High Risk to Individuals
'High risk to individuals' describes a situation where a particular way of handling personal data creates a heightened chance of harm to people, or a chance of more serious harm, or both. When data processing is likely to reach this heightened level, an organisation generally must carry out a Data Protection Impact Assessment before proceeding. The idea centres on potential harm to people, which can be physical, material (such as financial loss), or non-material (such as distress or loss of control over one's data).
Under the GDPR and UK GDPR, 'high risk' is a qualified threshold applied to the phrase 'likely to result in a high risk to the rights and freedoms of natural persons,' which triggers the obligation to conduct a Data Protection Impact Assessment (associated in the Regulation with the DPIA provisions in Article 35). Per ICO guidance, 'high risk' implies a higher threshold reached either because harm is more likely, because the potential harm is more severe, or through a combination of the two; a 'risk' in this context is the potential for significant physical, material or non-material harm to individuals. The assessment is inherently contextual and forward-looking, evaluated case by case against the nature, scope, context and purposes of the processing, and is distinct from (though related to) the separate high-risk trigger for breach notification to affected individuals. Note that regulators and national guidance publish indicative lists of processing types considered likely to be high risk, and these lists and their application can vary between member states and over time; practitioners should verify the current official text and applicable supervisory authority guidance. The term as used here is specific to data protection risk and should not be confused with unrelated security-sector uses of 'high-risk individual' (for example, personal safety guidance identifying persons who are potential targets of threats).
Why it matters
The concept of 'high risk to individuals' functions as a gatekeeping threshold within the GDPR and UK GDPR accountability framework. When processing is likely to result in a high risk to the rights and freedoms of individuals, an organisation generally must carry out a Data Protection Impact Assessment before it begins that processing. Getting this determination right matters because it shapes whether a formal risk assessment is legally required, and because it forces organisations to consider potential harm to people before harm can occur rather than after.
The threshold is deliberately focused on harm to individuals, not on inconvenience to the organisation. Per ICO guidance, a 'risk' in this context is the potential for significant physical, material or non-material harm, meaning financial loss, distress, or loss of control over one's data can all count. This orientation keeps the assessment person-centred: the question is not only whether something could go wrong technically, but whether people could be seriously affected. Because the standard is qualified ('likely to result in a high risk') rather than absolute, organisations must reason carefully about both the probability and the severity of potential harm.
It is worth noting that the term as used here is specific to data protection risk assessment and should not be confused with unrelated security-sector uses of 'high-risk individual', which describe people who may be targets of threats. The data protection meaning concerns how personal data is processed, not the personal safety profile of a given person. Practitioners should also be aware that indicative lists of high-risk processing types are published by regulators and can vary between member states and over time, so the current official text and applicable supervisory authority guidance should be verified.
Who it's relevant to
Inside High Risk to Individuals
Common questions
Answers to the questions practitioners most commonly ask about High Risk to Individuals.