DATASHEET
GDPR compliance with ARIS
Technical terms model with GDPR content
When you get started with GDPR compliance, you first need to understand the legislation and add the requirements to your ARIS Repository. An out-of-the-box technical terms model in ARIS helps you to derive your compliance requirements, define risks and controls and assign responsibilities.
Surveys for PA documentation (PAD)
- Data protection officers can describe the processing activities in more detail and define questionnaires to collect missing GDPR-relevant information
- PAD surveys help to collect and evaluate answers from stakeholders
- Survey intelligence reports can be used to evaluate a score that helps the data protection officer to define further measures
Data protection impact assessments (DPIAs)
- For critical Processing Activities (PAs) with a high score, you can perform more detailed surveys for PA Qualification (PAQ) and risk assessments
- Risk assessments help to identify the need for DPIAs for PA risks with high probability and/or high occurrence frequency
- DPIAs should be performed for PAs with high-risk probability according to the PAQ and/or risk assessment result
- Run DPIA workshops to evaluate the necessity and proportionality in relation to the purpose, and to document existing mechanisms for data protection connections.
Record of processing activities (ROPA)
- It is required that you maintain a ROPA including all data controllers and data processors of privacy data
- When Processing Activities (PAs) are equivalent to business processes, you can simply reuse this data from the ARIS Repository and add more PA details, or you can add them as new information to the ROPA.
- The ARIS fact sheet presents the ROPA in an easy-to-use table
GDPR-tailored dashboards
- GDPR-tailored dashboards help the Data Protection Officer (DPO) to be up to date about the current situation and to react quickly in case of any issues or incidents.
- Via the dashboard, the DPO has direct access to the affected elements
GDPR accelerators
- Filters based on conventions enable you to document PAs and GDPR-relevant qualification of application systems, processes, and data
- Classification of data with the help of data privacy attributes
- Method extensions also include risk assignment
GDPR management report
Finally, after all the work is done, the data protection officer needs a reliable tool to easily prove GDPR compliance by a click on a button. Management reports for GDPR make this an easy exercise.