Assessment before processing begins
Which documented assessment is required before the data is processed or exported?
EU
Dataskyddsförordningen
art. 35
A data protection impact assessment is required where processing is likely to result in high risk, and must be done before processing starts.
- Deadline
- Before the transfer begins
- Penalty
- Up to EUR 10 million or two percent of global turnover
- Supervision
- Integritetsskyddsmyndigheten
- Read
- 2026-08-22
United States
California Consumer Privacy Act, som ändrad genom CPRA
Cal. Civ. Code § 1798.185(a)(15)
A risk assessment is required for processing that presents significant risk, and is submitted to the regulator under its rules.
- Deadline
- No deadline stated
- Penalty
- Civil penalty per violation
- Supervision
- California Privacy Protection Agency
- Read
- 2026-08-22
China
Personal Information Protection Law
art. 55 och 56
An impact assessment is required for outbound transfers, sensitive data and automated decision-making, and the record is kept for three years.
- Deadline
- Before the transfer begins
- Penalty
- Order to rectify, warning, suspension of the service and a fine
- Supervision
- Cyberspace Administration of China
- Read
- 2026-08-22
Connections
Sources and review
Register version crossover-v1.0.0 · Read 2026-08-22
This page restates written law with the provision and the official source. It is not legal advice in an individual matter.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.