The purpose of this master's thesis is to examine the institution of impact assessment regarding personal data protection. Impact assessment is the process of identifying risks in personal data processing, on the basis of which the controller adopts organizational and technical measures for the protection of personal data. The controller is also bound to this by the principle of accountability, which is a fundamental principle for compliance throughout the processing procedure. The controller's responsible attitude towards personal data of data subjects is crucial for ensuring a high level of personal data protection. A great increase in quantity and quality of data processing in the digital age have required a systemic solution which will provide effective protection against personal data breach such as unauthorized access, mass disclosure and profiling. The current regulation adopts a risk-based approach to personal data protection. In the digital age reducing the risks in personal data processing is of paramount importance when ensuring a high standard of protection of the rights of data subjects. The risks must be analyzed by the controller at the beginning of pre-processing activities, which is in accordance with the concept of privacy by design. Under the concept of privacy by design, the fundamental principles of personal data protection have been formulated and also adopted by current legislation. The basic elements of the institutions under consideration are indicated in the impact assessment process regarding personal data protection. Within the impact assessment process, the controller selects and substantiates the appropriate legal basis for the collection of personal data, analyzes the risks, and then adopts effective measures to ensure compliance of personal data processing with the fundamental principles of personal data protection. Implementation of impact assessment strengthens the rights of data subjects. This has been the essential objective of the new regulation brought about by the General Data Protection Regulation.
|