Recital 91

Recital 91

General Data Protection Regulation · UE 2016/679

(91)

This should in particular apply to large-scale processing operations which aim to process a considerable amount of personal data at regional, national or supranational level and which could affect a large number of data subjects and which are likely to result in a high risk, for example, on account of their sensitivity, where in accordance with the achieved state of technological knowledge a new technology is used on a large scale as well as to other processing operations which result in a high risk to the rights and freedoms of data subjects, in particular where those operations render it more difficult for data subjects to exercise their rights. A data protection impact assessment should also be made where personal data are processed for taking decisions regarding specific natural persons following any systematic and extensive evaluation of personal aspects relating to natural persons based on profiling those data or following the processing of special categories of personal data, biometric data, or data on criminal convictions and offences or related security measures. A data protection impact assessment is equally required for monitoring publicly accessible areas on a large scale, especially when using optic-electronic devices or for any other operations where the competent supervisory authority considers that the processing is likely to result in a high risk to the rights and freedoms of data subjects, in particular because they prevent data subjects from exercising a right or using a service or a contract, or because they are carried out systematically on a large scale. The processing of personal data should not be considered to be on a large scale if the processing concerns personal data from patients or clients by an individual physician, other health care professional or lawyer. In such cases, a data protection impact assessment should not be mandatory.

Luxembourg specificity
loi du 1er aout 2018 portant organisation de la CNPD + deliberation CNPD du 5 octobre 2018 sur la liste des traitements soumis a AIPD

In Luxembourg, the CNPD (not APDL, which does not exist) published on 5 October 2018 the list of processing operations subject to mandatory DPIA, supplemented by the list of operations for which a DPIA is not required. The law of 1 August 2018 organising the CNPD states that it may, based on Recital 91, require a DPIA for any processing it considers high-risk, even outside the positive list. Local specificity: municipal authorities and Luxembourg financial sector players (under CSSF supervision) are systematically deemed to operate at large scale as soon as they process resident data.

Luxgap practice: our DPIA Trigger Radar natively integrates the CNPD 5 October 2018 grid and specifically alerts when a processing activity ticks a CNPD criterion in addition to the EDPB criteria, materialising the dual compliance expected during a Luxembourg inspection.