Skip to main content
Category: Security & Breach Notification

Likely to Result in a Risk

Also known as: Likely to Result in a High Risk
Simply put

This is a threshold phrase used in data protection to decide whether a particular use of personal data could pose a meaningful risk to people, and therefore whether extra safeguards or assessments are needed. It looks at both how likely something harmful is to happen and how serious the effect would be. It does not mean harm is certain, only that there is a realistic possibility that should be assessed rather than dismissed.

Formal definition

A trigger standard in the GDPR framework used to determine whether specific obligations apply, most notably whether a Data Protection Impact Assessment is required under Article 35 where processing is 'likely to result in a high risk' to the rights and freedoms of natural persons. Assessing risk generally involves evaluating both the likelihood (probability) of an adverse event and the severity of its potential impact on individuals, and the standard represents a forward-looking screening test rather than proof that harm will materialise. Regulatory guidance, including the Article 29 Working Party guidelines on DPIAs (endorsed by the EDPB) and ICO guidance, provides non-exhaustive examples and criteria for identifying qualifying processing; the specific lists and thresholds are set out in that guidance rather than in the Regulation text itself and can vary between regulators and member state supervisory authorities. Readers should note that the plain word 'risk' and the elevated 'high risk' threshold are distinct concepts within the GDPR and attract different obligations, and the applicable criteria should be verified against current official guidance, which continues to evolve.

Why it matters

The phrase "likely to result in a risk", and its elevated counterpart "likely to result in a high risk", functions as a gatekeeping threshold that determines when specific GDPR obligations are engaged. Most prominently, where processing is likely to result in a high risk to the rights and freedoms of natural persons, a Data Protection Impact Assessment is generally required under Article 35. Because the threshold controls whether these safeguards apply, misjudging it can leave an organisation without an assessment it was obliged to carry out, or conversely lead it to expend effort where the trigger is not met. Getting the calibration right is therefore central to accountability.

The standard is deliberately forward-looking: it asks controllers to assess a realistic possibility of harm before processing begins, rather than to wait for harm to materialise. This screening character means the threshold is exercised under uncertainty and depends on judgement about both the probability of an adverse event and the severity of its potential impact. Regulatory guidance offers illustrative examples of qualifying processing, the ICO, for instance, lists activities such as credit checks and mortgage or insurance applications among pre-contract processes that may be likely to result in high risk, but these lists are non-exhaustive and are set out in guidance rather than in the Regulation text itself.

Because the applicable criteria are drawn from guidance that continues to evolve, and because supervisory authorities in different member states may publish their own lists and interpretations, the practical position can vary. Organisations should treat any single list as a starting point for assessment rather than a definitive rulebook, and should verify the current criteria against the relevant supervisory authority's guidance, particularly where a term is being applied under national implementing law or the UK GDPR.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy teams typically operate this threshold as part of screening new or changed processing. They generally use it to decide when a DPIA or other safeguard is triggered, drawing on supervisory authority guidance and example lists. Because criteria vary between regulators and evolve over time, they should verify the applicable standard against current official guidance for each relevant jurisdiction.
Compliance and Accountability Functions
Those responsible for demonstrating accountability rely on this threshold to justify why an assessment was or was not carried out. Documenting how likelihood and severity were weighed helps evidence that the forward-looking screening test was applied reasonably, rather than that harm was ignored or overstated.
Product and Engineering Teams
Teams designing systems that process personal data, for example activities involving credit checks, insurance or mortgage applications, or other pre-contract processing that may be flagged as high risk in guidance, benefit from applying this threshold early. Identifying potential triggers at the design stage supports timely assessment and helps embed safeguards before processing begins.
Legal Advisers
Lawyers advising on GDPR obligations use this threshold to scope where duties such as a mandatory DPIA under Article 35 arise. They should distinguish the plain 'risk' standard from the elevated 'high risk' threshold, note that qualifying criteria derive from guidance rather than the Regulation text, and flag where member state derogations or divergence between the EU and UK GDPR may affect the analysis.

Inside Likely to Result in a Risk

Risk-based threshold
The phrase 'likely to result in a risk' functions as a threshold that triggers certain GDPR obligations. It denotes a probability and severity assessment of adverse effects on individuals rather than a certainty of harm, and it sits below the higher threshold of 'high risk' used elsewhere in the Regulation.
Personal data breach notification (Article 33)
Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, the controller generally must notify the competent supervisory authority. Where a breach is unlikely to result in such a risk, notification to the authority may not be required, though the controller should document its reasoning.
'High risk' escalation (Articles 34 and 35)
The related but distinct phrase 'high risk' raises the bar. A breach 'likely to result in a high risk' generally triggers communication to affected data subjects under Article 34, and processing 'likely to result in a high risk' generally triggers the requirement to carry out a Data Protection Impact Assessment under Article 35. Practitioners should not conflate the plain 'risk' threshold with the 'high risk' threshold.
Rights and freedoms of natural persons
The risk assessed relates to potential adverse impacts on individuals, which can include but is not limited to material and non-material damage such as loss of control over personal data, discrimination, identity theft, financial loss, reputational damage, or other significant economic or social disadvantage. Because the GDPR concerns personal data of individuals, this analysis does not generally extend to anonymous data or the data of legal entities.
Probability and severity factors
Assessing likelihood typically involves weighing both the probability that an adverse effect occurs and the severity if it does. Relevant considerations commonly include the nature, sensitivity and volume of the data (including any Article 9 special category data), the ease of identifying individuals, the number of affected data subjects, and the potential consequences. This is a contextual, case-by-case evaluation rather than a fixed formula.
Documentation and accountability
Even where a controller concludes that a risk is unlikely, the accountability principle generally supports recording the assessment and its rationale so the position can be justified to a supervisory authority. The threshold is a judgment that should be evidenced rather than assumed.

Common questions

Answers to the questions practitioners most commonly ask about Likely to Result in a Risk.

Does "likely to result in a risk" mean the same thing as the "high risk" threshold that triggers a Data Protection Impact Assessment?
No. These are distinct thresholds that appear in different contexts within the GDPR and should not be conflated. The "likely to result in a risk" standard is generally associated with obligations such as notifying the supervisory authority of a personal data breach, whereas the higher "likely to result in a high risk" standard is generally associated with obligations such as communicating a breach to affected data subjects and with the requirement to carry out a Data Protection Impact Assessment. The word "high" is doing meaningful work: it signals a more serious level of potential impact. Because the two thresholds carry different consequences, you should identify which obligation you are assessing before applying the test. Regulatory guidance on how to distinguish the levels exists and may evolve, so verify the current position against the official text and applicable guidance.
If there is any conceivable risk at all, does that automatically mean the threshold is met?
Not necessarily. The phrase uses the qualifier "likely," which points to an assessment of probability and significance rather than the existence of any theoretical or remote possibility of harm. A purely speculative or negligible risk would not typically satisfy the standard on its own. The assessment generally weighs factors such as the nature, sensitivity, and volume of the data involved, the ease with which affected individuals could be identified, the potential severity of consequences, and any mitigating measures in place. This is a context-dependent judgement rather than a mechanical test, and reasonable assessments can differ. Where the outcome is uncertain, it is prudent to document your reasoning and, in borderline cases, take a cautious approach.
How should we document our assessment of whether a situation is likely to result in a risk?
It is generally advisable to keep a contemporaneous, reasoned record of how you reached your conclusion, because the ability to demonstrate your reasoning supports the broader accountability expectations under the GDPR. Such a record typically captures the facts considered, the categories and volume of personal data involved, the potential impact on individuals, any mitigating factors, and the resulting decision. Documenting the assessment is useful whether the conclusion is that the threshold is met or not met, since a decision not to notify or not to take further action may itself need to be justified later. The specific format is not prescribed, so organisations often align it with their existing risk and breach-handling procedures. Verify any procedural expectations against current guidance from the relevant supervisory authority.
Who within an organisation should make the "likely to result in a risk" determination?
Responsibility for the determination generally rests with the controller, since it is the controller that carries the associated obligations. In practice, the assessment is often made by the individuals or team responsible for incident and breach handling, frequently with input from a Data Protection Officer where one has been designated, and sometimes with legal or security colleagues. Where a Data Protection Officer is involved, their role is typically advisory rather than decision-making, and the controller remains accountable for the outcome. Where processing involves a processor, the processor may need to supply information to enable the controller's assessment, but the threshold judgement itself is generally for the controller. Allocate these roles clearly in your internal procedures so that assessments can be made promptly.
How quickly does the assessment need to happen in a breach scenario?
The assessment of whether an incident is likely to result in a risk is typically time-sensitive, because breach notification obligations operate against defined timeframes and the outcome of the assessment determines whether and how you must act. This means organisations generally benefit from having a pre-defined process that can be triggered rapidly, rather than deciding how to assess risk for the first time during a live incident. The assessment may need to be revisited as new facts emerge, so an initial view can be provisional and updated. Because the precise timing requirements attach to the underlying obligations rather than to the risk threshold itself, confirm the applicable deadlines and any interpretive guidance against the current official text before relying on a specific interval.
What factors typically feed into the assessment in practice?
Assessments generally take into account a combination of factors rather than any single element. These commonly include the type and sensitivity of the personal data concerned, noting that special category data may raise the potential for more serious impact, the volume of data and number of individuals affected, how readily the affected individuals could be identified, the potential consequences for those individuals, and the effectiveness of any technical or organisational measures that reduce the likelihood or severity of harm. Because these factors interact and their weight varies with the circumstances, the exercise is one of reasoned judgement rather than a fixed checklist. Supervisory authorities have published guidance touching on relevant factors, and approaches can differ between regulators, so treat any list as indicative and check current guidance for the jurisdictions that apply to you.

Common misconceptions

'Likely to result in a risk' and 'likely to result in a high risk' mean the same thing, so any breach automatically requires telling affected individuals.
These are distinct thresholds. The lower 'risk' threshold generally governs whether a breach is notifiable to the supervisory authority, while the higher 'high risk' threshold generally governs communication to affected individuals under Article 34 and, in the processing context, the need for a DPIA under Article 35. Not every notifiable breach requires individual communication.
If harm has not actually occurred, there is no risk and no obligation is triggered.
The test is about likelihood, weighing probability and severity of potential adverse effects, not proof of realised harm. A breach can meet the threshold based on the potential for adverse effects even where no concrete damage has yet materialised. Assessment is contextual and should be made on the facts of each case.
A determination that a breach is 'unlikely to result in a risk' means nothing needs to be recorded.
In most cases the accountability principle supports documenting the assessment and reasoning behind concluding that the threshold is not met, so the controller can demonstrate and justify its decision to a supervisory authority if questioned.

Best practices

Assess the threshold on a case-by-case basis, expressly weighing both the probability and the severity of potential adverse effects on individuals rather than applying a fixed rule.
Clearly distinguish which threshold applies to which obligation: use the 'risk' threshold for authority notification and the 'high risk' threshold for communication to data subjects and for triggering a DPIA.
Consider aggravating factors such as the sensitivity of the data, whether Article 9 special category data is involved, the volume of records, the ease of identifying individuals, and the number of affected data subjects.
Document every risk determination, including cases where you conclude a risk is unlikely, so the reasoning can be produced to a supervisory authority under the accountability principle.
Use qualified, evidence-based language in internal assessments and avoid treating any single outcome as automatically compliant, since the conclusion is context and risk dependent.
Verify the applicable obligations and thresholds against the current official text and relevant regulator guidance, and account for possible divergence between the EU GDPR, the UK GDPR, and national implementing measures.