Skip to main content
Category: Security & Breach Notification

High Risk to Individuals

Also known as: high risk to the rights and freedoms of individuals, high risk processing, likely to result in a high risk
Simply put

'High risk to individuals' describes a situation where a particular way of handling personal data creates a heightened chance of harm to people, or a chance of more serious harm, or both. When data processing is likely to reach this heightened level, an organisation generally must carry out a Data Protection Impact Assessment before proceeding. The idea centres on potential harm to people, which can be physical, material (such as financial loss), or non-material (such as distress or loss of control over one's data).

Formal definition

Under the GDPR and UK GDPR, 'high risk' is a qualified threshold applied to the phrase 'likely to result in a high risk to the rights and freedoms of natural persons,' which triggers the obligation to conduct a Data Protection Impact Assessment (associated in the Regulation with the DPIA provisions in Article 35). Per ICO guidance, 'high risk' implies a higher threshold reached either because harm is more likely, because the potential harm is more severe, or through a combination of the two; a 'risk' in this context is the potential for significant physical, material or non-material harm to individuals. The assessment is inherently contextual and forward-looking, evaluated case by case against the nature, scope, context and purposes of the processing, and is distinct from (though related to) the separate high-risk trigger for breach notification to affected individuals. Note that regulators and national guidance publish indicative lists of processing types considered likely to be high risk, and these lists and their application can vary between member states and over time; practitioners should verify the current official text and applicable supervisory authority guidance. The term as used here is specific to data protection risk and should not be confused with unrelated security-sector uses of 'high-risk individual' (for example, personal safety guidance identifying persons who are potential targets of threats).

Why it matters

The concept of 'high risk to individuals' functions as a gatekeeping threshold within the GDPR and UK GDPR accountability framework. When processing is likely to result in a high risk to the rights and freedoms of individuals, an organisation generally must carry out a Data Protection Impact Assessment before it begins that processing. Getting this determination right matters because it shapes whether a formal risk assessment is legally required, and because it forces organisations to consider potential harm to people before harm can occur rather than after.

The threshold is deliberately focused on harm to individuals, not on inconvenience to the organisation. Per ICO guidance, a 'risk' in this context is the potential for significant physical, material or non-material harm, meaning financial loss, distress, or loss of control over one's data can all count. This orientation keeps the assessment person-centred: the question is not only whether something could go wrong technically, but whether people could be seriously affected. Because the standard is qualified ('likely to result in a high risk') rather than absolute, organisations must reason carefully about both the probability and the severity of potential harm.

It is worth noting that the term as used here is specific to data protection risk assessment and should not be confused with unrelated security-sector uses of 'high-risk individual', which describe people who may be targets of threats. The data protection meaning concerns how personal data is processed, not the personal safety profile of a given person. Practitioners should also be aware that indicative lists of high-risk processing types are published by regulators and can vary between member states and over time, so the current official text and applicable supervisory authority guidance should be verified.

Who it's relevant to

Data Protection Officers and privacy leads
DPOs and privacy teams typically own the process of screening proposed processing against the high-risk threshold and deciding whether a DPIA is required. Because the standard is contextual and depends on the likelihood and severity of potential harm, this group needs to document its reasoning and keep pace with evolving regulator guidance and indicative lists, which can vary between member states.
Compliance leads and accountability owners
Those responsible for demonstrating accountability rely on a consistent, defensible method for identifying high-risk processing, since the determination drives when formal impact assessments must be carried out before processing begins. Treating potential harm to individuals, physical, material or non-material, as the central test helps align the compliance programme with the person-centred focus of the Regulation.
Product and engineering teams
Teams designing systems that process personal data are often the first to know when a new use of data could raise the likelihood or severity of harm. Understanding what pushes processing over the high-risk threshold allows them to flag concerns early and support a DPIA before deployment rather than after harm could arise.
Legal advisers
Lawyers advising on data processing need to distinguish the high-risk trigger for requiring a DPIA from the separate high-risk trigger relating to breach notification, and to advise clients that determinations are case by case and subject to current supervisory authority guidance. They should also caution against conflating this data protection meaning of 'high risk' with unrelated security-sector uses of the phrase.

Inside High Risk to Individuals

Risk to Rights and Freedoms
The GDPR frames risk in terms of potential harm to the rights and freedoms of natural persons, not merely to the organisation. This encompasses physical, material, and non-material damage, and the concept centres on individuals (data subjects) rather than legal entities or anonymous data.
High Risk as a Threshold Concept
"High risk" is a heightened level of risk that triggers specific obligations. It typically arises where processing is likely to result in a significant likelihood or severity of harm to individuals. The Regulation does not exhaustively define the term, so assessment is context-dependent and informed by regulatory guidance.
Link to Data Protection Impact Assessments
Where a type of processing is likely to result in a high risk to the rights and freedoms of individuals, a Data Protection Impact Assessment (DPIA) is generally required under Article 35. The DPIA is the primary instrument for identifying and mitigating such risk before processing begins.
Indicative Risk Factors
Regulatory guidance identifies factors that tend to indicate high risk, such as systematic and extensive evaluation or profiling, large-scale processing of special category data (Article 9) or data on criminal matters, and systematic monitoring of publicly accessible areas. The presence of multiple factors generally increases the likelihood that processing is high risk.
Consultation and Notification Consequences
A finding of high risk can carry downstream obligations. Where a DPIA indicates high residual risk that cannot be mitigated, prior consultation with the supervisory authority may be required. High risk is also relevant to whether a personal data breach must be communicated to affected individuals.
Severity and Likelihood Assessment
Determining high risk generally involves weighing both the severity of potential harm and the likelihood of it occurring. This is a documented, evidence-based judgement rather than a fixed formula, and its outcome depends on the specific processing context.

Common questions

Answers to the questions practitioners most commonly ask about High Risk to Individuals.

Does every processing activity involving personal data require a Data Protection Impact Assessment?
No. A DPIA is required under Article 35 where processing is likely to result in a high risk to the rights and freedoms of individuals, not for every processing activity. Routine, low-risk processing generally does not trigger the DPIA obligation. Controllers should assess the specific characteristics of the processing against the relevant criteria and, where applicable, any list of high-risk processing operations published by their supervisory authority, to determine whether the high-risk threshold is met. Because supervisory authorities can differ in how they frame these lists, the position should be verified against the guidance applicable in the relevant jurisdiction.
Does 'high risk' mean risk to the organisation's business, such as financial or reputational harm?
No. In this context 'high risk' refers to risk to the rights and freedoms of individuals whose personal data is processed, not to the organisation's own commercial, financial, or reputational interests. The focus is on potential harms to data subjects. Organisational risk may be a separate business consideration, but it is not what the GDPR concept of high risk to individuals is measuring.
How do we decide whether a proposed processing activity crosses the high-risk threshold?
The assessment is typically criteria-based and made before processing begins. Controllers generally consider factors drawn from regulatory guidance, such as large-scale processing, systematic monitoring, use of special category data, evaluation or scoring, automated decision-making with significant effects, processing of vulnerable individuals, and combining or matching datasets. The presence of several such factors tends to increase the likelihood that the threshold is met. Where a supervisory authority has published a list of operations requiring a DPIA, that list should be consulted. Because guidance and lists can vary between regulators and evolve over time, the outcome should be documented and revisited if the processing changes.
What should we do once we conclude that processing is likely to be high risk?
Where processing is likely to result in a high risk, a DPIA under Article 35 is generally required before processing starts. The DPIA typically describes the processing and its purposes, assesses necessity and proportionality, evaluates the risks to individuals, and identifies measures to address those risks. If, after the DPIA and any mitigations, a high residual risk remains, the controller is generally required to consult the supervisory authority under the prior consultation mechanism before proceeding. Where a data protection officer is designated, their advice should be sought as part of the process.
Who within the organisation is responsible for identifying and managing high risk to individuals?
Responsibility for assessing risk and, where required, carrying out a DPIA generally rests with the controller, since the controller determines the purposes and means of processing. In practice this is often coordinated by privacy, compliance, or legal functions in cooperation with the business owners of the processing and, where applicable, engineers or system owners who understand the technical detail. Where a data protection officer has been designated, their advice should be sought and their involvement documented. A processor is typically expected to assist the controller but does not usually bear the primary obligation.
How often should a high-risk assessment or DPIA be reviewed?
Risk assessment is generally treated as an ongoing rather than a one-off exercise. A DPIA is typically reviewed when there is a change to the nature, scope, context, or purposes of the processing that could alter the level of risk to individuals, for example new data categories, new technologies, expanded scale, or new recipients. Periodic review, even absent a specific change, is often considered good practice to confirm that the earlier conclusions and mitigations remain accurate. The appropriate review cadence is context-dependent and should be documented.

Common misconceptions

High risk automatically means the processing is unlawful or prohibited.
A high risk finding generally triggers additional obligations, such as conducting a DPIA and, where residual risk remains high, consulting the supervisory authority. It does not by itself render processing unlawful; the processing may proceed subject to appropriate assessment and mitigation.
High risk is a fixed category defined exhaustively in the GDPR.
The Regulation does not provide an exhaustive definition. Assessment is context-dependent and informed by regulatory guidance and supervisory authority lists, which can vary between member states. What is high risk in one context may not be in another, and interpretations can evolve.
High risk only concerns risks to the organisation, such as fines or reputational damage.
The GDPR's concept of high risk is centred on the rights and freedoms of individuals, including physical, material, and non-material harm to data subjects. Organisational risk is a separate consideration and is not the measure used to trigger DPIA or related obligations.

Best practices

Document your risk assessment methodology, recording how you weigh both the severity and likelihood of potential harm to individuals, so the basis for a high risk determination is defensible and auditable.
Screen processing activities against recognised high-risk indicators (such as large-scale special category processing, systematic profiling, or systematic monitoring) and treat the presence of multiple factors as a strong prompt to conduct a DPIA.
Conduct a DPIA under Article 35 where processing is likely to result in a high risk, and complete it before the processing begins rather than retrospectively.
Where a DPIA identifies high residual risk that cannot be adequately mitigated, escalate to prior consultation with the relevant supervisory authority before proceeding.
Check applicable supervisory authority lists of processing operations requiring a DPIA, and note that these can differ across member states and under the UK GDPR, verifying against the current official guidance.
Re-assess high risk determinations periodically and when processing changes, since the risk picture and regulatory guidance can evolve over time.