The requirement does not apply where the controller employs
fewer than 250 persons and the processing is not likely result in a
risk for the rights and freedoms of data subjects, is not occasional,
or is not of special categories of data (which means most
organisations will be caught)