Process modeling of a data protection impact assessment (DPIA)
Project duration: 7 months
Brief description
Analysis and modelling of the process flow of a data protection impact assessment (DPIA) with BPMN. The aim is to provide the customer with a transparent presentation of the activities to be carried out within the scope of a DPIA. In addition, the model provides the customer with a tool for a uniform company-wide implementation and documentation of a DPIA.
Supplement
The DPIA process is documented with the modeling tool Visual Paradigm (version 14) in the standard notation language BPMN. The technical basis for the process model is the information available at the time of preparation of the new data protection basic regulation as well as the results of searches on the Internet (information from the authorities, white papers, etc.). In addition to the process-related description of the activities, documentation templates are created from which a structured documentation can be generated automatically. To support the practical implementation, a case study is created by filling the documentation templates with sample data.
Subject description
The new EU General Data Protection Regulation (GDPR), which will enter into force in May 2018, obliges companies to carry out a review of the necessity of conducting a data protection impact assessment (DPIA) for each data procedure (e. g. collection and processing of personal data). If sensitive personal data is processed in a certain form in the data procedure, it must be checked whether the data protection guidelines are adhered to. A risk assessment must be carried out with regard to the rights and freedom of the persons concerned and, if necessary, a catalogue of measures must be drawn up to eliminate or minimise the risks. This is done with the implementation of a so-called DPIA, which has a direct influence on the implementation of a data procedure. The DPIA must be documented uniformly and transparently in order to ensure traceability, especially for the supervisory authorities.