The requirement does not apply where the controller employs fewer than 250 persons and the processing is not likely result in a risk for the rights and freedoms of data subjects, is not occasional,or is not of special categories of data (which means mostorganisations will be caught)