Children Data Protection Impact Assessment (CRIA) Diagnostic Tools

Published: 29 September 2026| Version 1 | DOI: 10.17632/4d27cfy8xr.1
Contributors:
Bambang Pratama,
,
,

Description

Data protection impact assessment (DPIA) is a tool that can be used to map an organization's readiness in managing personal data. Provisions regarding DPAI are regulated in the GDPR and are also adopted by countries that adhere to the GDPR regulatory model. Under normative provisions, children's personal data is sensitive data that must be protected, it's can be viewed into two point of view, namely as part of sensitive data and stand alone as a subject that must be protected by law. On many assessment models, the methods oftentimes tedious to fill in with the many questions asked. In addition, it also demands to be answered by the managerial level within an organization. This makes the accuracy of the assessment very subjective because it can only be seen at certain levels in the organization. Whereas the impact assessment method must be able to see holistically at every level on the organization. This paper offers a new model of impact assessment by combining the assessment methods of ISO 9001 2015, NIST 800-300 R1, Startup readiness level, and regulations on personal data protection. By merging the models, four approaches were formulated, namely: (1) leadership, (2) process, (3) technology, and (4) regulatory/law. The assessment model offered is made to be simple so that it is easy to fill in, can be filled in by any level of management, is not fatigue to fill out, and can be applied to public institutions and private institutions with different levels of readiness, so that they can be mapped out early on how the conditions for protecting personal data are. in an organization.

Files

Categories

Analytical Modeling

Funders

Licence