Skip to content
Calcrivo

Privacy Risk Calculator

Score privacy risk for a processing activity: data categories, volume, lawful basis, transfers, retention and re-identification.

Inputs

people

Privacy Risk Band

Medium

Privacy Risk Score

5.18/ 10

Severity to Data Subjects

9.00/ 10

Compliance Gap

5.50/ 10

DPIA Required

Probably not mandatory — document the assessment that reached that conclusion

Highest-Value Control

Drop the surplus fields — the cheapest privacy control is not collecting the data

Step by step

  1. Values used

    Most sensitive data category = 8; Data subjects affected = 500,000 people; Lawful basis and transparency = Legitimate interest with assessment — 5; Cross-border transfers = Standard contractual clauses plus assessment — 6; Data minimisation = Some surplus fields retained — 6; Re-identification risk of derived datasets = Pseudonymised with keys alongside — 6; Automated decisions with legal effect = No; Ability to fulfil access and erasure requests = Manual but complete — 5

  2. Privacy Risk

    severity = dataCategory sensitivity plus a volume uplift; complianceGap = mean(lawful basis, transfers, minimisation, subject rights); risk = severity × mean(re-identification, complianceGap) ÷ 10, uplifted 15% for automated decisions with legal effect.

  3. Privacy Risk Band

    = Medium

  4. Privacy Risk Score

    = 5.18 / 10

  5. Severity to Data Subjects

    = 9.00 / 10

  6. Compliance Gap

    = 5.50 / 10

  7. DPIA Required

    = Probably not mandatory — document the assessment that reached that conclusion

  8. Highest-Value Control

    = Drop the surplus fields — the cheapest privacy control is not collecting the data

How it works

Privacy risk is severity to individuals multiplied by exposure, not a compliance checklist score. Special-category and children's data carry the highest severity, and volume uplifts it because a breach affecting ten million people is categorically different from one affecting a hundred. The compliance gap covers the four failures regulators actually pursue: no documented basis, undocumented transfers, collecting more than needed, and being unable to honour subject rights. The cheapest privacy control is deletion: every field you do not collect and every month you do not retain removes risk permanently rather than mitigating it.

Formula

Privacy Risk

severity = dataCategory sensitivity plus a volume uplift; complianceGap = mean(lawful basis, transfers, minimisation, subject rights); risk = severity × mean(re-identification, complianceGap) ÷ 10, uplifted 15% for automated decisions with legal effect.

severity
Harm to individuals if the processing goes wrong
complianceGap
Weakness in the legal and operational basis for processing
reidentification
How readily derived data can be linked back to a person

Frequently Asked Questions

How is Privacy Risk calculated?

severity = dataCategory sensitivity plus a volume uplift; complianceGap = mean(lawful basis, transfers, minimisation, subject rights); risk = severity × mean(re-identification, complianceGap) ÷ 10, uplifted 15% for automated decisions with legal effect. Privacy risk is severity to individuals multiplied by exposure, not a compliance checklist score. Special-category and children's data carry the highest severity, and volume uplifts it because a breach affecting ten million people is categorically different from one affecting a hundred. The compliance gap covers the four failures regulators actually pursue: no documented basis, undocumented transfers, collecting more than needed, and being unable to honour subject rights.

Why does Privacy Risk matter?

The cheapest privacy control is deletion: every field you do not collect and every month you do not retain removes risk permanently rather than mitigating it.

What values do I need to enter?

This calculator takes 8 inputs: Most sensitive data category, Data subjects affected, Lawful basis and transparency, Cross-border transfers, Data minimisation, Re-identification risk of derived datasets, Automated decisions with legal effect, Ability to fulfil access and erasure requests. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Is pseudonymisation enough to take data out of scope?

No. If you or anyone else can re-link it to a person — and holding the key alongside the data means you can — it remains personal data. It genuinely reduces risk, which is why it lowers the score, but it does not remove the obligation.

When is a DPIA mandatory?

In broad terms, for large-scale processing of special-category data, systematic monitoring of public areas, or automated decisions with legal or similarly significant effect. The flag here follows those thresholds, but confirm against your own regulator's published list.

You might also need