DevPortalPagoPA



Tabella dei contenuti

Risk analysis

Why complete it

The risk analysis questionnaire has been introduced in the PDND to implement the provisions contained in the GDPR, the General Data Protection Regulation. The Regulation was adopted by the European Union regarding the processing of personal data and privacy.
The risk analysis questionnaire has been reviewed by the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali), which has given a favorable opinion.

Who must complete it

The risk analysis must be completed by the party receiving the data from the other party, which, in GDPR terminology, is the Data Controller.
The most common case in the E-service Catalog is that of an e-service that provides data (direct provision — read data from an e-service). In this case, it is the consumer that receives the data and must therefore complete the risk analysis.
In the case of an e-service that receives data (reverse provision — write data to an e-service), it will be the producer who must complete the risk analysis. When the consumer creates a purpose for that e-service, they will have to select the use case that corresponds to the one for which they send data to the producer. The producer will be required to process the data in compliance with what is requested by the consumer in the selected risk analysis.

Who is responsible?

The responsibility for the statements made in the risk analysis always lies with the party making the declaration. This party is required to process the data in accordance with the statements made.
For this reason, it is mandatory that a purpose is always submitted by a user with the administrator role.

How to complete it

Completion varies from case to case. Some guidance and practices are discussed in the ANCI course dedicated to Data Exchange through the PDND (Italian only).

Hai bisogno di aiuto?

Apri un ticket utilizzando l’apposita funzione all’interno della tua Area Riservata

Dicci cosa ne pensi

Per segnalare problemi o dare feedback, puoi aprire una segnalazione su Github