-
Notifications
You must be signed in to change notification settings - Fork 115
Open
Description
Description:
In the Processing Activities module, after adding a new Processing Activity via the sidebar tab and then editing it, users can create DPIA (Data Protection Impact Assessment) and TIA (Transfer Impact Assessment) records and save them without filling any mandatory fields. This violates GDPR compliance rules.
Steps to Reproduce:
- Click on Processing Activitie' from the sidebar.
- Add a new Processing Activity.
- Edit the newly created Processing Activity.
- Navigate to the 'Data Protection Impact Assessment' (DPIA) tab.
- Create a DPIA without filling any fields.
- Click Save.
- Navigate to the 'Transfer Impact Assessment' (TIA) tab.
- Create a TIA without filling any fields.
- Click Save.
Actual Result:
- DPIA and TIA records are saved with all fields empty.
- Only the Processing Name from Overview is reflected.
- No validation or warning is displayed.
Expected Result:**
- DPIA tab must require at least: Description, Potential Risk, Residual Risk.
- TIA tab must require at least: Data Subjects, Transfer, Legal Mechanism, Local Law Risk.
- System should prevent saving and display an error message indicating that mandatory fields are missing.
Note:
I would like to work on fixing this issue if approved or needed.
aktasfatih
Metadata
Metadata
Assignees
Labels
No labels