EKSISTENZ D9.5 Core elements of a Privacy Impact Assessment of the EKSISTENZ platform

Ivo Emanuilov · Lirias · 2017

The objective of this deliverable is to provide guidance to data controllers who will consider EKSISTENZ in a production environment in assessing the impact of the system on citizens’ privacy. The deliverable is based on elements of the Privacy Impact Assessment Methodology provided by the French Data Protection Authority (CNIL) as well as the Guidelines on Data Protection Impact Assessment under the General Data Protection Regulation published by the Article 29 Working Party in April 2017, and other relevant sources. This impact assessment should be complemented with a specific impact assessment in an organisational context whenever EKSISTENZ is being implemented in a production environment. As such, it has indicative role and outlines criteria, legal and risk-treatment controls that could help controllers meet their obligations under the General Data Protection Regulation. The deliverable provides analysis of whether and why EKSISTENZ falls under the scope of the General Data Protection Regulation and qualifies for a mandatory data protection impact assessment. Furthermore, the document provides a brief overview of the available methodologies for privacy impact assessment and argues that a combination of the CNIL’s recognised methodology with elements of other methodologies specifically tailored for impact assessment of biometric systems, is most beneficial. The impact assessment is carried out in the form of multiple tables outlining the results of the analysis at the respective step of the methodology. The main findings of the impact assessment are that EKSISTENZ has implemented strong data protection by design and by default measures, such as biometric template protection, anonymous tokens and weak-link architecture. In combination with sufficient organisational controls and the recommended risk-treatment controls, the majority of the risks are likely to be mitigated. The impact assessment demonstrated that the processing in the context of EKSISTENZ is likely to result in a high risk in the absence of measures taken by the controller to mitigate the risk. The existing privacy by design measures must be complemented with sufficient guarantees at an organisational level which are often context-dependent. Finally, close cooperation with the supervisory authority, as mandated by Article 36 (1) GDPR, will ensure smooth and future-proof implementation in full compliance with the requirements of the data protection law. This deliverable draws on the analysis and outcomes of the work of EKSISTENZ Work Packages 4, 5, and 6.

Read the paper · More papers on PaperTik