Breach Severity Assessment (ENISA Methodology)
The ENISA methodology is a structured approach for estimating how serious a personal data breach is for the individuals affected. It works out a severity score by considering what kind of data was involved, how easily people could be identified, and any circumstances that make the situation better or worse. Organisations and tools use it to help gauge the potential impact of a breach in a consistent, criteria-based way.
The ENISA breach severity methodology provides a criteria-based scoring model for assessing the severity of a personal data breach to affected individuals. Per the evidence, severity (SE) is calculated as SE = (DPC × EI) + CB, where DPC reflects the Data Processing Context (the type and sensitivity of the data involved), EI reflects the Ease of Identification of the individuals concerned, and CB represents aggravating or mitigating Circumstances of the Breach. The methodology supplies objective, structured criteria to support consistent severity estimation and is commonly embedded in breach assessment tools. Note: the precise definitions, scoring bands, and weighting of the DPC, EI, and CB parameters are not detailed in the evidence provided and should be verified against the current ENISA guidance. This severity assessment is analytical guidance and is distinct from, though it may inform, the separate risk-based determinations required under the GDPR for breach notification to a supervisory authority and communication to data subjects; those obligations should be assessed against the applicable Regulation text and regulator guidance.
Why it matters
When a personal data breach occurs, one of the first challenges organisations face is gauging how serious the incident is for the individuals affected. The ENISA methodology matters because it offers a structured, criteria-based way to estimate breach severity rather than relying on ad hoc judgement. By breaking the assessment into defined parameters, the nature of the data involved, how easily affected individuals can be identified, and the circumstances surrounding the breach, it promotes consistency across incidents and across the different people who may be involved in an assessment.
Consistency has practical value. A defensible, documented severity assessment supports internal decision-making and can help demonstrate a considered approach if a regulator later examines how an organisation handled an incident. The methodology's objective, structured criteria are widely embedded in breach assessment tools, which reflects demand for a repeatable analytical framework that reduces the influence of subjective bias when teams are working under time pressure.
It is important to keep the boundary of this tool clear. A severity score produced under the ENISA methodology is analytical guidance; it is distinct from, though it may inform, the separate risk-based determinations that the GDPR requires for notifying a supervisory authority and communicating with data subjects. Those notification and communication obligations must be assessed against the applicable Regulation text and current regulator guidance, and should not be treated as automatically satisfied or displaced by a severity score alone.
Who it's relevant to
Inside Breach Severity Assessment (ENISA Methodology)
Common questions
Answers to the questions practitioners most commonly ask about Breach Severity Assessment (ENISA Methodology).