Skip to main content

High and Low Risk of Personal Data Breach

How Do We Define the Differences Between High and Low Risk from a GDPR Perspective?

Written by Petr Pech

GDPR does not define a specific threshold between risk levels — a risk analysis must be carried out. Assess the individual activities performed with personal data in relation to their potential likelihood of a breach. Possible examples of risks include:

  • personal data breach on the processor's side

  • leakage or compromise of access credentials

  • error in the source code

Determine how to prevent the risk, what the consequences of the risk materializing would be, and what measures are required in such a situation.

Data Protection Impact Assessment, or DPIA, is a tool that helps organizations identify the most effective way to bring their personal data protection practices into compliance with GDPR.

Did this answer your question?