| Today’s topic | Data Privacy Impact Assessment |
|---|---|
| Estimated time | 90-120 minutes |
| Primary Act reference | s.28 |
| Guide reference | Guide pp.5, 9 and Assessment 2 |
Learning Objectives
Explain and apply high-risk screening.
Explain and apply necessity and proportionality.
Explain and apply risks to rights.
Explain and apply mitigation and residual risk.
Explain and apply prior consultation.
Diagnostic Assessment
Attempt these questions before reading the model responses.
1. What is the principal compliance issue addressed by s.28?
Show model response
Model response: It is data privacy impact assessment. The analysis should focus on high-risk screening and the connected statutory conditions.
2. Identify two concepts that must be considered when analysing data privacy impact assessment.
Show model response
Model response: Any two of the following are relevant: high-risk screening, necessity and proportionality, risks to rights, mitigation and residual risk.
3. Why should a DPO cite the exact section instead of relying only on a general privacy principle?
Show model response
Model response: The section contains the controlling conditions, limits and exceptions. A general principle may guide analysis but cannot replace the specific statutory test.
4. What evidence should an organisation retain when applying s.28?
Show model response
Model response: It should retain the facts considered, the statutory test, the decision, supporting records, responsible approval and any review or corrective action.
5. How should the organisation respond when the uploaded sources do not resolve a material detail?
Show model response
Model response: It should record the limitation and avoid inventing a requirement. The DPO should return to the full statutory wording and seek current authoritative material when permitted.
Structured Lesson
1. High-Risk Screening
High-risk screening is a central issue for this study day. The DPO should locate the exact statutory conditions in s.28, apply them to the particular processing activity and retain evidence supporting the conclusion.
The Guide’s workflow moves from high-risk screening through necessity, proportionality, risk, safeguards, residual risk, approval and possible consultation with the Commission.
2. Necessity And Proportionality
Necessity and proportionality is a central issue for this study day. The DPO should locate the exact statutory conditions in s.28, apply them to the particular processing activity and retain evidence supporting the conclusion.
The Guide’s workflow moves from high-risk screening through necessity, proportionality, risk, safeguards, residual risk, approval and possible consultation with the Commission.
3. Risks To Rights
Risks to rights is a central issue for this study day. The DPO should locate the exact statutory conditions in s.28, apply them to the particular processing activity and retain evidence supporting the conclusion.
The Guide’s workflow moves from high-risk screening through necessity, proportionality, risk, safeguards, residual risk, approval and possible consultation with the Commission.
4. Mitigation And Residual Risk
Mitigation and residual risk is a central issue for this study day. The DPO should locate the exact statutory conditions in s.28, apply them to the particular processing activity and retain evidence supporting the conclusion.
The Guide’s workflow moves from high-risk screening through necessity, proportionality, risk, safeguards, residual risk, approval and possible consultation with the Commission.
5. Prior Consultation
Prior consultation is a central issue for this study day. The DPO should locate the exact statutory conditions in s.28, apply them to the particular processing activity and retain evidence supporting the conclusion.
The Guide’s workflow moves from high-risk screening through necessity, proportionality, risk, safeguards, residual risk, approval and possible consultation with the Commission.
Nigerian Scenario and Model Analysis
A public university begins a project involving staff or customer personal data. The project raises questions about high-risk screening and necessity and proportionality. Identify the controller, any processor, the data subjects, likely personal data, the required statutory analysis under s.28, key risks and the compliance evidence that should be retained.
Show model response
Model analysis: The organisation determining why and how the project operates is normally the controller. A vendor acting only on documented instructions is normally a processor. Staff or customers are the data subjects. The DPO should inventory the data, apply s.28 to the stated purpose, document the decision, assign controls and retain evidence. The final conclusion depends on the precise facts and statutory conditions.
Lesson Summary
Day 10 establishes how a DPO should understand and apply data privacy impact assessment. The legal starting point is s.28. The main operational lesson is to connect high-risk screening, necessity and proportionality, risks to rights to documented facts and evidence.
Ten Key Terms
| Term | Working definition |
|---|---|
| Controller | A person or body that determines the purposes and means of processing personal data. |
| Processor | A person or body that processes personal data on behalf of a controller. |
| Data Subject | The identified or identifiable individual to whom personal data relate. |
| Personal Data | Information relating to an identified or identifiable individual. |
| Processing | An operation performed on personal data, including collection, use, storage, disclosure or deletion. |
| Dpia | A prior assessment of high-risk processing, its necessity, risks, safeguards and residual risk. |
| Residual Risk | Risk remaining after planned safeguards and mitigation measures are applied. |
| Accountability | Responsibility for compliance and the ability to demonstrate it with evidence. |
| Security | Risk-appropriate technical and organisational protection for personal data. |
| Processing | An operation performed on personal data, including collection, use, storage, disclosure or deletion. |
Definitions are paraphrased for study. Check section 65 and the relevant operative provision for controlling wording.
Five Revision Questions and Responses
1. What provisions govern this lesson?
Show model response
Response: s.28
2. What are the principal concepts?
Show model response
Response: high-risk screening, necessity and proportionality, risks to rights, mitigation and residual risk, prior consultation.
3. What is the correct source hierarchy?
Show model response
Response: The Act is primary authority. The Guide supports learning and professional application. Tutor explanation assists interpretation without creating new law.
4. What is the central evidence requirement?
Show model response
Response: Record the facts, applicable test, conclusion, approval, controls and review trigger.
5. What common error should be avoided?
Show model response
Response: Do not assume a broad principle answers the issue. Test the exact conditions and exceptions in the assigned section.
Five Multiple-Choice Questions
1. Which source provides the primary statutory rule for Day 10?
A. The Guide
B. The Act
C. A workplace policy
D. A vendor contract
2. Which provision set should be consulted first?
A. Section 1 only
B. s.28
C. Section 65 only
D. No statutory provision
3. What should follow identification of the relevant section?
A. Assume compliance
B. Test conditions and exceptions
C. Ignore evidence
D. Use consent automatically
4. Which record best supports accountability?
A. An undocumented opinion
B. A reasoned decision record
C. A verbal assurance
D. A marketing brochure
5. If the sources do not resolve a detail, what should the learner do?
A. Invent a rule
B. State the limitation
C. Cite an unrelated law
D. Ignore the uncertainty
Show model response
Answer key: 1-B, 2-B, 3-B, 4-B, 5-B. Review the lesson citations before marking.
Practical Workplace Task
Prepare a one-page compliance record for a Nigerian organisation applying s.28. Include the processing purpose, actors, data subjects, personal data, statutory test, risks, decision, controls, owner, evidence and review date.
Show model response
Expected deliverable: A dated, approved record that links factual evidence to each applicable statutory condition and records any unresolved issue.
Three Flashcards
Front: Act reference for Day 10? | Back: s.28
Front: Central topic? | Back: Data Privacy Impact Assessment
Front: Best analysis habit? | Back: Facts → role → section → conditions → evidence.
Reread and Progress Record
Reread: s.28; Guide pp.5, 9 and Assessment 2.
| Date completed | ________________ | Score | ______% |
|---|---|---|---|
| Strong areas | ________________ | Weak areas | ________________ |
| Recommended revision | ________________ | Readiness | Developing / Competent / Ready |
Cumulative Assessment 2
This checkpoint covers Days 6-10. Answer without consulting the model responses.
Explain and apply one central rule from Day 6, with its section citation and a Nigerian workplace example.
Explain and apply one central rule from Day 7, with its section citation and a Nigerian workplace example.
Explain and apply one central rule from Day 8, with its section citation and a Nigerian workplace example.
Explain and apply one central rule from Day 9, with its section citation and a Nigerian workplace example.
Explain and apply one central rule from Day 10, with its section citation and a Nigerian workplace example.
Show model response
Marking guide: 20 marks per response, allocated to correct section, accurate rule, application, evidence and clear conclusion.
