Privacy Risk Calculator
Score privacy risk for a processing activity: data categories, volume, lawful basis, transfers, retention and re-identification.
Inputs
Privacy Risk Band
Medium
Privacy Risk Score
5.18/ 10
Severity to Data Subjects
9.00/ 10
Compliance Gap
5.50/ 10
DPIA Required
Probably not mandatory — document the assessment that reached that conclusion
Highest-Value Control
Drop the surplus fields — the cheapest privacy control is not collecting the data
Step by step
Values used
Most sensitive data category = 8; Data subjects affected = 500,000 people; Lawful basis and transparency = Legitimate interest with assessment — 5; Cross-border transfers = Standard contractual clauses plus assessment — 6; Data minimisation = Some surplus fields retained — 6; Re-identification risk of derived datasets = Pseudonymised with keys alongside — 6; Automated decisions with legal effect = No; Ability to fulfil access and erasure requests = Manual but complete — 5
Privacy Risk
severity = dataCategory sensitivity plus a volume uplift; complianceGap = mean(lawful basis, transfers, minimisation, subject rights); risk = severity × mean(re-identification, complianceGap) ÷ 10, uplifted 15% for automated decisions with legal effect.
Privacy Risk Band
= Medium
Privacy Risk Score
= 5.18 / 10
Severity to Data Subjects
= 9.00 / 10
Compliance Gap
= 5.50 / 10
DPIA Required
= Probably not mandatory — document the assessment that reached that conclusion
Highest-Value Control
= Drop the surplus fields — the cheapest privacy control is not collecting the data
How it works
Privacy risk is severity to individuals multiplied by exposure, not a compliance checklist score. Special-category and children's data carry the highest severity, and volume uplifts it because a breach affecting ten million people is categorically different from one affecting a hundred. The compliance gap covers the four failures regulators actually pursue: no documented basis, undocumented transfers, collecting more than needed, and being unable to honour subject rights. The cheapest privacy control is deletion: every field you do not collect and every month you do not retain removes risk permanently rather than mitigating it.
Formula
Privacy Risk
severity = dataCategory sensitivity plus a volume uplift; complianceGap = mean(lawful basis, transfers, minimisation, subject rights); risk = severity × mean(re-identification, complianceGap) ÷ 10, uplifted 15% for automated decisions with legal effect.
- severity
- Harm to individuals if the processing goes wrong
- complianceGap
- Weakness in the legal and operational basis for processing
- reidentification
- How readily derived data can be linked back to a person
Frequently Asked Questions
How is Privacy Risk calculated?
severity = dataCategory sensitivity plus a volume uplift; complianceGap = mean(lawful basis, transfers, minimisation, subject rights); risk = severity × mean(re-identification, complianceGap) ÷ 10, uplifted 15% for automated decisions with legal effect. Privacy risk is severity to individuals multiplied by exposure, not a compliance checklist score. Special-category and children's data carry the highest severity, and volume uplifts it because a breach affecting ten million people is categorically different from one affecting a hundred. The compliance gap covers the four failures regulators actually pursue: no documented basis, undocumented transfers, collecting more than needed, and being unable to honour subject rights.
Why does Privacy Risk matter?
The cheapest privacy control is deletion: every field you do not collect and every month you do not retain removes risk permanently rather than mitigating it.
What values do I need to enter?
This calculator takes 8 inputs: Most sensitive data category, Data subjects affected, Lawful basis and transparency, Cross-border transfers, Data minimisation, Re-identification risk of derived datasets, Automated decisions with legal effect, Ability to fulfil access and erasure requests. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is pseudonymisation enough to take data out of scope?
No. If you or anyone else can re-link it to a person — and holding the key alongside the data means you can — it remains personal data. It genuinely reduces risk, which is why it lowers the score, but it does not remove the obligation.
When is a DPIA mandatory?
In broad terms, for large-scale processing of special-category data, systematic monitoring of public areas, or automated decisions with legal or similarly significant effect. The flag here follows those thresholds, but confirm against your own regulator's published list.
You might also need
- Synthetic Identity Risk CalculatorCommonly used together
- PII Exposure CalculatorCommonly used together
- Data Classification CalculatorCommonly used together
- Data Retention Compliance CalculatorCommonly used together
- LLM Prompt Injection Risk CalculatorAlso in Forensics & Emerging Threats
- Ransomware Impact CalculatorAlso in Forensics & Emerging Threats