Measures to Address the Risks
Measures to address the risks are the actions an organization takes to reduce the likelihood or impact of things that could harm people or the organization. These can range from technical safeguards to organizational procedures, and in some cases an organization may decide to accept a risk rather than act on it. The right measures depend on the specific situation and the level of risk involved.
Measures to address the risks refers to the set of technical and organizational controls selected and implemented to reduce identified risks to an acceptable level, typically by decreasing the likelihood (frequency) and/or the severity (consequences) of adverse events. In risk management practice, addressing risk encompasses a range of responses, including mitigating, transferring, avoiding, or retaining (accepting) the risk. The appropriate measures are determined through a risk assessment and should be proportionate to the nature and level of risk; the concept is context-dependent and does not prescribe a fixed set of controls. Note: the evidence provided draws on general risk management and information security sources rather than the GDPR text itself, so any mapping of this term to specific GDPR obligations (for example, security of processing or data protection impact assessment requirements) should be verified against the current official Regulation text and applicable guidance.
Why it matters
Measures to address the risks are the operational heart of any risk management program: identifying a risk is only useful if an organization then decides how to respond to it. Without a deliberate set of measures, an organization may leave itself exposed to adverse events whose likelihood or severity could have been reduced. In a data protection context, these measures often take the form of technical and organizational safeguards, though the mapping of this general concept to specific GDPR obligations should be verified against the current official Regulation text and applicable guidance.
The importance of these measures lies in their proportionality. Because risk is context-dependent, there is no fixed checklist of controls that will be appropriate in every situation. A measure that is reasonable for a low-risk processing activity may be inadequate for a high-risk one, and vice versa. Organizations therefore need to tie their choice of measures to a risk assessment, so that the effort and cost invested is generally proportionate to the nature and level of the risk being managed.
It is also significant that addressing a risk does not always mean actively reducing it. Recognized risk management practice includes the option of retaining (accepting) a risk, alongside mitigating, transferring, or avoiding it. Treating every risk as something that must be eliminated can misallocate resources, while treating no risk as worth addressing can leave people and the organization unprotected. The value of this term is that it frames a structured range of choices rather than a single prescribed action.
Who it's relevant to
Inside Measures to Address the Risks
Common questions
Answers to the questions practitioners most commonly ask about Measures to Address the Risks.