Likely to Result in a Risk
This is a threshold phrase used in data protection to decide whether a particular use of personal data could pose a meaningful risk to people, and therefore whether extra safeguards or assessments are needed. It looks at both how likely something harmful is to happen and how serious the effect would be. It does not mean harm is certain, only that there is a realistic possibility that should be assessed rather than dismissed.
A trigger standard in the GDPR framework used to determine whether specific obligations apply, most notably whether a Data Protection Impact Assessment is required under Article 35 where processing is 'likely to result in a high risk' to the rights and freedoms of natural persons. Assessing risk generally involves evaluating both the likelihood (probability) of an adverse event and the severity of its potential impact on individuals, and the standard represents a forward-looking screening test rather than proof that harm will materialise. Regulatory guidance, including the Article 29 Working Party guidelines on DPIAs (endorsed by the EDPB) and ICO guidance, provides non-exhaustive examples and criteria for identifying qualifying processing; the specific lists and thresholds are set out in that guidance rather than in the Regulation text itself and can vary between regulators and member state supervisory authorities. Readers should note that the plain word 'risk' and the elevated 'high risk' threshold are distinct concepts within the GDPR and attract different obligations, and the applicable criteria should be verified against current official guidance, which continues to evolve.
Why it matters
The phrase "likely to result in a risk", and its elevated counterpart "likely to result in a high risk", functions as a gatekeeping threshold that determines when specific GDPR obligations are engaged. Most prominently, where processing is likely to result in a high risk to the rights and freedoms of natural persons, a Data Protection Impact Assessment is generally required under Article 35. Because the threshold controls whether these safeguards apply, misjudging it can leave an organisation without an assessment it was obliged to carry out, or conversely lead it to expend effort where the trigger is not met. Getting the calibration right is therefore central to accountability.
The standard is deliberately forward-looking: it asks controllers to assess a realistic possibility of harm before processing begins, rather than to wait for harm to materialise. This screening character means the threshold is exercised under uncertainty and depends on judgement about both the probability of an adverse event and the severity of its potential impact. Regulatory guidance offers illustrative examples of qualifying processing, the ICO, for instance, lists activities such as credit checks and mortgage or insurance applications among pre-contract processes that may be likely to result in high risk, but these lists are non-exhaustive and are set out in guidance rather than in the Regulation text itself.
Because the applicable criteria are drawn from guidance that continues to evolve, and because supervisory authorities in different member states may publish their own lists and interpretations, the practical position can vary. Organisations should treat any single list as a starting point for assessment rather than a definitive rulebook, and should verify the current criteria against the relevant supervisory authority's guidance, particularly where a term is being applied under national implementing law or the UK GDPR.
Who it's relevant to
Inside Likely to Result in a Risk
Common questions
Answers to the questions practitioners most commonly ask about Likely to Result in a Risk.