{"id":690,"date":"2018-08-24T16:25:59","date_gmt":"2018-08-24T14:25:59","guid":{"rendered":"http:\/\/blog.eprivacy.eu\/?p=690"},"modified":"2020-12-13T16:26:42","modified_gmt":"2020-12-13T15:26:42","slug":"data-protection-impact-assessment","status":"publish","type":"post","link":"https:\/\/blog.eprivacy.eu\/?p=690","title":{"rendered":"Data Protection Impact Assessment"},"content":{"rendered":"\n<p>ePrivacy&#8217;s&nbsp;data protection experts have been discussing&nbsp;the question of the necessity of a data protection impact assessment (DPIA) for classic models of the online marketing industry, especially for a DMP. A&nbsp;DPIA seems to be necessary according to the current state of affairs.&nbsp;<br>This is not only the result of the recently published DPIA&nbsp;blacklists by German authorities (e.g. the BayLDA), but also&nbsp;of the remarks of Art. 29 Group.<br>&nbsp;&nbsp;<br>At this point&nbsp;the question of whether personal data is processed at all in the context of a DMP may be discussed and the discussion on this concern is not&nbsp;finished yet. Apart from that,&nbsp;the &#8222;comprehensive profiles on interests, etc.&#8220; mentioned in paragraph 7 of the blacklist&nbsp;as well as the big data analyses mentioned in paragraph 8 and the associated data&nbsp;accumulation from third-party sources are currently being drawn up. Most likely therefore&nbsp;a DPIA&nbsp;is required for the&nbsp;operating of a&nbsp;DMP.<\/p>\n\n\n\n<p><br><strong>It is important to know:&nbsp;<\/strong><\/p>\n\n\n\n<ul><li>A company that uses DMP services from a third party&nbsp;still has&nbsp;to carry out its&nbsp;own DPIA.&nbsp;However, most of the information from the existing DPIA from a third party can be taken over to set up the own DPIA.&nbsp;<\/li><li>A DPIA&nbsp;does not necessarily has to be carried out by external parties. The &#8222;responsible body&#8220; has a scope of discretion how to&nbsp;carry&nbsp;out its&nbsp;DPIA.&nbsp;<\/li><li>DPIAs for DMPs can be developed based on a standardized model, ePrivacy conducts DPIAs and has&nbsp;already accomplished a large number of DPIAs for different business models.<\/li><li>ePrivacy is&nbsp;not aware of any cases in which a DPIA&nbsp;would have been necessary in connection with a CRM or personnel databases. This may apply&nbsp;if the CRM data is linked to a DMP.<\/li><\/ul>\n\n\n\n<p>Do you have any further questions about a DPIA or need any support on this particular&nbsp;matter? Please feel free to&nbsp;<a href=\"https:\/\/www.eprivacy.eu\/en\/contact\/\" target=\"_blank\" rel=\"noreferrer noopener\">contact us<\/a>!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ePrivacy&#8217;s&nbsp;data protection experts have been discussing&nbsp;the question of the necessity of a data protection impact assessment (DPIA) for classic models of the<\/p>\n<p class=\"link-more\"><a class=\"myButt \" href=\"https:\/\/blog.eprivacy.eu\/?p=690\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/690"}],"collection":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=690"}],"version-history":[{"count":1,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/690\/revisions"}],"predecessor-version":[{"id":691,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/690\/revisions\/691"}],"wp:attachment":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=690"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=690"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=690"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}