Data protection impact assessments
Article 7
1. The joint controllers shall agree whether a data protection impact assessment is required and which of the joint controllers shall prepare a draft of the data protection impact assessment. 2. A data protection impact assessment may only be considered final if it has been approved by all the joint controllers. 3. In justified cases, such as where the joint controllers are not involved during the same stages of a processing operation, the joint controllers shall carry out a separate data protection impact assessment for the specific stage of the processing operation during which they are involved. 4. Where a data protection impact assessment indicates that the processing would, in the absence of safeguards, security measures and mechanisms to mitigate the risk, result in a high risk to the rights and freedoms of natural persons and the joint controller responsible for preparing the draft under paragraph 1 is of the opinion that the risk cannot be mitigated by reasonable means in view of the available technologies and costs of implementation, that joint controller shall consult its supervisory authority. In such a case, the ECB shall also consult the European Data Protection Supervisor pursuant to Article 40 of Regulation (EU) 2018/1725, even if it is not the joint controller responsible for preparing the draft under paragraph 1.