The guideline 'Risk Assessment & Data Protection Impact Assessment' is entirely new and was compiled with regard to the new requirements of Article 32 and Article 35 of the GDPR. It provides guidance on the methodology that can be applied when developing the risk assessment and the data protection impact assessment, and compares the requirements of the Regulation with methods that are already known to many companies from information security standards.