Risk Profile Analysis Test



We conduct automated decision making with legal or similar significant effect that includes the use of profiling or algorithmic means or use of sensitive personal data as an element to determine access to services or that results in legal or similarly significant effects;:

we never do
we hardly do this
We do this regularly
we always do this





We use of personal data on a large-scale for a purpose other than that for which the data was initially collected;:

  Yes we do
we do this sometimes
we hardly do this
we never do this





We have made some changes in our internal processing that may result in higher risk to data subjects:

Yes we have
No we have not





We process sensitive personal data or data relating to children or vulnerable groups:

  no we don't
Yes we do




We conduct large scale processing of personal data:

never
sometimes
regularly
always





We combine, link or cross-reference datasets from different sources and process these for new/different purposes;

No we don't
We Rarely do it
Yes we do





We have adopted innovative use or application of new technological or organizational solutions:

No we haven't
Yes we have
>




We conduct large scale processing of personal data:

No we dont
We conduct it on a small scale
We conduct it on a large scale




We perform systematic monitoring of publicly accessible areas on a large scale:

no we dont
We do it at times
We do it on a small scale
Yes we do




We have adopted innovative use or application of new technological or organizational solutions:

  No we have not
we adopted some
Most are adopted
Yes we have




Our processing activities could prevent a data subject from exercising a right:

Yes it does
some of it does
No it does not




We process details around salary, fee, commission, bonus, gratuity, allowance or other remuneration paid or payable to the data subject by any person:

Yes we do
We process some of them
We process most of them
No we don't




We process details around income that a data subject receives from the sale of any goods or property:

no we don't
we process little data of this nature
We process a lot of data of this nature
Yes we do




We process credit card, charge card or debit card data issued to or in the name of the data subject.

never
sometimes
regularly
always




We process account numbers a data subject has with any entity that is a bank or finance company.

never
sometimes
regularly
always




We process information that identifies, or is likely to lead to the identification of a child in conflict with the law or in need of care and protection.

we never do this
sometimes we do
we do it regularly
we always do this




We process private key of or relating to a data subject that is used or may be used
- to create a secure electronic record or secure electronic signature;
- to verify the integrity of a secure electronic record;
- to verify the authenticity or integrity of a secure electronic signature

never
sometimes
regularly
always





We process data about the net worth or creditworthiness of a data subject.

We never process such data
We do this sometimes
We regularly do this
We always process such data



We process data about deposit or withdraw of moneys by a data subject with any entity.

We never do this
We do this sometimes
We regularly do this
Yes we do




We process data about withdrawal of moneys deposited by individual any entity or a payment system.

no we dont
we do it at times
We regularly do this
We do this most of the time




We process data about the granting by a person of advances, loans and other facilities by which the data subject, being a customer of the entity, has access to funds or financial guarantees.

never
sometimes
regularly
always




The incurring by the entity of any liabilities on behalf of the data subject.

never
sometimes
regularly
always




The payment of any moneys, or transfer of any property, by any person to the individual, including the amount of the moneys paid or the value of the property transferred, as the case may be is done online.

never
sometimes
regularly
always




The data subject’s investment in any capital markets products.

never
sometimes
regularly
always




Any term and condition, premium or benefits payable, or any detail relating to the condition of health, from an accident, health, or life policy of which the data subject is the policy owner or a beneficiary.

never have any of this data
We have some of this data
We handle most of this data
We handle all of this data




The assessment, diagnosis, treatment, prevention or alleviation by a health professional of any of the following affecting the data subject
- any sexually‑transmitted diseases
- Human Immunodeficiency Virus Infection;
- mental disorder;
- substance abuse and addiction.

We never handle any of this data
We handle some of this data
We handle most of this data
We handle all of this data




The provision of treatment to the individual for or in respect of
- the donation or receipt of a human egg or human sperm
- any contraceptive operation or procedure or abortion

We never handle any of this data
We handle some of this data
We handle most of this data
We handle all of this data




Any of the following
- the donation and removal of any organ from the body of the deceased individual for the purpose of its transplantation into the body of another individual
- the donation and removal of any specified organ from the individual, being a living organ donor, for the purpose of its transplantation into the body of another individual
- the transplantation of any organ mentioned in paragraph (a) or (b) into the body of the individual

We never handle any of this data
We handle some of this data
We handle most of this data
we handle all of this data




The suicide or attempted suicide of the individual.

We never handle any of this data
We handle most of this data
We handle some of this data
We handle all of this data




Any of the following
- information that the individual is or had been adopted the identity of the natural father or mother of the data subject
- the identity of the adoptive father or mother of the subject
- the identity of any applicant for an adoption order
- the identity of any person whose consent is necessary under that Act for an adoption order to be made, whether or not the court has dispensed with the consent of that person in accordance with that Act.

We never handle any of this data
We handle most of this data
We handle some of this data
We handle all of this data




Do you collect any of the following data sets?
1. Racial or ethnic origin.
2. Political opinions.
3. Religious or philosophical beliefs.
4. Trade union membership.
5. Genetic data.
6. Sexual orientation and related data.
7. Biometric data.
8. Marital status and family details
9. Physical or mental health or condition

We never handle any of this data
We handle most of this data
We handle some of this data
We handle all of this data




We process data bout the granting by a person of advances, loans and other facilities by which the data subject, being a customer of the entity, has access to funds or financial guarantees.

We never handle any of this data
We handle most of this data
We handle some of this data
We handle all of this data




We use personal data for marketing purposes

never
sometimes
regularly
always




Canvassing political support among the electorate.
1. Crime prevention and prosecution of offenders (including operating security CCTV systems).
2. Gambling.
3. Operating an educational institution.
4. Health administration and provision of patient care.
5. Hospitality industry firms but excludes tour guides.
6. Property management including the selling of land.
7. Provision of financial services.
8. Telecommunications network or service providers.
9. Businesses that are wholly or mainly in direct marketing.
10.Transport services firms (including online passenger hailing applications)
11.Businesses that process genetic data.
the policy owner or a beneficiary.

We never handle any of this data
We handle most of this data
We handle some of this data
We handle all of this data