¶¶ÒõAPPµ¼º½

Data Protection Impact Assessment Process

In accordance with Article 35 of the GDPR and ¶¶ÒõAPPµ¼º½â€™s General Data Protection Regulation Compliance Standard, ¶¶ÒõAPPµ¼º½ engages in a Data Protection Impact Assessment (DPIA) where the processing of personal data subject to the GDPR may involve a high risk to the rights and freedoms of individuals. This includes situations involving processing activities of a large scale that involve special category or sensitive personal data or other high-risk situations such as when the processing activity is involves evaluation or scoring of individuals (profiling), automated decision-making, systematic monitoring, the matching or combining of datasets, vulnerable data subjects such as children or the elderly, or the innovative use of new data or technologies.

A DPIA is a documented assessment used to identify and mitigate privacy risks associated with processing activities such as research projects that involve processing personal data subject to the GDPR. To determine whether a DPIA is required for your project, or for more information regarding the process for completing a DPIA, please review the information below or contact the Data Protection Officer for guidance.

A DPIA is required where a processing activity is likely to result in a high-risk to the rights and freedoms of individuals including:

  • Large-scale processing of sensitive or special category personal data (e.g., clinical trials);
  • Profiling or evaluation of individuals;
  • Automated decision making;
  • Systematic monitoring;
  • Matching or combining datasets;
  • Processing activities involving vulnerable individuals such as children; and
  • Use of innovative technologies.

A completed DPIA generally includes:

  • A copy of the privacy notice provided to participants or informed consent document;
  • A data flow diagram showing how personal data moves through the project;
  • A privacy risk assessment and risk mitigation plan (if necessary) addressing identified risks and controls.

The applicable research team, faculty, department or administrative unit carrying out the project will be responsible for completing a DPIA. The DPIA will also need to be approved by the Information Steward (the Principal Investigator responsible for the research project or SLT member or designate responsible for the business processes in their faculty, functional area or department). 

The Data Protection Officer will maintain an oversight and advisory role, will provide guidance on GDPR obligations, monitor compliance, and assist with DPIAs. The Data Protection Officer will also cooperate with European privacy regulators during investigations, audits, consultations, or breach-related matters and be the primary liaison regarding GDPR compliance matters.

Frequently Asked Questions (FAQs)

Special category or sensitive personal data means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data (when processed to uniquely identify a person), data concerning health or data concerning an individual’s sex life or sexual orientation.

The DPIA process requires disclosure about the intended processing activity including the purposes of the processing, the categories of personal data collected, the number of data subjects affected, any sharing of the personal data with third parties such as collaborators or vendors, the legal basis for the processing, the security measures to protect the personal data, data flows, retention periods and the potential privacy risks associated with the project. 

A completed DPIA generally includes:

  • A copy of the privacy notice provided to participants or informed consent document;
  • A data flow diagram showing how personal data moves through the project; and
  • A privacy risk assessment and risk mitigation plan (if necessary) addressing identified risks and controls.

Questions about the DPIA requirements or completion of a DPIA should be directed to ¶¶ÒõAPPµ¼º½â€™s Data Protection Officer at dpo@ucalgary.ca.