GDPR does not define a specific threshold between risk levels — a risk analysis must be carried out. Assess the individual activities performed with personal data in relation to their potential likelihood of a breach. Possible examples of risks include:
personal data breach on the processor's side
leakage or compromise of access credentials
error in the source code
Determine how to prevent the risk, what the consequences of the risk materializing would be, and what measures are required in such a situation.
Data Protection Impact Assessment, or DPIA, is a tool that helps organizations identify the most effective way to bring their personal data protection practices into compliance with GDPR.
