‎15-02-2021 01:45 PM
Are the Final Risk Level and Final Compliance Level automatically set according to the details entered into the processing activities?
Solved! Go to Solution.
‎16-02-2021 12:18 PM
Hi Claus,
Yes please. A new thread would be better. I'm getting the info you requested so I should be able to come back to you shortly.
‎16-02-2021 11:56 AM
Please see replies below. We don't understand how Net Risk is calculated and we don't see that the Final Risk Level is calculated corretly. Shall we open a new thread with this issue?
‎16-02-2021 11:05 AM
Can you also explain to me how Net Risk is calculated?
It doesn't change when I'm changing "Risk" and "Risk Mitigation"
‎15-02-2021 02:31 PM
Just what I needed. Thanks 🙂
‎15-02-2021 02:11 PM
Good morning Claus,
Yes they are. Their value is based on the 5 compliance indicators of the processing activity:
1) Legal Basis Compliance Level
2) Data Minimization Compliance Level
3) Data Subjects' Rights and Notice Management Compliance Level
4) Data Transfers Compliance Level
5) Security Measures Compliance Level
In order to compute the Final Compliance Level, the algorithm sums the 5 indicators values, based on the following scoring table:
The result is averaged and rounded to the smallest integer. Please not that if a compliance indicator is left empty, it is considered as if it was set to "Not Compliant".
For the Final Risk Level, instead, the algorithm sums the 5 indicators values, based on the following scoring table:
The result is averaged and rounded to the biggest integer, then we subtract one.
Also the field "Subsequent Action" is automatically computed.
For Pre-Assessments:
For DPIAs:
Best,
Mike