Alessandro AleddaInsider Threat and Risk

INTRA/GV/GV008Impact assessment before deployment

The written assessment, made before a measure operates and kept afterwards, of what it will do to the people subject to it: what it will collect about them, what may follow from what it collects, and what they can do about either. It is a document, and its absence is a finding on its own.

Pillar
GV  |  Governance and mandate
Sources cited
3
Added
30 AUGUST 2026
Updated
30 AUGUST 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
GV008/EUMandatoryEuropean UnionRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.The assessment has to be completed before the measure operates, not compiled after it, wherever the processing is likely to result in a high risk.
GV008/ITMandatoryItalyProvvedimento n. 243Garante per la protezione dei dati personali · read 11 Aug 2026That ninety days of metadata and browsing logs, kept without the procedural steps, draws a fine, the reasoning turning on the steps and not the purpose.Its absence is enough on its own: a decision has turned on the missing procedural steps without reaching the purpose the processing served.
RecommendedUnited Kingdomwhere writtenEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.An assessment must be carried out before any processing likely to cause high risk, and the examples given reach an insider risk management program directly: the biometric data of workers, keystroke monitoring, monitoring that may result in financial loss, and the use of profiling or special category data to decide on access. Where there is a data protection officer, their independent advice must be sought and recorded. Anyone else the monitoring captures, a customer or a member of a worker’s household, is to be considered in it.