Hi !
When conducting a Data Protection Impact Assessment (DPIA), you are required to ask the data subject or a representative for their opinion on the processing. And yes, this is an obligation that applies "when relevant." If you know who the data subjects are, and for the Google DPIA, it is clear that we know who they are.
Our experience shows that many skip this part of DPIAs. We suspect this is both because it would involve extra work and because it might be a bit daunting to talk to the data subjects.
So how did we solve this in the national DPIA?
Method you can also use
We tried to make it as simple as possible. We asked the Education Union, the Student Organization, and FUG if they could ask their members if anyone would like to be interviewed by us. We received a list of names and then scheduled interviews.
Before the interviews, we sent each individual an overview of the personal data processed in Google Workspace for Education and how. This largely corresponds to the part of the DPIA that describes the processing activities.
During the interview, we presented this orally, and then we asked two questions:
- What privacy concerns do you have based on what you now know about how personal data is processed? (Here, we ask about privacy risk)
- What do you want us to do about it? (Here, we ask about risk-reducing measures) They were also informed in advance that these were the two questions we wanted to ask them.
After the interviews, we wrote minutes that the interviewee could verify.
We then summarized all the feedback in a separate report.
And voilĂ ! Done!
Published report
We have recently published the summary from the gathering of the data subject's input.
You can read them here.
Invitation to LinkedIn Live
At SkoleSec, we have not only worked with the DPIA of Google Workspace for Education. We have also conducted a DPIA for services provided by Learnlab. And in that context, we have also gathered the data subject's opinion.
This means that we are now beginning to gain quite a bit of experience on how to do this in practice.
And that means it's time for a new LinkedIn Live â this time where we share experiences on how to obtain the data subject's opinion in connection with a DPIA.
What have we learned? What tips do we have for you who will also do this? What can you take away from our experiences? What are the data subjects really most concerned about? In what way can it help you when you sit down to do a DPIA?
Join us on LinkedIn Live Tuesday, 19.11.24 from 12:00 PM to 1:00 PM!
Register for the event here
I wish you a wonderful, privacy-friendly week-end!
Best regards,
Ida Thorsrud
Project manager national DPIA
This newsletter was translated from Norwegian to English with assistance from ChatGPT by OpenAI. While it guided our translation, we made independent editorial choices. Any discrepancies result from this combined approach.