Skip to main content
Category: Impact Assessments & Documentation

Measures to Address the Risks

Also known as: Risk Control Measures, Risk-Reducing Measures, Risk Treatment Measures
Simply put

Measures to address the risks are the actions an organization takes to reduce the likelihood or impact of things that could harm people or the organization. These can range from technical safeguards to organizational procedures, and in some cases an organization may decide to accept a risk rather than act on it. The right measures depend on the specific situation and the level of risk involved.

Formal definition

Measures to address the risks refers to the set of technical and organizational controls selected and implemented to reduce identified risks to an acceptable level, typically by decreasing the likelihood (frequency) and/or the severity (consequences) of adverse events. In risk management practice, addressing risk encompasses a range of responses, including mitigating, transferring, avoiding, or retaining (accepting) the risk. The appropriate measures are determined through a risk assessment and should be proportionate to the nature and level of risk; the concept is context-dependent and does not prescribe a fixed set of controls. Note: the evidence provided draws on general risk management and information security sources rather than the GDPR text itself, so any mapping of this term to specific GDPR obligations (for example, security of processing or data protection impact assessment requirements) should be verified against the current official Regulation text and applicable guidance.

Why it matters

Measures to address the risks are the operational heart of any risk management program: identifying a risk is only useful if an organization then decides how to respond to it. Without a deliberate set of measures, an organization may leave itself exposed to adverse events whose likelihood or severity could have been reduced. In a data protection context, these measures often take the form of technical and organizational safeguards, though the mapping of this general concept to specific GDPR obligations should be verified against the current official Regulation text and applicable guidance.

The importance of these measures lies in their proportionality. Because risk is context-dependent, there is no fixed checklist of controls that will be appropriate in every situation. A measure that is reasonable for a low-risk processing activity may be inadequate for a high-risk one, and vice versa. Organizations therefore need to tie their choice of measures to a risk assessment, so that the effort and cost invested is generally proportionate to the nature and level of the risk being managed.

It is also significant that addressing a risk does not always mean actively reducing it. Recognized risk management practice includes the option of retaining (accepting) a risk, alongside mitigating, transferring, or avoiding it. Treating every risk as something that must be eliminated can misallocate resources, while treating no risk as worth addressing can leave people and the organization unprotected. The value of this term is that it frames a structured range of choices rather than a single prescribed action.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those responsible for overseeing compliance rely on this concept to structure how their organization responds to identified risks, ensuring that chosen measures are proportionate to the level of risk. They should verify how the general risk management framing maps onto specific GDPR obligations by reference to the current official Regulation text and applicable guidance.
Risk and Security Practitioners
Professionals who select and implement controls use this concept to distinguish between technical safeguards and organizational procedures, and to weigh the different responses to risk, including mitigating, transferring, avoiding, or retaining it. Their focus is typically on reducing the likelihood or severity of adverse events to an acceptable level following a risk assessment.
Privacy Lawyers and Advisors
Legal advisors encounter this term when assessing whether an organization's response to risk is defensible and proportionate. They should be careful to separate general risk management terminology from precise legal obligations, and to confirm any specific requirements against the current official GDPR text rather than treating general sources as settled law.
Engineers and Product Teams
Those building and operating systems translate risk decisions into concrete technical safeguards. This concept helps them understand that the measures they implement should be driven by a risk assessment and calibrated to the level of risk, rather than applied as a fixed, one-size-fits-all set of controls.

Inside Measures to Address the Risks

Technical and Organisational Measures (TOMs)
The safeguards a controller or processor implements to mitigate identified risks to the rights and freedoms of data subjects. These typically include both technical controls (such as encryption, pseudonymisation, and access restrictions) and organisational controls (such as policies, training, and governance structures). The appropriate measures are determined by reference to the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, alongside the likelihood and severity of the risk.
Risk-Based Assessment
Measures are not fixed or prescriptive; they are selected following an assessment of the specific risks presented by a processing operation. Where a Data Protection Impact Assessment (DPIA) under Article 35 identifies high risks, the measures section documents how those risks will be addressed to reduce them to an acceptable level. The adequacy of measures is context-dependent and subject to ongoing evaluation.
Safeguards and Security Controls
Concrete controls intended to ensure a level of security appropriate to the risk, which may include measures for confidentiality, integrity, availability, and resilience of processing systems, as well as processes for restoring access to data and regularly testing effectiveness. The specific controls chosen should be justified against the assessed risk rather than applied uniformly.
Mechanisms to Demonstrate Compliance (Accountability)
Documentation and evidence showing that the selected measures address the identified risks, supporting the accountability principle. This generally includes recording the rationale for chosen measures, residual risk, and, where applicable, whether consultation with the supervisory authority is required because residual high risk cannot be mitigated.
Review and Monitoring
Measures are typically treated as living controls that must be monitored, tested, and updated as risks, technology, and processing activities change. This reflects that the effectiveness of a measure at one point in time does not guarantee continued adequacy.

Common questions

Answers to the questions practitioners most commonly ask about Measures to Address the Risks.

Does the GDPR require me to eliminate all identified risks before processing can proceed?
No. The framework is risk-based rather than risk-elimination based. Measures to address the risks are intended to mitigate risks to the rights and freedoms of individuals to an acceptable level, taking into account the nature, scope, context, and purposes of the processing and the likelihood and severity of the risk. It is generally accepted that residual risk may remain after measures are applied; the question is whether that residual risk is proportionate and justifiable, not whether it has been reduced to zero. Where a high residual risk cannot be sufficiently mitigated, prior consultation with the supervisory authority may be required, subject to assessment.
Are the measures to address risks simply the same thing as the security controls required elsewhere in the GDPR?
Not exactly. Technical and organisational security measures are one important category, but measures to address the risks are typically broader. They can include safeguards, security measures, and mechanisms aimed at protecting personal data and demonstrating compliance, such as data minimisation, pseudonymisation, transparency measures, retention limits, access governance, and steps that support the exercise of data subject rights. Treating the exercise as security-only risks overlooking measures directed at fairness, lawfulness, and the wider rights and freedoms of individuals.
How should measures be linked to the specific risks that have been identified?
In most cases each identified risk should be mapped to one or more corresponding measures, so that it is clear how a given measure reduces the likelihood or severity of that risk. Documenting this mapping helps demonstrate accountability and supports later review. It is generally advisable to record the residual risk that remains after each measure is applied, rather than listing measures in the abstract without connecting them to the risks they are meant to address.
Who should be involved in deciding on and approving the measures?
Responsibility for determining appropriate measures typically rests with the controller, informed by relevant stakeholders. Where a data protection officer has been designated, their advice is generally sought and their input recorded. Depending on the organisation, input from information security, engineering, legal, and business owners is often useful because measures span technical, organisational, and contractual domains. Where processors are involved, the allocation of measures should be reflected in the relevant contractual arrangements. The precise governance and sign-off route will vary by organisation.
How can the effectiveness of the measures be tested and maintained over time?
Measures are generally expected to be reviewed periodically and when there is a change in the risk presented by the processing. Effectiveness can be checked through methods such as testing, audits, monitoring, and revisiting the underlying risk assessment. Because processing operations, technologies, threats, and applicable guidance evolve, treating the measures as a one-off exercise is usually inadequate; ongoing review helps ensure that the measures remain appropriate to the current level of risk.
How should the chosen measures and the reasoning behind them be documented?
It is generally advisable to record the measures, the risks they address, and the rationale for concluding that the residual risk is acceptable, so that the organisation can demonstrate its decision-making if asked. This documentation often forms part of a broader assessment record. Clear, dated records that show who was involved and when the assessment was reviewed tend to support accountability. Organisations should align their documentation approach with any applicable regulator guidance and verify current expectations against the official text and supervisory authority publications.

Common misconceptions

Implementing a standard checklist of security measures makes processing fully compliant.
There is no universal set of measures that guarantees compliance. Appropriate measures are determined by assessing the specific risks of a given processing operation, and adequacy is context-dependent and subject to ongoing review. A generic checklist may leave certain risks unaddressed and does not, by itself, demonstrate that measures are appropriate to the risk.
Encryption or pseudonymisation alone is sufficient to address the risks.
Encryption and pseudonymisation are examples of measures that may reduce risk, but they are generally not sufficient on their own. Appropriate measures typically combine technical and organisational controls selected against the assessed risk, and their sufficiency must be evaluated case by case rather than assumed.
Once measures are chosen and documented, no further action is needed.
Measures are generally treated as ongoing controls requiring monitoring, testing, and updating as risks, technology, and processing change. Where a DPIA identifies residual high risk that cannot be adequately mitigated, prior consultation with the supervisory authority may be required.

Best practices

Tie each measure explicitly to a specific risk identified in the assessment or DPIA, rather than applying a uniform set of controls, and document the rationale for the measures selected.
Combine technical controls (such as encryption, pseudonymisation, and access restrictions) with organisational controls (such as policies, training, and governance) so that measures address the full range of assessed risks.
Assess appropriateness by reference to the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, together with the likelihood and severity of the risk.
Record residual risk after measures are applied, and where residual high risk cannot be adequately mitigated, evaluate whether prior consultation with the supervisory authority is required.
Establish a process to monitor, test, and periodically review the effectiveness of measures, updating them as risks, technology, or processing activities change.
Maintain documentation of the measures and the reasoning behind them to support the accountability principle and to demonstrate that the chosen measures address the identified risks.