Skip to main content
Category: Security & Breach Notification

Breach Severity Assessment (ENISA Methodology)

Also known as: ENISA Breach Severity Methodology, Data Breach Severity Score, ENISA Severity (SE) Calculation
Simply put

The ENISA methodology is a structured approach for estimating how serious a personal data breach is for the individuals affected. It works out a severity score by considering what kind of data was involved, how easily people could be identified, and any circumstances that make the situation better or worse. Organisations and tools use it to help gauge the potential impact of a breach in a consistent, criteria-based way.

Formal definition

The ENISA breach severity methodology provides a criteria-based scoring model for assessing the severity of a personal data breach to affected individuals. Per the evidence, severity (SE) is calculated as SE = (DPC × EI) + CB, where DPC reflects the Data Processing Context (the type and sensitivity of the data involved), EI reflects the Ease of Identification of the individuals concerned, and CB represents aggravating or mitigating Circumstances of the Breach. The methodology supplies objective, structured criteria to support consistent severity estimation and is commonly embedded in breach assessment tools. Note: the precise definitions, scoring bands, and weighting of the DPC, EI, and CB parameters are not detailed in the evidence provided and should be verified against the current ENISA guidance. This severity assessment is analytical guidance and is distinct from, though it may inform, the separate risk-based determinations required under the GDPR for breach notification to a supervisory authority and communication to data subjects; those obligations should be assessed against the applicable Regulation text and regulator guidance.

Why it matters

When a personal data breach occurs, one of the first challenges organisations face is gauging how serious the incident is for the individuals affected. The ENISA methodology matters because it offers a structured, criteria-based way to estimate breach severity rather than relying on ad hoc judgement. By breaking the assessment into defined parameters, the nature of the data involved, how easily affected individuals can be identified, and the circumstances surrounding the breach, it promotes consistency across incidents and across the different people who may be involved in an assessment.

Consistency has practical value. A defensible, documented severity assessment supports internal decision-making and can help demonstrate a considered approach if a regulator later examines how an organisation handled an incident. The methodology's objective, structured criteria are widely embedded in breach assessment tools, which reflects demand for a repeatable analytical framework that reduces the influence of subjective bias when teams are working under time pressure.

It is important to keep the boundary of this tool clear. A severity score produced under the ENISA methodology is analytical guidance; it is distinct from, though it may inform, the separate risk-based determinations that the GDPR requires for notifying a supervisory authority and communicating with data subjects. Those notification and communication obligations must be assessed against the applicable Regulation text and current regulator guidance, and should not be treated as automatically satisfied or displaced by a severity score alone.

Who it's relevant to

Data Protection Officers and privacy leads
DPOs and privacy teams can use the methodology as a structured input when triaging a personal data breach and documenting how impact on individuals was considered. It should be treated as analytical guidance that informs, but does not replace, the separate GDPR risk assessments for regulator notification and data subject communication.
Incident response and security teams
Teams responding to a cybersecurity incident that involves personal data can apply the criteria-based approach to reach a consistent severity estimate under time pressure, helping to prioritise response and escalation. The DPC, EI, and CB parameters give responders a common vocabulary for describing why an incident is more or less serious for affected individuals.
Vendors and tool builders
Providers of breach assessment and incident management tools frequently embed the ENISA methodology as an objective, source-based scoring model. Builders should reference the current official ENISA guidance for the exact parameter definitions and scoring bands, since the evidence here does not specify them, and should make clear to users where severity scoring ends and legal notification decisions begin.
Compliance and legal advisers
Advisers guiding an organisation through breach handling can use a severity assessment to help structure and document reasoning, while keeping it distinct from the legal determinations required under the applicable Regulation text. Because the methodology is analytical rather than a legal test, its output should be paired with an assessment of notification and communication obligations against current regulator guidance.

Inside Breach Severity Assessment (ENISA Methodology)

Data Processing Context (DPC)
A factor scoring the type of personal data involved and the circumstances of the processing, typically ranging across categories such as simple data, behavioural data, financial data, and sensitive data. Higher scores reflect data whose exposure carries greater potential impact on individuals. The methodology derives from ENISA guidance rather than the GDPR text itself, so it should be treated as a recommended approach rather than a legally binding standard.
Ease of Identification (EI)
A factor assessing how easily the affected data can be linked to a specific individual, from negligible to high. It considers whether identification is possible directly, indirectly, or only with significant additional effort. This element interacts with concepts of pseudonymisation and, at its outer boundary, with data that may be effectively anonymous and therefore generally outside the scope of the GDPR.
Circumstances of Breach (CB)
A factor accounting for aggravating characteristics of the incident, such as loss of confidentiality, integrity, or availability, and factors like malicious intent. These adjustments increase the overall severity score to reflect elevated risk arising from how the breach occurred.
Severity (SE) Calculation
The combined output, typically expressed as SE = DPC x EI + CB, producing a score mapped to qualitative bands such as low, medium, high, and very high. The bands help inform, but do not replace, the controller's own risk assessment and any notification decisions under the GDPR.
Relationship to GDPR Notification Duties
The methodology is intended to support decisions on notification to a supervisory authority and communication to affected data subjects, which under the GDPR are triggered by a risk-based assessment. The severity score is an input to that assessment and does not itself constitute the legal test; readers should verify obligations against the current GDPR text and applicable regulator guidance.

Common questions

Answers to the questions practitioners most commonly ask about Breach Severity Assessment (ENISA Methodology).

Does a high ENISA severity score automatically mean the breach must be notified to the supervisory authority or to affected individuals?
No. The ENISA severity methodology is a risk-scoring tool, not a legal notification trigger. Notification obligations flow from the GDPR itself: notification to the supervisory authority generally applies unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, and communication to affected individuals generally applies where the breach is likely to result in a high risk. A high severity score can inform and support that assessment, but the legal decision must be made against the GDPR standard and any relevant regulator guidance, which can diverge between member states. The score should be treated as an input, not a substitute for the controller's own documented risk determination.
Is the ENISA methodology a mandatory or officially endorsed standard that regulators require controllers to use?
No. The ENISA methodology is guidance rather than a binding legal instrument, and it is not the required approach under the GDPR text. Controllers may use it, adapt it, or apply an alternative structured method for assessing the severity of a personal data breach. Its value is in providing a consistent, defensible framework for documenting reasoning. Because it is guidance and not law, reliance on it does not by itself demonstrate compliance, and different regulators may expect or weigh assessments differently.
What inputs does the ENISA methodology typically use to arrive at a severity score?
The methodology generally combines factors relating to the type of data involved, the circumstances of the breach, and the ease with which affected individuals could be identified or the data misused. These factors are assessed together to produce an overall severity indication. Because the specific weightings and categories are set out in the ENISA guidance itself, you should apply them by reference to the current published version rather than from memory, and document how each factor was scored for the particular incident.
How should the ENISA severity assessment be integrated into an internal breach response workflow?
In most cases it is used as a structured step after the facts of the incident have been gathered but before the formal notification decision is made. Typically the assessment is performed by or with the data protection function, recorded in the internal breach register, and used to support the documented rationale for whether and how to notify. Because it is one input among several, it is generally advisable to run it alongside, not instead of, the legal analysis of risk to rights and freedoms and any sector-specific obligations.
Can the severity score change as more information about the breach emerges?
Yes, and it typically should be revisited. Early scoring is often based on incomplete information, and as the scope, affected data, and number of individuals become clearer the severity indication may rise or fall. Good practice is generally to record the assessment at each stage, note the assumptions made, and update both the score and the notification decision if the facts materially change, since notification timeframes and obligations under the GDPR continue to apply as understanding develops.
Should the completed ENISA assessment be retained as part of the breach documentation?
Generally yes. The GDPR requires controllers to document personal data breaches, including the facts, effects, and remedial action taken, so that the supervisory authority can verify compliance. A recorded severity assessment, together with the reasoning behind the notification decision, typically forms part of that accountability record. Retain the version of the methodology used and the factor-by-factor scoring, and treat the documentation as demonstrating your decision process rather than as proof that the decision was correct.

Common misconceptions

A given ENISA severity score automatically determines whether a breach must be notified to a supervisory authority or to affected individuals.
The methodology is a supporting tool, not the legal test. Notification obligations under the GDPR turn on a risk-based assessment carried out by the controller, and regulators may apply their own expectations. The score should inform, not substitute for, that assessment, and outcomes can vary between member states and regulators.
The ENISA methodology is part of the GDPR and is legally binding.
The methodology derives from ENISA guidance rather than the Regulation text. It is a recommended, widely referenced approach, but it is not mandatory, and other assessment frameworks may reasonably be used subject to the controller's accountability obligations.
A low severity score means a breach is fully compliant or carries no obligations.
A low score generally indicates lower likely impact, but obligations such as internal documentation of the breach can still apply, and the assessment remains context dependent. Compliance cannot be inferred from the score alone, and the position may differ depending on the data and circumstances involved.

Best practices

Use the ENISA severity score as one input into a broader, documented risk assessment rather than as the sole basis for notification decisions under the GDPR.
Record the reasoning behind each factor (DPC, EI, and CB) and the resulting score to support accountability and to evidence the decision if questioned by a supervisory authority.
Reassess severity as new facts emerge during incident investigation, since ease of identification and circumstances of the breach may change and alter the outcome.
Cross-check conclusions against current regulator guidance and applicable national implementing law, as expectations can diverge between member states.
Involve both legal or data protection and technical roles when scoring, so that the data context and identification factors are assessed accurately.
Verify the specific scoring bands and formula against the current official ENISA methodology before relying on them, as guidance can be updated over time.