Take-Aways (AI)
  • Seve­ral Euro­pean aut­ho­ri­ties have published posi­ti­ve (black­list) and nega­ti­ve (white list) lists on the obli­ga­ti­on to car­ry out data pro­tec­tion impact assess­ments (DPI­As).
  • Ger­ma­ny (seve­ral count­ries) and the Data Pro­tec­tion Con­fe­rence pri­ma­ri­ly published black­lists on 25.5.2018 and 25.7.2018 respectively.
  • Austria published a white list on 25.5.2018; Bel­gi­um, Pol­and and other count­ries have also pro­vi­ded lists.
  • Black­lists are often bin­ding for public aut­ho­ri­ties; white­lists may be vol­un­t­a­ry for public aut­ho­ri­ties (Art. 35 (4) and (5) GDPR).
[Updated 19 Sep­tem­ber 2018]

To date, the fol­lo­wing posi­ti­ve and nega­ti­ve lists on data pro­tec­tion impact assess­ments (DSFA) (both con­cre­ti­ze the obli­ga­ti­on to pro­vi­de a DSFA based on Art. 35 Para. 4 (posi­ti­ve lists, black list; pro­ba­b­ly man­da­to­ry for aut­ho­ri­ties) and Para. 5 (nega­ti­ve list, white list; pro­ba­b­ly vol­un­t­a­ry for authorities)):

Aut­ho­ri­ty Date Type Link
Bel­gi­um 28.2.2018 black/white https://goo.gl/bSa1Mr
Ger­ma­ny / Baden-Wuerttemberg 25.5.2018 black https://goo.gl/UjjECY
Ger­ma­ny / Saarland 25.5.2018 black https://goo.gl/pCDqfz (same as Baden-Würt­tem­berg, but with two addi­tio­nal cases)
Ger­ma­ny / Schles­wig-Hol­stein 25.5.2018 black https://goo.gl/81Yoa9 (same as Baden-Würt­tem­berg, but with one addi­tio­nal case; not iden­ti­cal to the addi­tio­nal cases in Saarland).
Ger­ma­ny / Rhi­ne­land-Pala­ti­na­te 25.5.2018 black – for public use only https://goo.gl/wSWJsZ
Ger­ma­ny (Data Pro­tec­tion Con­fe­rence, DSK) 25.7.2018 black https://goo.gl/nN3eCt
Austria 25.5.2018 white https://bit.ly/2l50aqU
Pol­and unda­ted black Polish: https://giodo.gov.pl/pl/file/13366

Eng­lish trans­la­ti­on by Koby­lańs­ka & Lewo­szew­ski: https://goo.gl/36bnBM