As mentioned above, it is mandatory to conduct a PIA when the processing of the data may give rise to a high risk for the rights and freedoms of the data subjects of the collection, such as in the following cases:
- The processing is included in the list of types of processing operations for which the CNIL (supervisory authority of the European General Regulation on Data Protection) requires a PIA. (See CNIL article)
- The data processing meets at least two of the following criteria:
– Evaluation/profiling
– Automatic decision with legal or similar effect
– Systematic monitoring
– Collection of sensitive data
– Large-scale collection of personal data
– Cross-referencing of data
– Data concerning vulnerable people (patients, children, elderly)
– Innovative use with the use of new technology
– Exclusion of the benefit of a right and a contract