DATA PROTECTION IMPACT ASSESSMENT (DPIA)
1. Project DescriptionProcessing of personal data of course participants, subscribers, and event attendees through digital platforms.
Data Collected:
- Name
- Email
- Phone number
- Address
- Organisation
- Payment details (if applicable)
Purpose:
- Course registration
- Communication
- Service delivery
- Payment processing
- 2. Lawful BasisArticle 6(1)(b) – Contractual necessity
- Article 6(1)(a) – Consent (marketing)
- Article 6(1)(f) – Legitimate interests
3. Necessity & Proportionality AssessmentData collected is limited to what is necessary for:
- Identity verification
- Communication
- Service provision
Data minimisation principles are applied.
- 4. Risk Assessment Identified Risks:Unauthorised access
- Data breach
- Phishing targeting participants
- International transfer risk
Risk Level:Medium (standard CRM + email database risk profile)
- 5. Mitigation MeasuresSSL encryption
- Secure hosting
- Access controls
- Two-factor authentication
- Data Processing Agreements
- SCCs for international transfers
- Regular software updates
6. Residual RiskLow to Medium after safeguards implemented.
- 7. ConsultationIf residual high risk remains, consultation with the ICO (UK) may be required before processing.