The GDPR should be reviewed following a change in the risks arising from the processing operations (for example, the use of new technology, when personal data is used for a different purpose, etc.).
If certain changes reduce the risk, in such situations, the re-examination of the risk analysis made may show that it is not necessary for the controller to implement the PVZLP.

