Score privacy risk for a processing activity: data categories, volume, lawful basis, transfers, retention and re-identification.
Privacy risk is severity to individuals multiplied by exposure, not a compliance checklist score. Special-category and children's data carry the highest severity, and volume uplifts it because a breach affecting ten million people is categorically different from one affecting a hundred. The compliance gap covers the four failures regulators actually pursue: no documented basis, undocumented transfers, collecting more than needed, and being unable to honour subject rights. The cheapest privacy control is deletion: every field you do not collect and every month you do not retain removes risk permanently rather than mitigating it.
Privacy Risk
severity = dataCategory sensitivity plus a volume uplift; complianceGap = mean(lawful basis, transfers, minimisation, subject rights); risk = severity × mean(re-identification, complianceGap) ÷ 10, uplifted 15% for automated decisions with legal effect.
severity = dataCategory sensitivity plus a volume uplift; complianceGap = mean(lawful basis, transfers, minimisation, subject rights); risk = severity × mean(re-identification, complianceGap) ÷ 10, uplifted 15% for automated decisions with legal effect. Privacy risk is severity to individuals multiplied by exposure, not a compliance checklist score. Special-category and children's data carry the highest severity, and volume uplifts it because a breach affecting ten million people is categorically different from one affecting a hundred. The compliance gap covers the four failures regulators actually pursue: no documented basis, undocumented transfers, collecting more than needed, and being unable to honour subject rights.
The cheapest privacy control is deletion: every field you do not collect and every month you do not retain removes risk permanently rather than mitigating it.
This calculator takes 8 inputs: Most sensitive data category, Data subjects affected, Lawful basis and transparency, Cross-border transfers, Data minimisation, Re-identification risk of derived datasets, Automated decisions with legal effect, Ability to fulfil access and erasure requests. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No. If you or anyone else can re-link it to a person — and holding the key alongside the data means you can — it remains personal data. It genuinely reduces risk, which is why it lowers the score, but it does not remove the obligation.
In broad terms, for large-scale processing of special-category data, systematic monitoring of public areas, or automated decisions with legal or similarly significant effect. The flag here follows those thresholds, but confirm against your own regulator's published list.