Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

DPIA residual risk rating after mitigation measures

DPIA Residual Risk: Rating Risk After Controls 2026

DPIA residual risk is the level of risk to individuals that remains after you have applied every measure you plan to use. It is the number that decides whether a processing operation can go ahead, needs redesign or must be referred to the regulator. Many impact assessments describe risks and list controls but never state what is left, which leaves the most important question unanswered.

This guide explains how to assess DPIA residual risk: how it differs from the starting risk, how to rate it consistently, who should accept it and what to do when it stays high.

Where DPIA residual risk fits in Article 35

Article 35(7) of the GDPR sets the minimum content of a data protection impact assessment. It must include a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to the rights and freedoms of individuals, and the measures envisaged to address those risks, including safeguards and security measures. The article does not use the words residual risk, but you cannot show that measures address the risks without stating what risk remains. Article 36(1) then requires consultation with the supervisory authority where the assessment indicates that the processing would result in a high risk in the absence of measures taken to mitigate it. Our guide to DPIA prior consultation covers that route.

Before any of this begins, confirm that an assessment is needed at all; our guide on when a DPIA is required lists the triggers, and the wider overview of the DPIA process shows how the risk stage connects to the rest. Doing the residual rating well depends on a sound description of the processing, so do not rush the early sections to reach the risk table.

Inherent risk versus DPIA residual risk

Inherent risk is the risk before you apply controls; DPIA residual risk is the risk after. Keeping the two separate lets a reader see what each measure achieves and prevents the common trap of rating risk only after imagined controls that are not yet in place.

StageQuestionRecord
Inherent riskHow likely and how severe is harm to individuals if we did nothing extra?Likelihood, severity, overall rating
MeasuresWhat will we do to reduce likelihood or severity?Measure, owner, date, effect
Residual riskWhat harm remains once measures are working?New likelihood, severity, overall rating
DecisionIs what remains acceptable?Approver, date, reasons, conditions

The risk that matters is risk to individuals, not to the organisation. That is a key difference from a business risk assessment, explained in our comparison of privacy risk assessment and DPIA.

Free DPIA template and tool

Does this processing need a DPIA, and what would it say?

Screen the processing against Article 35 and the nine WP248 criteria, describe it, test necessity and proportionality, rate the risks to the people concerned and record the DPO's advice and sign-off. Free, with findings and the Article 36 check.

Start the free DPIA →  or  View premium report sample

How to rate DPIA residual risk

The Information Commissioner’s Office guidance on data protection impact assessments describes risk as a combination of the likelihood of harm and the severity of that harm. The same logic applies across the EU. Use a written scale so that two assessors reach a similar rating.

Likelihood

Consider how probable it is that the harm occurs given the controls. A control that is designed but not yet deployed does not lower likelihood; a control that is deployed but not tested deserves cautious credit. Base your rating on evidence such as past incidents, testing results and the strength of technical protections.

Severity

Severity looks at how bad the harm would be for the people affected: financial loss, discrimination, distress, loss of control over data, physical risk or damage to reputation. Severity often does not change after mitigation unless you reduce the data, remove the sensitive element or make an effect reversible. A control that only lowers likelihood leaves severity where it was, and your record should say so.

Combine and state the result

Combine likelihood and severity using a simple matrix, and record the reasoning in a sentence rather than only a colour. Keep the scale to three or four levels. Adding more precision than your evidence supports gives false confidence and invites argument over minor differences.

Measures that lower risk after mitigation

Measures fall into groups. Some reduce the data: collect less, keep it for a shorter time, aggregate or anonymise. Some reduce access: encryption, role-based access, pseudonymisation and segregation. Some improve transparency and control: clearer notices, easy opt-outs and simple ways to exercise rights. Some add oversight: human review of automated decisions, audit logging and training. Each measure should say which risk it addresses and whether it lowers likelihood, severity or both, and should name an owner and a date.

Be careful with measures that describe intentions, such as “staff will be trained”. If a measure is not in place when the residual risk is rated, mark the rating as conditional on delivery and track the action until it closes. Our DPIA example shows measures and ratings recorded in a full assessment.

Who accepts the remaining risk

The person with authority to accept the risk for the organisation should sign it off, and this is usually a senior manager who owns the processing, not the privacy team. The data protection officer, where you have one, must be asked for advice on the DPIA under Article 35(2), and you should record that advice and, where you depart from it, the reasons. The DPO advises and does not accept the risk on behalf of the controller.

Acceptance should carry conditions and an expiry. For example, acceptance may hold only while volumes stay below a stated level or until the next review. Without an end point, acceptance quietly becomes permanent.

When DPIA residual risk is still high

If after all reasonable measures the residual risk remains high, you have three options. Redesign the processing to lower the risk further, drop the part of the processing that causes it, or consult the supervisory authority before starting. Under Article 36, the regulator may give written advice and, if it considers the processing would breach the GDPR, can use its powers. Do not start the processing while awaiting the consultation outcome.

Make sure you can explain why a further measure was not possible, because regulators expect you to show that you explored options before consulting. A record that jumps from a high inherent rating straight to consultation, with no attempt at mitigation, will look like an incomplete assessment.

A hypothetical example of DPIA residual risk

The following is a hypothetical example invented for illustration. A company plans an employee wellbeing app that analyses free-text messages to flag possible stress. The inherent risk is high: sensitive inferences about staff, an imbalance of power between employer and employee, and possible use in performance decisions.

The measures include keeping analysis on the device, sharing only anonymous team-level trends with managers, making participation optional with no consequence for declining, and banning use of results in employment decisions through a written rule audited quarterly. After measures, likelihood falls from likely to unlikely, and severity falls from major to moderate, because individual results are no longer visible to the employer. The residual rating is medium, accepted by the HR director with the DPO’s advice recorded, on the condition that the audit runs and that no individual-level reports are ever produced.

Common mistakes with DPIA residual risk

Typical weaknesses include rating only once, giving credit for planned controls, treating security controls as if they reduced severity, letting the project lead accept the risk alone, omitting the DPO’s advice, recording no conditions or expiry, and never revisiting the rating after go-live. Another is using the same ratings for every assessment without reference to the actual processing, which makes the analysis look mechanical.

Reviewing DPIA residual risk after launch

Article 35(11) says the controller must review whether processing is performed in accordance with the assessment, at least when the risk represented by the processing changes. Set triggers such as new data, new recipients, a new technology, a breach, complaints and changes in law. When a trigger fires, re-rate the risk and record the outcome. A steady stream of small reviews is more useful than one large refresh that happens when someone remembers.

A structured report for DPIA residual risk

A consistent report helps each assessment show inherent risk, measures and residual risk in the same way. The DPIA Report and Workbook provides a report and workbook for describing processing, assessing necessity and risk, recording measures and documenting sign-off. Whichever tool you use, keep the same fields for every DPIA so decisions are comparable and reviewable.

DPIA residual risk FAQ

Is residual risk a legal term in the GDPR?

The words do not appear in Article 35, but the article requires measures to address the risks, and Article 36 turns on whether high risk remains without mitigation. In practice you must state what remains.

Can we start processing if residual risk is high?

Not without consulting the supervisory authority first. Where residual risk cannot be reduced, redesign the processing or consult before starting.

Who signs off DPIA residual risk?

A senior person who owns the processing and can accept the risk on behalf of the organisation. The DPO advises but does not accept the risk.

Do security measures reduce severity?

Usually they reduce likelihood. Severity falls only if the harm itself changes, for example by removing sensitive data or making an outcome reversible.

How often should we re-rate the risk?

Whenever the risk changes, such as a new use, recipient or technology, and at a fixed review interval you define in the assessment.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.