Recital 90
General Data Protection Regulation · UE 2016/679
| (90) | In such cases, a data protection impact assessment should be carried out by the controller prior to the processing in order to assess the particular likelihood and severity of the high risk, taking into account the nature, scope, context and purposes of the processing and the sources of the risk. That impact assessment should include, in particular, the measures, safeguards and mechanisms envisaged for mitigating that risk, ensuring the protection of personal data and demonstrating compliance with this Regulation. |
In Luxembourg, the CNPD has issued its own list of processings requiring a mandatory DPIA (decision of 16 October 2018), which complements the EDPB criteria with cases specific to the Luxembourg economic fabric (cross-border processings, financial big data, systematic HR profiling). The law of 1 August 2018 organising the CNPD further confirms the authority's injunction power, allowing it to require the production of a DPIA during an inspection, even after the fact.
Luxgap practice: for any high-risk processing operated by a Luxembourg entity (private bank, CSSF fintech, CAA insurer, investment fund), we systematically align the DPIA template with the CNPD list of 16 October 2018, and not solely with the EDPB criteria, to ensure direct enforceability during inspections.