What controls can we include in our DPIA to mitigate risks?
Depending on the organisation's use case, controls may include:
- Clear recording notices
- Appropriate lawful basis
- Staff training
- Restricted user access
- Role-based permissions
- Encryption
- Short retention periods
- Approved use cases
- Human review of transcripts and summaries
- Procedures for correcting inaccurate records
- Subprocessor assurance
- Data subject rights procedures
- Incident response procedures
- Regular review of the DPIA
- Controls preventing inappropriate secondary use