02 Privacy Impact Assessment
02 Privacy Impact Assessment
02 Privacy Impact Assessment
2. Systematic description of the anticipated processing operations It must consider the following:
and the purposes of the processing, including, where applicable, the
legitimate interest pursued by the agency;
For agencies that process the personal data records of more than
one thousand (1,000) individuals, including agency personnel, the
Commission recommends the use of the ISO/IEC 27002 control
set as the minimum standard to assess any gaps in the agencys
control framework.