{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Risk Assessment & Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-16","description":"Privacy / data protection impact assessments are conducted before initiating processing likely to result in high risk to individuals, covering a systematic description of processing, necessity and proportionality analysis, risk assessment, and mitigation measures, with advice from the designated privacy officer and consultation with the competent regulator where required. Assessments are documented, approved, reviewed when processing changes, and retained.","details":{"control_category":"administrative","control_type":"preventive","domain":"Risk Assessment & Management","guidance":[],"members":[{"control_id":"RA-8","coverage":"partial","delta":"RA-8 mandates PIAs for any PII-processing IT and new collections, not only high-risk","framework":"nist-800-53","relationship":"intersects_with"},{"control_id":"GDPR-Art35","coverage":"full","framework":"gdpr","relationship":"superset_of"}],"statement":"Privacy / data protection impact assessments are conducted before initiating processing likely to result in high risk to individuals, covering a systematic description of processing, necessity and proportionality analysis, risk assessment, and mitigation measures, with advice from the designated privacy officer and consultation with the competent regulator where required. Assessments are documented, approved, reviewed when processing changes, and retained.","title":"Conduct privacy impact assessments for high-risk processing","unified_id":"UC-RISK-16"},"id":"uc:UC-RISK-16","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-16","sourceIds":["gdpr","nist-800-53"],"sourceUrl":null,"title":"UC-RISK-16 — Conduct privacy impact assessments for high-risk processing","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:18cccd4335d99eef7b36763c32f291dfeced05df7e7e3618a1bdb7954bc3d8c2","properties":{"rationale":"Mitigating privacy risks before high-risk processing lowers the likelihood of privacy incidents/breaches that trigger reputational crises.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-16-81243062.json","sourceId":"uc:UC-RISK-16","targetDetailPath":"/data/v1/records/risk-reputational-brand-crisis-4d7c293d.json","targetId":"risk:reputational-brand-crisis","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:48afab00c51493858a3017cec2c5da651d09307c8cebd4c0f6bd1d3b157630e4","properties":{"control_id":"GDPR-Art35","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-16-81243062.json","sourceId":"uc:UC-RISK-16","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art35-4314d563.json","targetId":"ctrl:gdpr:GDPR-Art35","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e0b91b6945069b7e7edae111d475c5e13cc043c1d41718d123a918a403bef97","properties":{"rationale":"DPIA/PIA (GDPR Art 35) before high-risk processing is a direct data-protection compliance control identifying and mitigating privacy-law violations before they occur.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-16-81243062.json","sourceId":"uc:UC-RISK-16","targetDetailPath":"/data/v1/records/risk-compliance-sector-regulatory-breach-5eb29698.json","targetId":"risk:compliance-sector-regulatory-breach","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e600918eea6aa373fc4b910c7e5fca129017381bec805003c4d2c980f796b2d1","properties":{"control_id":"RA-8","coverage":"partial","delta":"RA-8 mandates PIAs for any PII-processing IT and new collections, not only high-risk","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-16-81243062.json","sourceId":"uc:UC-RISK-16","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ra-8-60887d49.json","targetId":"ctrl:nist-800-53:RA-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fda4770d953c7433b9fa2b7a8c84ed8282cfb8848fc14d1dcb93668a0a3f99a5","properties":{},"sourceDetailPath":"/data/v1/records/wf-r8-7a63c8f3.json","sourceId":"wf:R8","targetDetailPath":"/data/v1/records/uc-uc-risk-16-81243062.json","targetId":"uc:UC-RISK-16","type":"operates"}],"schemaVersion":1}
