Risk analysis and impact assessment relating to data protection: its application to cooperative companies
Abstract
The GDPR requires all businesses to conduct a risk analysis of the processing of personal data. If this analysis shows that there is a high risk, it will be mandatory to perform a DPIA in order to foresee the impacts and risks this may pose to the privacy of the interested parties. On this basis, the GDPR requires the implementation of security and control measures to guarantee the rights and freedoms of individuals. This paper focuses, on the one hand, on analysing when a cooperative society must carry out a DPIA and, on the other hand, on studying the phases involved in conducting a DPIA correctly.
Received: 25 July 2019
Accepted: 21 February 2020
Published online: 01 April 2020
Downloads
References
AGENCIA ESPAÑOLA DE PROTECCIÓN DE DATOS, «Guía del Reglamento General de Protección de Datos para responsables de tratamiento», https://www.aepd.es/media/guias/guia-rgpd-para-responsables-de-tratamiento.pdf.
AGENCIA ESPAÑOLA DE PROTECCIÓN DE DATOS, «Guía para el cumplimiento del deber de informar», https://www.aepd.es/media/guias/guiamodelo-clausula-informativa.pdf.
AGENCIA ESPAÑOLA DE PROTECCIÓN DE DATOS, «Guía práctica para las Evaluaciones de Impacto en la Protección de los Datos sujetas al RGPD», https://www.aepd.es/media/guias/guia-evaluaciones-de-impacto-rgpd.pdf.
AUTORIDAD CATALANA DE PROTECCIÓN DE DATOS, «Guía Práctica: Evaluación de impacto protección de datos personales», https://apdcat.gencat.cat/.../GUIA-EVALUACION-DE-IMPACTO-CAST-2.0.pdf.
GRUPO PROTECCIÓN DE DATOS DEL ARTÍCULO 29, WP 248, «Directrices sobre la evaluación de impacto relativa a la protección de datos (EIPD) y para determinar si el tratamiento «entraña probablemente un alto riesgo» a efectos del Reglamento (UE) 2016/679», https://www.aepd.es/media/criterios/wp248rev01-es.pdf.
LÓPEZ CALVO, José. 2017. Comentarios al Reglamento Europeo de protección de Datos. Las Rozas (Madrid): Editorial Sepín.
MERCADER UGUINA, Jesús R. 2019. Protección de datos y garantía de los derechos digitales en las relaciones laborales, 3.ª ed., Francis Lefebre, Madrid, 2019.
MUÑOZ DEIROS, Eva. 2014. «La Privacidad desde el Diseño y las Evaluaciones de Impacto en la Protección de Datos». 31 de octubre de 2014, http://evamunoz.es/privacidad-desde-diseno-evaluaciones-impacto-protecciondatos/.
NIETO MARTÍN, Adán. 2015. «El cumplimiento normativo». En Manual de cumplimiento penal en la empresa, 25-48. Valencia: Editorial Tirant LoBlanch. https://dialnet.unirioja.es/servlet/articulo?codigo=4959230.
PUYOL, Javier. 2018. El modelo de evaluación de riesgos en la protección de datos EIPD / PIA’s. Valencia: Tirant lo Blanch, 2018.
RECIO GAYO, Miguel. 2016. «Aproximación basada en el riesgo, Evaluación de Impacto relativa a la protección de datos personales y consulta previa a la autoridad de control». En Reglamento General de protección de Datos. Hacia un nuevo modelo europeo de privacidad, 351-366. Madrid: Editorial Reus.
Last update: 29/06/2026
The authors are advised to read their rights carefully. We believe this approach ensures a fair agreement for both parties. These instructions should be read in conjunction with the Ethical Guidelines and the Open Access Policy, Licensing Terms and Copyright of the journal "Boletín de la Asociación Internacional de Derecho Cooperativo (BAIDC)".
1. Authorship and Ethics
By submitting their manuscripts to Boletín de la Asociación Internacional de Derecho Cooperativo (BAIDC), the authors accept and undertake to comply with the conditions of publication without the need to sign an additional transfer agreement with the Publisher (University of Deusto). In doing so, they guarantee that their work is unpublished in any form, original, and does not breach BAIDC’s Ethical Guidelines or the rights of third parties, and that no licences have been or will be granted that are incompatible with the rights granted to the Publisher.
The authors assume full and exclusive responsibility for the content of the study and formally declare that they have no conflicts of interest that affect the integrity of the research.
2. Publisher’s Rights
By submitting the manuscript, the authors agree to its publication under the Creative Commons CC BY-NC-ND 4.0 licence. Consequently, they grant the Publisher the exclusive, royalty-free and worldwide right of first publication, editing, layout and exploitation of the article. This grant authorises the Publisher to distribute, sub-license and index the work in any format, medium, database or institutional repository, for the purposes of promotion and scientific dissemination.
3. Copyright
The authors retain the intellectual property rights to their article and retain the right to distribute and use their work for teaching purposes, future research or personal archiving, provided that the original publication in the Journal is cited. They are also permitted to republish in other media, provided that a (foot)note is included with the full reference to BAIDC (including the DOI, where available) and no explicit endorsement of the Journal and/or Publisher is implied.
4. Open access
BAIDC is an open-access journal; this means that it is freely and fully accessible in its entirety immediately upon publication of its content. However, in accordance with the licence mentioned above, the authors of the articles must always be properly cited; and both commercial use and any modification intended for distribution will require the express prior written permission of the rights holder.
More details are available under the section “Open Access Policy, Licensing Terms and Copyright”.
.jpg)
.jpg)
.jpg)
1.jpg)
.jpg)
.jpg)



