My municipality is considering using Trello as a tool for our leaders to better streamline their workflow. To do this, our DPO tells me we need an initial assessment of DPIA and a risk-analysis (ROS-analyse in Norwegian) to comply with the General Data Protection Regulation (GDPR).
Has anyone written a risk-analysis like this? Preferably in Norwegian, but anything will help:-)