AEPD guidelines on risk assessments and data protection impact assessments
To facilitate compliance with the General Data Protection Regulation, the Spanish Data Protection Agency, or AEPD, has published data protection impact assessment guidelines and risk assessment guidelines (in Spanish).
The guidelines provide information and examples about the concepts, measures and techniques that could be applied to identify, evaluate and manage the risks and high risks involved in the processing of personal data. The guidelines also help organizations know how to reduce such risks to an acceptable or tolerable level, meet individuals’ expectations of privacy, and comply with the GDPR.
Source: AEPD guidelines on risk assessments and data protection impact assessments