unified
UC-RISK-16 — Conduct privacy impact assessments for high-risk processing
Privacy / data protection impact assessments are conducted before initiating processing likely to result in high risk to individuals, covering a systematic description of processing, necessity and proportionality analysis, risk assessment, and mitigation measures, with advice from the designated privacy officer and consultation with the competent regulator where required. Assessments are documented, approved, reviewed when processing changes, and retained.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-RISK-16
- title
- Conduct privacy impact assessments for high-risk processing
- statement
- Privacy / data protection impact assessments are conducted before initiating processing likely to result in high risk to individuals, covering a systematic description of processing, necessity and proportionality analysis, risk assessment, and mitigation measures, with advice from the designated privacy officer and consultation with the competent regulator where required. Assessments are documented, approved, reviewed when processing changes, and retained.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- RA-8
- coverage
- partial
- delta
- RA-8 mandates PIAs for any PII-processing IT and new collections, not only high-risk
- relationship
- intersects_with
- framework
- gdpr
- control_id
- GDPR-Art35
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-RISK-16 — Conduct privacy impact assessments for high-risk processing mitigates Brand and reputational crisis
- strength
- related
- rationale
- Mitigating privacy risks before high-risk processing lowers the likelihood of privacy incidents/breaches that trigger reputational crises.
- UC-RISK-16 — Conduct privacy impact assessments for high-risk processing maps_to GDPR-Art35 — Data protection impact assessment (DPIA)
- framework
- gdpr
- control_id
- GDPR-Art35
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Regulation (EU) 2016/679
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-16 — Conduct privacy impact assessments for high-risk processing mitigates Sector regulatory non-compliance (financial, healthcare, trade)
- strength
- primary
- rationale
- DPIA/PIA (GDPR Art 35) before high-risk processing is a direct data-protection compliance control identifying and mitigating privacy-law violations before they occur.
- UC-RISK-16 — Conduct privacy impact assessments for high-risk processing maps_to RA-8 — Privacy Impact Assessments
- framework
- nist-800-53
- control_id
- RA-8
- coverage
- partial
- delta
- RA-8 mandates PIAs for any PII-processing IT and new collections, not only high-risk
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- DPIA / Privacy Impact Assessment operates UC-RISK-16 — Conduct privacy impact assessments for high-risk processing