Personal data protection law and risk analysis: a practical approach

Authors

  • Fernando-Francisco García-Sotoca Barreda Doctorando del Programa de Doctorado en Unión Europea de la UNED. Responsable de Actuaciones y Proyectos en Protección de Datos del Grupo Tragsa

DOI:

https://doi.org/10.5944/rduned.35.2025.45877

Keywords:

privacy, GDPR, risk, rights, impact

Abstract

In a social environment characterized by the massive availability of our data to organizations with increasing capacity to process them and extract valuable information, the protection of personal data is not only a constitutionally recognized right, but also has the character of a guarantee of other rights.
The protection of these rights, in accordance with the General Data Protection Regulation, must be implemented through a risk management process for which there are multiple methodological proposals, from those specific to the protection of personal data, developed by various control authorities, or the ISO 29134 standard; to others of a generic nature, such as the ISO 31000 standard; or specific to the field of information security, such as the ISO 27005 or MAGERIT standard.
This article explores the particularities of each of these methodologies and, based on various interviews and the analysis of internal regulations and the process of implementing a risk management system in a real organization, proposes various recommendations and good practices for risk management on the rights and freedoms of natural persons.

Downloads

Download data is not yet available.

Published

2025-07-24

How to Cite

García-Sotoca Barreda, F.-F. (2025). Personal data protection law and risk analysis: a practical approach. Revista de Derecho de la UNED (RDUNED), (35), 347–376. https://doi.org/10.5944/rduned.35.2025.45877

Issue

Section

Estudios

Similar Articles

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 > >> 

You may also start an advanced similarity search for this article.