High-Risk Processing
What is High-Risk Processing?
Data processing activities that pose a significant risk to the rights and freedoms of individuals, requiring enhanced safeguards and impact assessments.
Terms that appear alongside high-risk processing
Each of these is named in at least one of the same controls as high-risk processing. The number is how many controls name both.
- data protection 40 shared controls
- impact assessment 29 shared controls
- gdpr 23 shared controls
- data protection impact assessment 22 shared controls
- profiling 20 shared controls
- privacy by design 16 shared controls
- consent 14 shared controls
- governance 14 shared controls
Frameworks that govern high-risk processing
What the standards actually require on high-risk processing
Requirements naming high-risk processing across 6 standards, quoted from the control text.
Section 34 of the Jamaica Data Protection Act 2020 establishes Privacy by Design + Privacy by Default + and Data Protection Impact Assessment (DPIA) requirements.
JM-DPA2020-Privacy-by-Design-Default-Sec34-Engineering-Data-Protection-Impact-Assessment-DPIA-Risk-Based · Jamaica DPA 2020 Privacy by Design + Privacy by Default + Section 34 + Data Protection Impact Assessment (DPIA) + Risk-Based + High-Risk Processing + Prior Consultation + Privacy Engineering →Businesses whose processing of PI presents significant risk to consumers privacy or security must submit risk assessments to the CPPA on a regular basis.
§1798.185(a)(15) · Risk Assessments for High-Risk Processing →Per IC 24-15-4 and IC 24-15-5 INCDPA imposes heightened obligations for sensitive data + children + and high-risk processing activities.
INCDPA-SensitiveData-Children-Consent-COPPA-DataProtectionAssessment-DPIA · Indiana CDPA Sensitive Data + Consent for Sensitive Categories + Children Under 13 + COPPA Coordination + Data Protection Assessment (DPA) + High-Risk Processing →Conduct Data Protection Impact Assessments for processing likely to result in high risk, following AEPD criteria and consulting AEPD where required.
LOPDGDD-09 · DPIA for High Risk Processing →Following 2024 amendments aligning with GDPR-style requirements, owners must conduct impact assessments for processing likely to result in high risk to data subjects, particularly involving profiling, large-scale sensitive data, or systematic monitoring.
UA-PDP-15 · Data Protection Impact Assessments for High-Risk Processing →Conduct and document data protection assessments for processing activities that present heightened risk to consumers, including targeted advertising, profiling, sensitive data, and sale.
VT-AICDA-15 · Data Protection Assessment for High-Risk Processing →Questions people ask about high-risk processing
What is High-Risk Processing?
Why is High-Risk Processing important for compliance?
Which compliance frameworks address High-Risk Processing?
Where can I learn more about High-Risk Processing?
See how High-Risk Processing applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.