(40) In order to comply with the law, the processing of data should be carried out on the basis of the consent of the data subject or on another reasonable basis provided for by law: either in this Regulation or in another Union legal act or in the law of a Member State referred to in this Regulation, including in compliance with the legal obligation to which the controller is subject, or in compliance with the contract to which the data subject is a party, or in order to take action at the request of the data subject before the conclusion of the contract.
„We are perfectly capable of assessing the risk ourselves."
Are you sure about that?

