(84) In order to improve compliance with this Regulation, when processing operations are likely to involve a high risk of violation of the rights or freedoms of natural persons, the controller should be required to conduct a data protection impact assessment to evaluate in particular the source, nature, specificity and severity of that risk. The results of the assessment should be taken into account in determining the appropriate measures to be taken to demonstrate that the processing of personal data is carried out in accordance with this Regulation. If the data protection impact assessment demonstrates that the processing operations give rise to high risks that cannot be minimized by the controller with appropriate measures from the point of view of available technology and implementation costs, the supervisory authority must be consulted before processing.
„We can resolve any doubts related to GDPR ourselves."
Are you sure about that?

