Section 3 – Fundamental principles
Risk assessment
3.1. Which application or product line does this repository belong to?
This grouping will create reports at an application/product level.
3.2. What type of personal data does this processing involve?
Select the categories of personal data being processed.
3.3. What is the legal basis for processing this data?
Select the applicable legal basis under GDPR Article 6.
3.4. How long will the data be retained?
Specify the retention period for this data processing activity.
3.5. Are there any data transfers outside the EEA?
Indicate if data is transferred to third countries.
3.6. What security measures are in place?
Describe the technical and organizational security measures.
3.7. Is a Data Protection Impact Assessment required?
Determine if a DPIA is needed based on risk assessment.