OPIA (Data Protection Impact Assessment) - template
When and how to perform DPO according to GDPR Art. 35.
The DPO is mandatory where processing may pose a high risk to personal data rights. Triggers: large volumes of profiling operations, systematic monitoring, bulk processing of sensitive data, new technologies. The structure of the DPO: 1) Description of processing - objectives, data flows, categories, storage periods; 2) Assessment of necessity and proportionality; 3) Risk assessment - data subjects' rights; 4) Measures to reduce risks - technical and organisational. If the remaining risk remains high, the Data State Inspectorate (DCI) should be consulted. DPIA should be reviewed regularly and subject to significant changes.