Governata runs the full assessment cycle, from describing the activity and rating its risks through to mitigation measures, approval, and documentation.
Activity description
Risk rating
Mitigation measures
Approval cycle
Full documentation
A service is designed and released, and only then does it emerge that it collects more data than it needs, making changes expensive.
The value of an assessment is not in writing it, but in its decisions being taken before the activity actually begins.

Documenting the activity under assessment, the personal data it processes, and its purpose.

Capturing the privacy risks the activity poses to data subjects and to the organization.

Rating each risk at a defined level, making its priority and need for mitigation clear.

Defining the measures that reduce each risk, with an owner and a target date.

Routing the assessment through review and approval before the activity launches.

Holding completed assessments in a register available at any review or update.
Starting an assessment for the activity and documenting its description, data, and purpose.
Capturing the privacy risks tied to the activity and rating the level of each.
Setting mitigation measures for each risk and assigning an owner and a date.
Routing the assessment through approval and saving its outcome in the register.

Privacy requirements known at design stage, so they do not appear as an obstacle just before launch.

One assessment cycle for every activity, instead of a differently shaped document with each project.

Documented evidence that the organization assesses risk before processing rather than after.

A clear view of risks and their mitigation when assessing any obligation or liability.

Launching a service or system that processes personal data not previously processed.

Processing highly sensitive categories of data, such as health or financial information.

Processing data on a large number of individuals, which multiplies the effect of any failure.

Transferring personal data to a party outside the organization for any purpose.
It is a structured assessment carried out before an activity that processes personal data begins, to identify its risks to data subjects and define measures to reduce them.
Typically when launching a new activity, processing sensitive data, processing at large scale, or applying new technologies to personal data.
Because changing a service after release is harder and more expensive. Early assessment allows the design to change instead of managing the consequences later.
A RoPA documents what the organization actually processes. An assessment examines a specific activity before it starts and rates its risks. One is ongoing documentation, the other is prior evaluation.
Measures are defined to bring the risk to an acceptable level. Where that proves impossible, the activity itself or its scope may be reconsidered.
Yes, when it changes materially, such as an expanded processing purpose or newly added data categories.
An activity description, rated risks, mitigation measures, and a documented approval cycle, for every activity processing personal data.