In interesting set of reference material, that is regularly coming back in data protection, cybersecurity and information security discussions I lately had with peers and colleagues.
May you can use it too…
Feel free to provide some feedback yourself, if you know additional pointers I should add.
You know where to find me.
Change history
2022-04-27 14:00: Added EDPB announcement to references section
Governmental DPIAs
Netherlands
2018-12-06: DPIA on Microsoft Office 2016 & 365
https://iapp.org/news/a/dutch-government-commissioned-dpia-on-microsoft-office-pro-plus/
Direct download of PDF:
2022-02-22: DPIA on Microsoft Office 365
https://www.dataguidance.com/news/netherlands-dutch-government-publishes-dpia-microsoft
Press release by Dutch Government:
Publication of DPIA by Dutch Government
2022-02-21 : https://www.rijksoverheid.nl/documenten/publicaties/2022/02/21/public-dpia-teams-onedrive-sharepoint-and-azure-ad
Source: Beltug news https://www.beltug.be/news/7430/Dutch_government_publishes_DPIA_and_DTIA_for_Microsoft/
2022-02: The Dutch Ministry of Justice and Security requested an analysis of US legislation in relation to the GDPR and Schrems II by GreenburgTraurig.
Switzerland
In a recent article (In French) by ICT journal, the Canton of Zurich published a
Research
Researchgate
Data Protection Impact Assessment (DPIA) for Cloud-Based Health Organizations
Guidelines
CNIL
https://www.cnil.fr/en/tag/Privacy+Impact+Assessment+(PIA)
https://www.cnil.fr/en/guidelines-dpia
IAPP
https://iapp.org/news/a/guidance-for-a-cloud-migration-privacy-impact-assessment/
Templates
IAPP
https://iapp.org/resources/article/transfer-impact-assessment-templates/
Referring to:
IAPP Templates
- Cloud Computing: Risk Assessment of Lawful Access By Foreign Authorities
- EU SCC Transfer Impact Assessment (TIA)
Supplier references
Microsoft
Data Protection Impact Assessment for the GDPR
2021-11-17: https://docs.microsoft.com/en-us/compliance/regulatory/gdpr-data-protection-impact-assessments
Data Protection Impact Assessments: Guidance for Data Controllers Using Microsoft Professional Services
Part 1: Determining whether a DPIA is needed
Part 2: Contents of a DPIA
Download Customizable DPIA document
https://www.microsoft.com/en-us/download/details.aspx?id=102398
(more to come, this article will be updated with additional references when necessary)
Other relevant references
EDPB (European Data Protection Board)
Launch of coordinated enforcement on use of cloud by public sector
https://edpb.europa.eu/news/news/2022/launch-coordinated-enforcement-use-cloud-public-sector_en