Skip to main content
Category: Impact Assessments & Documentation

Assessment of Risks to Rights and Freedoms

Also known as: Risk to Rights and Freedoms, Risks to the Rights and Freedoms of Data Subjects, Risks to the Rights and Freedoms of Natural Persons
Simply put

An assessment of the risks to rights and freedoms is an evaluation of how a data processing activity might harm the individuals whose personal data is involved. It is used to judge whether processing poses a 'high risk' that triggers additional obligations, such as carrying out a fuller impact assessment. The concept also informs decisions about whether certain incidents need to be reported to a regulator or affected individuals.

Formal definition

The assessment of risks to the rights and freedoms of natural persons is a core analytical step within data protection accountability, appearing notably in the data protection impact assessment (DPIA) process, where the assessment expressly includes evaluating the risks to the rights and freedoms of data subjects and the measures envisaged to address those risks (Art. 35 GDPR). The 'likely to result in a high risk to the rights and freedoms' standard operates as the threshold determining when a DPIA is mandatory before processing begins. Related risk-to-rights-and-freedoms standards also inform other GDPR determinations, such as whether an incident requires notification; practitioners should note that the precise application of the standard is context- and risk-dependent, may be shaped by supervisory authority guidance (for example, guidance from the ICO and national authorities such as the Irish Data Protection Commission), and the reader should verify specific article references and thresholds against the current official text, including any UK GDPR or member state variations.

Why it matters

The assessment of risks to the rights and freedoms of natural persons is the pivot on which several key GDPR obligations turn. Whether an organisation must carry out a fuller data protection impact assessment before processing begins depends on whether the processing is 'likely to result in a high risk to the rights and freedoms' of individuals. Getting this threshold judgment wrong in either direction has consequences: underestimating risk can leave high-risk processing without the mandatory safeguards, while treating every activity as high risk can dilute the accountability effort and obscure the genuinely serious cases.

The same risk-to-rights-and-freedoms standard also informs other determinations, including whether a personal data incident needs to be reported to a supervisory authority or communicated to affected individuals. This makes the assessment more than a one-off form-filling exercise; it is a recurring analytical discipline that connects the design of processing activities to breach response. Because the standard is expressed in qualitative terms rather than fixed numeric triggers, its application is context- and risk-dependent.

Practitioners should be aware that the precise application of the standard may be shaped by supervisory authority guidance, and different regulators, for example the ICO in the UK and the Irish Data Protection Commission, may publish their own lists of processing operations and interpretive material. There may also be UK GDPR and member state variations. Readers should verify specific article references and thresholds against the current official text rather than relying on any single snapshot.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy teams typically own the methodology for assessing risks to rights and freedoms, advising on when the high-risk threshold is met and a DPIA becomes mandatory, and maintaining the documentation that evidences the accountability decision. They generally monitor relevant supervisory authority guidance, which can shape how the standard applies in specific contexts.
Compliance and Legal Counsel
Legal and compliance functions use the assessment to judge whether processing can proceed, what safeguards are required, and whether an incident crosses the threshold for reporting to a regulator or affected individuals. They should verify the applicable article references and thresholds against the current official text, noting possible UK GDPR and member state variations.
Product and Engineering Teams
Teams designing new processing activities are typically the first to surface the facts that drive a risk assessment, the nature, scope, context and purposes of processing. Engaging early helps identify potentially high-risk processing before it begins and allows technical and organisational measures to be built in rather than retrofitted.
Incident and Breach Response Teams
Because the risk-to-rights-and-freedoms standard informs whether an incident requires notification, breach response teams apply the same analytical lens under time pressure. A consistent, documented approach to assessing risk supports defensible and timely notification decisions.

Inside Assessment of Risks to Rights and Freedoms

Focus on risks to individuals
The assessment centres on risks to the rights and freedoms of natural persons (data subjects), not primarily on organisational or commercial risk. This orientation flows from the GDPR's framing of accountability and, in particular, informs the threshold for when a Data Protection Impact Assessment is required under Article 35.
Likelihood and severity
Risk is generally evaluated as a function of the likelihood of an adverse event and the severity of its potential impact on individuals. Both dimensions are typically considered together rather than in isolation, and the outcome is a matter of assessment rather than a fixed calculation.
Types of harm considered
The rights and freedoms at issue extend beyond privacy narrowly conceived and can include physical, material, and non-material harm such as discrimination, financial loss, reputational damage, loss of confidentiality, or loss of control over personal data. The precise range is informed by regulatory guidance rather than an exhaustive statutory list.
Relationship to the DPIA trigger
Where processing is likely to result in a high risk to rights and freedoms, a DPIA under Article 35 is generally required. The risk assessment therefore functions as a gateway step that determines whether the more formal DPIA process must be undertaken.
Contextual factors
The assessment is context dependent, taking into account the nature, scope, context, and purposes of the processing, the categories of data (including whether special category data under Article 9 is involved), and the categories and vulnerability of the individuals affected.
Mitigation and residual risk
Measures intended to reduce risk are considered as part of the assessment, and any residual risk after mitigation is evaluated. Where high residual risk remains, consultation with the supervisory authority may be required; practitioners should verify the applicable procedure against the current official text.

Common questions

Answers to the questions practitioners most commonly ask about Assessment of Risks to Rights and Freedoms.

Is the assessment of risks to rights and freedoms only about risks to data security or confidentiality?
No. This is a common misconception. The assessment concerns risks to the rights and freedoms of natural persons more broadly, not just security or confidentiality of data. It typically encompasses potential physical, material, or non-material harms, such as discrimination, loss of control over personal data, reputational damage, financial loss, or other significant social or economic disadvantage. Security is one dimension, but the concept is wider and is oriented toward the impact on individuals rather than solely on the data or systems themselves.
Does a risk to rights and freedoms need to be high before a controller has to consider it?
Not generally. The assessment of risk is relevant across a range of accountability and transparency obligations, and the level of risk influences which specific measures apply rather than whether risk should be considered at all. A higher likelihood and severity of risk may trigger additional steps, such as conducting a Data Protection Impact Assessment under Article 35 where processing is likely to result in a high risk. Lower-risk processing still involves an assessment; the outcome simply calibrates the response. The threshold that triggers particular obligations should be checked against the relevant provision and current regulatory guidance.
What factors are typically weighed when assessing risks to rights and freedoms?
Assessments generally consider both the likelihood and the severity of potential harm to individuals. Relevant factors often include the nature, scope, context, and purposes of the processing; the categories and volume of personal data involved, including whether special category data under Article 9 is present; the vulnerability of the data subjects; the use of new technologies; and the potential consequences should the risk materialize. The specific factors and their weighting are context dependent and should be documented as part of the controller's accountability record.
How should the outcome of a risk assessment be documented?
In most cases it is advisable to record the assessment in a way that demonstrates the reasoning applied, the risks identified, their likelihood and severity, and the measures selected to address them. This supports the accountability principle and can help demonstrate that risk was considered before processing began. The appropriate level of detail is proportionate to the processing and its risks. Controllers should retain and review such records, and update them where processing or its context changes.
When does a risk assessment need to escalate into a Data Protection Impact Assessment?
Where an initial assessment indicates that processing is likely to result in a high risk to the rights and freedoms of individuals, a Data Protection Impact Assessment under Article 35 is generally required. The two are distinct but linked: a preliminary risk assessment often serves as the screening step that determines whether the more formal DPIA process is needed. Supervisory authorities may also publish lists of processing operations that require, or do not require, a DPIA, and these can vary between member states, so the applicable lists and guidance should be verified.
How often should a risk assessment be reviewed?
Risk assessments are typically treated as ongoing rather than one-time exercises. It is generally advisable to review an assessment when there is a material change to the nature, scope, context, or purposes of the processing, when new technologies or data categories are introduced, or when new risks emerge. Periodic review, even absent a triggering change, can help ensure the assessment remains current. The appropriate review cadence is context dependent and should be aligned with the organization's broader accountability and governance arrangements.

Common misconceptions

The assessment measures risk to the organisation.
The assessment is directed at risks to the rights and freedoms of natural persons, not primarily at commercial, financial, or reputational risk to the controller. Organisational risk may be relevant to a business more broadly, but it is not the focus of this analysis.
Any identified risk automatically triggers a DPIA.
A DPIA under Article 35 is generally required where processing is likely to result in a high risk. Lower-level risks may still need to be managed under the accountability principle, but they do not necessarily mandate a full DPIA. The threshold is a matter of assessment and informed by regulatory guidance.
Risk is only about the probability of a data breach.
Risk reflects both the likelihood and the severity of potential harm, and it encompasses a range of adverse outcomes such as discrimination or loss of control, not solely the chance of a security incident. Severity of impact can be high even where likelihood is comparatively low.

Best practices

Assess likelihood and severity together, documenting the reasoning for each so the conclusion can be justified under the accountability principle and revisited if circumstances change.
Frame the analysis around harm to individuals, considering physical, material, and non-material impacts including discrimination, financial loss, and loss of control, rather than defaulting to organisational risk.
Take account of context, including the nature and purposes of the processing, whether special category data under Article 9 is involved, and the vulnerability of the individuals concerned.
Use the assessment to determine whether the high-risk threshold for a DPIA under Article 35 is met, and treat it as a gateway step rather than a substitute for the DPIA itself.
Record mitigation measures and evaluate residual risk, escalating to prior consultation with the supervisory authority where high residual risk remains, and verify the applicable procedure against the current official text.
Review and update the assessment when processing, data categories, or the risk environment change, since risk evaluation is context dependent and can shift over time.