The EU Charter and Data Processing Risk
The EU Charter of Fundamental Rights has been legally binding since the Lisbon Treaty entered into force in December 2009. Article 35 of the GDPR requires a data protection impact assessment where processing is likely to result in a high risk to the rights and freedoms of natural persons — and those rights and freedoms extend well beyond data protection and privacy.
This reference maps all 54 articles across the Charter’s seven titles to data processing risks. It is not a checklist. It is a prompt — a way of ensuring that the rights assessment in a DPIA is not limited to the obvious ones.
This document was produced as a companion to Issue 4 of the Purpose & Means Newsletter, part of a short series on data protection impact assessments.
Browse by Topic
Related Posts
No related posts found. Browse by topic above or visit the blog for all posts.