30
5419/16
AV/NT/sr
46
DGD 2
EN
(74)
The responsibility and liability of the controller for any processing of personal data carried
out by the controller or on the controller's behalf should be established. In particular, the
controller should be obliged to implement appropriate and effective measures and be able
to demonstrate the compliance of processing activities with this Regulation, including the
effectiveness of the measures. Those measures should take into account the nature, scope,
context and purposes of the processing and the risk to the rights and freedoms of natural
persons.
(75)
The risk to the rights and freedoms of natural persons , of varying likelihood and severity,
may result from personal data processing which could lead to physical, material or
non-material damage, in particular: where the processing may give rise to discrimination,
identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of
personal data protected by professional secrecy, unauthorised reversal of
pseudonymisation, or any other significant economic or social disadvantage; where data
subjects might be deprived of their rights and freedoms or prevented from exercising
control over their personal data; where personal data are processed which reveal racial or
ethnic origin, political opinions, religion or philosophical beliefs, trade-union membership,
and the processing of genetic data, data concerning health or data concerning sex life or
criminal convictions and offences or related security measures; where personal aspects are
evaluated, in particular analysing or predicting aspects concerning performance at work,
economic situation, health, personal preferences or interests, reliability or behaviour,
location or movements, in order to create or use personal profiles; where personal data of
vulnerable natural persons, in particular of children, are processed; or where processing
involves a large amount of personal data and affects a large number of data subjects.