↓Skip to main content

The EU Charter and Data Processing Risk

·1 min

The EU Charter of Fundamental Rights has been legally binding since the Lisbon Treaty entered into force in December 2009. Article 35 of the GDPR requires a data protection impact assessment where processing is likely to result in a high risk to the rights and freedoms of natural persons — and those rights and freedoms extend well beyond data protection and privacy.

This reference maps all 54 articles across the Charter’s seven titles to data processing risks. It is not a checklist. It is a prompt — a way of ensuring that the rights assessment in a DPIA is not limited to the obvious ones.

Download the reference (PDF)


This document was produced as a companion to Issue 4 of the Purpose & Means Newsletter, part of a short series on data protection impact assessments.

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy notice privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts

No related posts found. Browse by topic above or visit the blog for all posts.