New software, customer profiling and changes to HR systems are useful points to review personal-data risks. A privacy impact assessment gives that review an owner, a record and a decision.
The development
Published regulatory guidance
Malaysia’s Personal Data Protection Commissioner now publishes a Data Protection Impact Assessment (DPIA) guideline alongside guidance on data protection by design and automated decision-making and profiling. Use the published guideline, rather than the earlier consultation paper, when assessing requirements.
What this means for a small team
A DPIA should help a business decide how a proposed process will work. Begin with the decision being made: whether to launch a tool, change a data flow or allow a supplier to access records. Identify whose information is involved and what could go wrong for those people. A completed form is useful only if its conclusions influence the project.
Actions to consider
- Assign a business owner and involve the privacy contact before procurement or launch decisions are final.
- Describe the purpose, information collected, recipients, access arrangements and deletion process.
- Screen the activity against the current guideline’s criteria; record the reason for the assessment decision.
- Record risks, proposed controls, unresolved questions and who can approve the next step.
- Revisit the assessment when the tool, supplier, purpose or data involved changes.
Scope and timing
A project’s size alone does not settle its assessment requirements. Check the current guideline and applicable law against the actual processing. Our practical workflow above is a starting point for organising that review.
What to prepare
A project screening record, an assessment owner and a prioritised action list linked to the launch decision.
Official sources
General information, not a determination of your organisation’s legal obligations. The actions are Averisdata’s practical suggestions; check the cited rules against your circumstances.