
Norwegian DPA publishes list of processing activities with mandatory DPIA
Under Article 35 of the GDPR, the national Data Processing Authority (DPA) shall establish and make public a list of processing operations which are subject to the requirement for a DPIA. The Norwegian DPA recently published a list of processing activities that the Norwegian DPA considers likely to result in a high risk to the rights and freedoms of data subjects, and which will therefore always require the controller to carry out a DPIA. The Norwegian DPA's list is based on the Working Party 29's analysis in the Guidelines on DPIA (WP 248).
10 April 2019










