregeln als verbindliche Vorgaben aus, um die datenschutzrechtliche Verhaltensweisen der Mitglieder festzulegen. In der DSFA ist zu beschreiben, ob es genehmigte Verhaltensregeln gemäß Art. 40 DSGVO gibt, zu denen das Unternehmen sich bekennen und deren Anforderungen sie umsetzen bzw. einhalten.
Approved rules of conduct are often referred to as "codes of conduct". They are published by a federation or association, such as professional associations or chambers, for example. The association issues the approved rules of conduct as binding specifications to determine the data protection-related conduct of its members. The DPIA must describe whether there are approved rules of conduct pursuant to Art. 40 GDPR to which the company subscribes and whose requirements they implement and comply with.


[[Datei:DSFA Schritt 4.1 Normen.PNG|left|thumb|900px|Normen und Standards]]
[[Datei:DSFA Schritt 4.1 Normen.PNG|left|thumb|900px|Norms and standards]]
<br clear=all>
<br clear=all>


==== Daten und Betriebsmittel ====
==== Data and resources ====
In der DSFA ist unter diesem Punkt eine detaillierte Darstellung der geplanten Verarbeitungstätigkeiten, einschließlich folgender Informationen zu finden:
In the DPIA, a detailed description of the planned processing activities, including the following information, can be found under this item:
- alle verarbeiteten personenbezogenen Daten inklusive der Angaben zu Betroffenenkategorien, Empfänger und der Informationen zur Aufbewahrung der Daten
* all personal data processed, including information on categories of data subjects, recipients and information on the storage of the data
- der dafür eingesetzten Informationssysteme (= Betriebsmittel)
* the information systems used for this purpose (=operating resources)


HITGuard unterstützt Sie in diesem Punkt, da es alle relevanten Informationen dazu, die bereits in der Haupt-VT erfasst wurden, hier auflistet.
HITGuard supports you here, as it lists all relevant information about this that has already been recorded in the main processing activity.


[[Datei:DSFA Schritt 4.2 Daten.PNG|left|thumb|900px|Daten und Betriebsmittel]]
[[Datei:DSFA Schritt 4.2 Daten.PNG|left|thumb|900px|Data and resources]]
<br clear=all>
<br clear=all>


Hier kann außerdem eine Detaillierte Beschreibungen zu den eingesetzten IT-Betriebsmitteln erfasst werden. Weiters können Dokumente mit visualisierten Darstellungen zu IT-Betriebsmitteln und ihren Abhängigkeiten abgelegt werden.
Detailed descriptions of the IT resources used can also be recorded here. Furthermore, documents with visualized representations of IT resources and their dependencies can be stored.


[[Datei:DSFA Betriebmittel Datei.PNG|left|thumb|900px|Daten und Betriebsmittel: Datei hochladen]]
[[Datei:DSFA Betriebmittel Datei.PNG|left|thumb|900px|Data and resources: upload file]]
<br clear=all>
<br clear=all>


==== Lebenszyklus von Daten und Prozessen ====
<span id="Lebenszyklus_von_Daten_und_Prozessen"></span>
==== Lifecycle of data and processes ====


In diesem Punkt der DSFA ist eine detaillierte Darstellung der geplanten Verarbeitungstätigkeiten, einschließlich folgender Informationen zu erfassen:
In this item of the DPIA, a detailed account of the planned processing activities, including the following information, is to be recorded:
- Beschreibung der Prozessschritte für eine detaillierte Darstellung der Funktionsweise und der Abläufe der Verarbeitungstätigkeit
* Description of the process steps for a detailed account of how the processing activity will work and what will happen.
- Interne und externe Schnittstellen sowie Datenflüsse
* Internal and external interfaces as well as data flows.


Um die Erklärung zu verdeutlichen, können in diesem Schritt Dokumente wie Datenflussdiagramme beigelegt werden. Sie können neben der Erfassung einer ausführlichen Beschreibung auch ein Dokument hochladen.
To clarify the explanation, documents such as data flow diagrams can be attached in this step in addition to capturing a detailed description.


[[Datei:DSFA Schritt 4.3 Lebenszyklus.PNG|left|thumb|900px|Lebenszyklus von Daten und Prozessen]]
[[Datei:DSFA Schritt 4.3 Lebenszyklus.PNG|left|thumb|900px|Lifecycle of data and processes]]
<br clear=all>
<br clear=all>


==== Notwendigkeit und Verhältnismäßigkeit ====
<span id="Notwendigkeit_und_Verhältnismäßigkeit"></span>
==== Necessity and proportionality ====


In diesem Punkt der DSFA wird gemäß Art. 35 Abs. 7 (b) DSGVO die Notwendigkeit und Verhältnismäßigkeit der Verarbeitungstätigkeiten begründet.
In this point of the DPIA, the necessity and proportionality of the processing activities are justified in accordance with Art. 35 (7) (b) GDPR.


Dazu müssen mehrere Punkte geklärt werden:
To do this, several points need to be clarified:
* Rechtmäßigkeit der Verarbeitung:
* Description of the necessity and proportionality
:: Hier werden die Rechtmäßigkeiten der Verarbeitungen der einzelnen Datenkategorien aufgelistet. (Datenkategorien aus Haupt-VT)
:: The necessity and proportionality of the processing activity for the purpose can be explained here with regard to the following information.
* Zweckbindungsprinzip (Art. 5 Abs 1 b DSGVO):
* Lawfulness of processing (Art 5  (1) (a) DSGVO):
:: Es muss erklärt werden warum die Verarbeitungszwecke bestimmt, eindeutig definiert und rechtmäßig sind.
:: The lawfulness of the processing activities of each data category are listed here. (Data categories from main processing activity)
* Datenminimierung (Art. 5 Abs. 1 c DSGVO):
* Purpose limitation principle (Art. 5 (1) (b) GDPR):
:: Es muss erklärt werden warum die erhobenen Daten erforderlich, notwendig und relevant sind.
:: It must be explained why the processing purposes are determined, clearly defined and lawful.
* Richtigkeit (Art. 5 Abs. 1 d DSGVO):
* Data minimization (Art 5 (1) (c) GDPR):
:: Es muss beschrieben werden, welche Schritte unternommen werden um die Qualität der Daten (Korrektheit, Aktualität, etc.) sicherzustellen.
:: It must be explained why the data collected are necessary, required and relevant.
:: Es können Maßnahmen und Kontrollen, die die Qualität der Daten sicherstellen, verknüpft werden.
* Accuracy (Art 5 (1) (d) GDPR):
* Speicherbegrenzung (Art. 5 Abs. 1 e DSGVO):
:: It must be described what steps are taken to ensure the quality of the data (accuracy, timeliness, etc.).
:: Es muss die Speicherdauer (Löschfrist) der Daten inklusive Begründung für diese angegeben werden. Dies erfolgt allerdings schon im Schritt "Daten und Betriebsmittel" und wird daher hier nicht angeführt.
:: Measures and controls that ensure the quality of the data can be linked.
* Storage limitation (Art 5 (1) (e) GDPR):
:: The storage period (deletion period) of the data including the justification for this must be specified. However, this is already done in the step "Data and resources" and is therefore not listed here.


[[Datei:DSFA Schritt 4.4 Notwendigkeit 1.PNG|left|thumb|900px|Notwendigkeit und Verhältnismäßigkeit 1]]
[[Datei:DSFA Schritt 4.4 Notwendigkeit 1.PNG|left|thumb|901px|Necessity and proportionality 1]]
<br clear=all>
<br clear=all>
[[Datei:DSFA Schritt 4.4 Notwendigkeit 2.PNG|left|thumb|900px|Notwendigkeit und Verhältnismäßigkeit 2]]
[[Datei:DSFA Schritt 4.4 Notwendigkeit 2.PNG|left|thumb|901px|Necessity and proportionality 2]]
<br clear=all>
<br clear=all>


==== Persönlichkeitsrechte der Betroffenen ====
<span id="Persönlichkeitsrechte_der_Betroffenen"></span>
==== Personal rights of the data subjects ====


In diesem Punkt der DSFA wird erfasst was unternommen wird, um die Persönlichkeitsrechte der Betroffenen zu gewähren.
This point of the DPIA records what is done to grant the personal rights of the data subjects.


Dazu müssen mehrere Punkte der DSGVO geklärt werden:
Several points of the GDPR must be clarified for this purpose:
* Informationspflicht (Art 12-14 DSGVO) und Einwilligung des Betroffenen (Art. 6 DSGVO):
* Information obligation (Art 12-14 GDPR) and consent of the data subject (Art 6 GDPR):
:: Es muss beschrieben werden wie die Betroffenen über die Verarbeitung informiert werden, welche Informationen Ihnen auf welche Art und Weise zur Verfügung gestellt werden und wie die Einwilligung der Verarbeitung eingeholt wird, falls diese erforderlich ist.
:: It must be described how the data subjects are informed about the processing, which information is provided to you in which way and how the consent for the processing is obtained, if this is required.
:: Dafür können hier Maßnahmen und Kontrollen zum Nachweis der Einhaltung der Informationspflicht und Einwilligung des Betroffenen verknüpft werden.
:: For this purpose, measures and controls to demonstrate compliance with the information obligation and consent of the data subject can be linked here.
* Betroffenenrechte (Art 13-22 DSGVO):
* Data subject rights (Art 13-22 GDPR):
:: Es muss erklärt werden, wie Betroffene ihr Recht auf Auskunft, Berechtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragung und Widerspruch ausüben können.
:: It must be explained how data subjects can exercise their rights of access, authorization, erasure, restriction of processing, data transfer and objection.
:: Dafür können hier Maßnahmen und Kontrollen zum Nachweis der Einhaltung der Betroffenenrechte zugeordnet werden.
:: For this purpose, measures and controls to demonstrate compliance with data subjects' rights can be assigned here.
* Auftragsverarbeitung (Art 28 DSGVO):
* Commissioned processing (Art 28 GDPR):
:: Es muss erklärt werden, ob und warum die Verpflichtungen der Auftragsverarbeiter klar definiert und vertraglich geregelt sind.
:: It must be explained whether and why the obligations of the processors are clearly defined and contractually regulated.
:: Dazu wird eine Liste der Auftragsverarbeiter angezeigt. Diese kommen aus der Haupt-Verarbeitungstätigkeit.
:: For this purpose, a list of the processors is displayed. These come from the main processing activity.
* Datenübermittlung in Drittländer (Art 44-49 DSGVO):
* Data transfers to third countries (Art 44-49 GDPR):
:: Es muss erklärt werden, ob Datenübermittlungen in Länder außerhalb der EU stattfinden sowie ob und wie diese Daten angemessen geschützt werden.
:: It must be explained whether data transfers to countries outside the EU take place and whether and how these data are adequately protected.
:: Dazu wird eine Liste der Empfänger in Drittländer angezeigt. Diese kommt aus der Haupt-VT.
:: For this purpose, a list of recipients to third countries is displayed. This comes from the main processing activity.
* Standpunkt der Betroffenen
* Position of the data subjects
:: Es muss beschrieben ob und wie der Standpunkt der Betroffenen erhoben wurde.  
:: It must be described if and how the data subject's point of view was ascertained.  
:: Falls er nicht erhoben wurde muss dies begründet werden!
:: If it was not ascertained, this must be justified!


[[Datei:DSFA Schritt 4.5 Persönlichkeitsrechte 1.PNG|left|thumb|900px|Persönlichkeitsrechte der Betroffenen 1]]
[[Datei:DSFA Schritt 4.5 Persönlichkeitsrechte 1.PNG|left|thumb|900px|Personal rights of data subjects 1]]
<br clear=all>
<br clear=all>
[[Datei:DSFA Schritt 4.5 Persönlichkeitsrechte 2.PNG|left|thumb|900px|Persönlichkeitsrechte der Betroffenen 2]]
[[Datei:DSFA Schritt 4.5 Persönlichkeitsrechte 2.PNG|left|thumb|900px|Personal rights of data subjects 2]]
<br clear=all>
 
=== Risk assessment and measure planning ===
----
 
Risk assessment involves analyzing risks to the rights and freedoms of the data subjects. I.e., the analysis of the risk is carried out from the perspective of the data subject and not the company. In the process, risks are identified and assessed. This is done in the risk management area of HITGuard. The identified hazard situations - which largely correspond to the concept of risk used in the GDPR - can be linked to the DPIA here.
 
HITGuard decides on measures and controls to deal with the identified hazard situations. These measures and controls are presented by the tool itself in the DPIA on the basis of the linked hazard situations.
 
 
[[Datei:DSFA Schritt 5 Risikobewertung.PNG|left|thumb|900px|Risk assessment and measure planning]]
<br clear=all>
<br clear=all>


=== Risikobewertung und Maßnahmenplanung ===
=== Consultations ===
----
----


Bei der Risikobewertung werden Risiken für die Rechte und Freiheiten der betroffenen Personen analysiert. D.h. die Analyse des Risikos erfolgt aus der Sicht des Betroffenen und nicht des Unternehmens. Dabei werden Risiken identifiziert und bewertet. Dies erfolgt im Bereich des Risikomanagements von HITGuard. Die identifizierten Gefährdungslagen - die weitgehend dem in der DSGVO verwendeten Begriff des Risikos entsprechen - können hier mit der DSFA verknüpft werden.  
This item records whether the advice of the data protection officer has been sought and whether the data protection authority has been consulted.


Zu den identifizierten Gefährdungslagen werden in HITGuard Maßnahmen und Kontrollen zur Risikobehandlung beschlossen. Diese Maßnahmen und Kontrollen werden vom Tool selbstständig anhand der verknüpften Gefährdungslagen in der DSFA dargestellt.
Pursuant to Article 35 (2) of the GDPR, the examiner must seek the advice of the data protection officer when carrying out a DPIA, if a data protection officer has been appointed. This consultation, the result thereof, or reasons for not carrying it out can and should be documented here.


If a DPIA shows that the processing would result in a high risk, then the examiner must consult the supervisory authority before processing if they do not or cannot take measures to mitigate the risk. This step can also be documented here in HITGuard by recording the decision of the data protection authority or by referring to the DPIA report.


[[Datei:DSFA Schritt 5 Risikobewertung.PNG|left|thumb|900px|Risikobewertung und Maßnahmenplanung]]
[[Datei:DSFA Schritt 6 Konsultation.PNG|left|thumb|901px|Consultations  ]]
<br clear=all>
<br clear=all>


=== Konsultationen ===
===Result===
----
----


In diesem Punkt wird erfasst, ob der Rat des Datenschutzbeauftragten eingeholt wurde und ob die Datenschutzbehörde konsultiert wurde.
The result of the DPIA is recorded here.
 
It can be recorded here whether the assigned processing activities are in alignment with the data protection regulations and may therefore be carried out.  


Gemäß Art. 35 Abs. 2 DSGVO hat der Verantwortliche bei der Durchführung einer DSFA den Rat des Datenschutzbeauftragten einzuholen, wenn ein Datenschutzbeauftragter benannt wurde. Diese Konsultation bzw. das Ergebnis daraus oder Gründe für ihre Nicht-Durchführung können und sollen hier dokumentiert werden.
If the processing activities do not currently align with the data protection regulations, they may no longer be carried out. This is why it's possible to create and assign measures and controls that are meant to align the processing activities with the data protection regulations. Then they may be carried out again.


Wenn aus einer DSFA hervorgeht, dass die Verarbeitung ein hohes Risiko zur Folge hätte, dann muss der Verantwortliche vor der Verarbeitung die Aufsichtsbehörde konsultieren, falls er keine Maßnahmen zur Eindämmung des Risikos trifft oder treffen kann. Auch dieser Schritt ist hier in HITGuard dokumentierbar indem dem sie die Entscheidung der Datenschutzbehörde erfassen bzw. auf den DSFA Bericht verweisen.
The result selected here is also displayed in the last step of the assigned processing activities.


[[Datei:DSFA Schritt 6 Konsultation.PNG|left|thumb|901px|Konsultationen ]]
[[Datei:DSFA Schritt 7 Ergebnis.PNG|left|thumb|900px|Result]]
<br clear=all>
<br clear=all>

Aktuelle Version vom 7. März 2024, 10:25 Uhr

According to the General Data Protection Regulation, it must be documented and decided for each processing activity whether a data protection impact assessment (DPIA) is to be carried out. This is done in the course of a data protection impact assessment necessity test.

Related processing activities may be subject to the same DPIA necessity test to declare that a DPIA is or is not necessary for the processing activity.

A DPIA in HITGuard combines the DPIA necessity test and the subsequent DPIA. First, the necessity test is performed and then, depending on the result of the test, the documentation step can either be completed or a DPIA must consequently be performed and thus documented.

In HITGuard, these DPIA can be found and managed under the menu item "Data protection → DPIA".

There is also the possibility to store existing DPIA documents.

Important: A standard DPIA report and likewise a report for the consultation with the data protection authority can be prepared.

Note: If you need less help but more space for filling in the DPIA, you can collapse the right part and hide the explanations.

DPIA

To create a DPIA, click the "Plus" button in the DPIA overview ("Data protection → DPIA").

To edit a DPIA, double-click on the desired DPIA.

In the following picture you can see an overview of all DPIAs:

Overview of the DPIAs


Hint: Many of the DPIA's steps offer additional explanatory texts in the right half of the assistant. If you do not need those and wish to hide them, they can be collapsed with the arrow in the top right.

Review details

The following describes the review details of a DPIA.

Review details


Name: A name for the DPIA is assigned here.

Confirmer: Owners, directors, officers or other legally appointed corporate officers.

Advisor: Those persons who are responsible for the processing activity in the company.

Examiner: The person who processes the DPIA. The user who creates the DPIA in HITGuard is suggested.

Version date: A date for the version of the DPIA must be entered here.

Version number: A version number for the DPIA must be entered here. This is for historization purposes.

Assigned processing activities:

  • Here, processing activities can be assigned to the DPIA. The DPIA applies to all assigned PAs.
  • A PA can only be assigned to a DPIA if it does not yet belong to any DPIA.
  • Main PA: The data of this processing activity are used as the basis for the DPIA and its content, such as linked TOMs, are loaded in. Further PAs can be assigned to the DPIA in order for the DPIA to also apply to them. The further PAs should describe similar processes with similarly high risks. Once at least one PA is linked with the DPIA, one of them must be set as the main PA.
  • No deactivated processing activities are available.
  • If a processing activity is deactivated, it marked as deactivated here.

Necessity test


The necessity test is the step towards knowing whether a DPIA needs to be performed for the assigned processing activities.

To assess whether a DPIA is necessary, three cases are distinguished:

  1. It is an exception to the DPIA.
  2. The necessity of the DPIA is specified.
  3. A threshold analysis is performed to determine whether a DPIA seems necessary.

A DPIA necessity test or a DPIA may apply to related processing activities. This is the case if the processing activity addresses a similar risk. Therefore, it is possible to link several processing activities to the DPIA in the review details. The processing activity marked as "Main processing activity" is the basis from which HITGuard draws the collected information from the processing activity (e.g., data categories, resources used, etc.) in the DPIA steps of the wizard.

Exception to the DSFA

There are cases in which it is not necessary to conduct a data protection impact assessment. These include, among others:

Anticipation: If the processing activities have been reviewed and approved by the data protection authority before May 2018 and have not changed, the data protection impact assessment may be omitted.

Whitelisting: If the processing activity is on the list of types of processing activities that do not require a DPIA that the supervisory authority may establish (Art. 35(5)), the DPIA may be omitted.

Similarity assessment: If the review of similar processing activities reveals similarly high risks due to their nature, scope, circumstances and purpose, then a data protection impact assessment may be carried out jointly (Art. 35 (1) GDPR).

Depending on whether it is an exception or not, either this concludes the necessity test and the DPIA is completed, or it continues with the next step.

Important:

  • If "Yes" is selected, reasons must be given as to why no data protection impact assessment is to be carried out!
  • "Yes" means that the necessity test has been completed and no further test steps need to be performed.
  • If "Yes" is selected, step 6 Consultations and step 7 DPIA result are not deactivated, as that information can still optionally be documented for purposes of completeness. In step 7 one would then choose the option showing that the processing activity complies with data protection guidelines.
Exception to the DPIA


Necessity of the DPIA specified

Unlike the previous point, this one assumes that there is no exception to the DPIA.

There are cases where it is mandatory to perform a data protection impact assessment. These include:

  • Art. 35 (3) GDPR: Concerns automated processing including profiling, extensive processing of special categories of personal data or criminal convictions and offences, and systematic, extensive monitoring of publicly accessible areas.
  • Mention on the blacklist: The supervisory authority draws up a list of processing activities for which a DPIA must be performed. Once this list has been published, it must be taken into account here.

Additionally, a rationale for the decision can be recorded.

Important: "Yes" skips the "Threshold analysis" item, as a DPIA is definitely to be performed.

Necessity of the DPIA specified


Threshold analysis

If the necessity of a DPIA is not specified by a clear obligation to perform or not perform it, it is at the discretion of the examiner to assess the necessity of performing the DPIA. The information provided by the Art. 29 Data Protection Working Party will help in this regard. The handling of the list of criteria is recommended using a rule of thumb as follows: A high risk exists in any case if at least two of the criteria of WP 248 (bottom) or at least one of the criteria of Art. 35 GDPR (top) are met. In this case a DPIA should be carried out.

In order to find out which criteria are met, the working paper "248 Criteria of the European Data Protection Board" should be reviewed first!

Subsequently, a decision must be made as to whether a DPIA is to be performed. A justification for this decision must be recorded.

Threshold analysis


Existing DPIA

The DPIA necessity test should be performed for every processing activity. With HITGuard, these review steps can be verifiably documented. In some cases, however, the necessity test must be documented for the processing register even though the DPIA has already been performed; for example, it was created together with an external consultant. In this case, you may not want to document another DPIA in HITGuard. For the central collection of your documents in case of contact by the authority, you might like to merge all documents in HITGuard. In this case, you can record that a DPIA has already been performed in this step. Upload the DPIA report here and specify that no further DPIA documentation steps are to be performed in HITGuard.

Important: Setting the "DPIA already done" will disable the following steps of the DPIA , because the DPIA is already in place.

Existing DPIA


Processing information


If a DPIA is to be performed in HITGuard, the planned processing activities must first be described.

Art. 35 (7) (a) GDPR requires a systematic description of the planned processing activities including the purpose of the processing. For this purpose, HITGuard will load the purpose of processing already recorded there from the main processing activity. You can supplement this information with additional information, such as area of application, user, etc.

The responsibilities for processing, such as the person responsible for the processing activity or any processors and information on joint processing are also presented to you from the main processing activity.

Processing information


Norms and standards

In this item, norms and standards are to be listed which are used for the processing. This also includes guidelines and data protection certifications (Art. 42 GDPR) as well as approved codes of conduct (Art. 40 GDPR).

Approved rules of conduct are often referred to as "codes of conduct". They are published by a federation or association, such as professional associations or chambers, for example. The association issues the approved rules of conduct as binding specifications to determine the data protection-related conduct of its members. The DPIA must describe whether there are approved rules of conduct pursuant to Art. 40 GDPR to which the company subscribes and whose requirements they implement and comply with.

Norms and standards


Data and resources

In the DPIA, a detailed description of the planned processing activities, including the following information, can be found under this item:

  • all personal data processed, including information on categories of data subjects, recipients and information on the storage of the data
  • the information systems used for this purpose (=operating resources)

HITGuard supports you here, as it lists all relevant information about this that has already been recorded in the main processing activity.

Data and resources


Detailed descriptions of the IT resources used can also be recorded here. Furthermore, documents with visualized representations of IT resources and their dependencies can be stored.

Data and resources: upload file


Lifecycle of data and processes

In this item of the DPIA, a detailed account of the planned processing activities, including the following information, is to be recorded:

  • Description of the process steps for a detailed account of how the processing activity will work and what will happen.
  • Internal and external interfaces as well as data flows.

To clarify the explanation, documents such as data flow diagrams can be attached in this step in addition to capturing a detailed description.

Lifecycle of data and processes


Necessity and proportionality

In this point of the DPIA, the necessity and proportionality of the processing activities are justified in accordance with Art. 35 (7) (b) GDPR.

To do this, several points need to be clarified:

  • Description of the necessity and proportionality
The necessity and proportionality of the processing activity for the purpose can be explained here with regard to the following information.
  • Lawfulness of processing (Art 5 (1) (a) DSGVO):
The lawfulness of the processing activities of each data category are listed here. (Data categories from main processing activity)
  • Purpose limitation principle (Art. 5 (1) (b) GDPR):
It must be explained why the processing purposes are determined, clearly defined and lawful.
  • Data minimization (Art 5 (1) (c) GDPR):
It must be explained why the data collected are necessary, required and relevant.
  • Accuracy (Art 5 (1) (d) GDPR):
It must be described what steps are taken to ensure the quality of the data (accuracy, timeliness, etc.).
Measures and controls that ensure the quality of the data can be linked.
  • Storage limitation (Art 5 (1) (e) GDPR):
The storage period (deletion period) of the data including the justification for this must be specified. However, this is already done in the step "Data and resources" and is therefore not listed here.
Necessity and proportionality 1


Necessity and proportionality 2


Personal rights of the data subjects

This point of the DPIA records what is done to grant the personal rights of the data subjects.

Several points of the GDPR must be clarified for this purpose:

  • Information obligation (Art 12-14 GDPR) and consent of the data subject (Art 6 GDPR):
It must be described how the data subjects are informed about the processing, which information is provided to you in which way and how the consent for the processing is obtained, if this is required.
For this purpose, measures and controls to demonstrate compliance with the information obligation and consent of the data subject can be linked here.
  • Data subject rights (Art 13-22 GDPR):
It must be explained how data subjects can exercise their rights of access, authorization, erasure, restriction of processing, data transfer and objection.
For this purpose, measures and controls to demonstrate compliance with data subjects' rights can be assigned here.
  • Commissioned processing (Art 28 GDPR):
It must be explained whether and why the obligations of the processors are clearly defined and contractually regulated.
For this purpose, a list of the processors is displayed. These come from the main processing activity.
  • Data transfers to third countries (Art 44-49 GDPR):
It must be explained whether data transfers to countries outside the EU take place and whether and how these data are adequately protected.
For this purpose, a list of recipients to third countries is displayed. This comes from the main processing activity.
  • Position of the data subjects
It must be described if and how the data subject's point of view was ascertained.
If it was not ascertained, this must be justified!
Personal rights of data subjects 1


Personal rights of data subjects 2


Risk assessment and measure planning


Risk assessment involves analyzing risks to the rights and freedoms of the data subjects. I.e., the analysis of the risk is carried out from the perspective of the data subject and not the company. In the process, risks are identified and assessed. This is done in the risk management area of HITGuard. The identified hazard situations - which largely correspond to the concept of risk used in the GDPR - can be linked to the DPIA here.

HITGuard decides on measures and controls to deal with the identified hazard situations. These measures and controls are presented by the tool itself in the DPIA on the basis of the linked hazard situations.


Risk assessment and measure planning


Consultations


This item records whether the advice of the data protection officer has been sought and whether the data protection authority has been consulted.

Pursuant to Article 35 (2) of the GDPR, the examiner must seek the advice of the data protection officer when carrying out a DPIA, if a data protection officer has been appointed. This consultation, the result thereof, or reasons for not carrying it out can and should be documented here.

If a DPIA shows that the processing would result in a high risk, then the examiner must consult the supervisory authority before processing if they do not or cannot take measures to mitigate the risk. This step can also be documented here in HITGuard by recording the decision of the data protection authority or by referring to the DPIA report.

Consultations


Result


The result of the DPIA is recorded here.

It can be recorded here whether the assigned processing activities are in alignment with the data protection regulations and may therefore be carried out.

If the processing activities do not currently align with the data protection regulations, they may no longer be carried out. This is why it's possible to create and assign measures and controls that are meant to align the processing activities with the data protection regulations. Then they may be carried out again.

The result selected here is also displayed in the last step of the assigned processing activities.

Result