DPIA risk scoring is the step where a data protection impact assessment stops being a description and becomes a decision. Article 35(7) of the GDPR asks you to assess the risks to the rights and freedoms of individuals and to set out the measures you will take to address them, and scoring is how most teams turn that assessment into something consistent, comparable and defensible.
This guide explains how to design a scoring approach for a DPIA, how to rate likelihood and severity, how to treat residual risk and when a high score means you must consult your supervisory authority. It is general information, not legal advice.
Why DPIA risk scoring focuses on people, not the organization
The most important idea in DPIA risk scoring is whose risk you are scoring. A DPIA looks at risk to individuals: discrimination, financial loss, loss of confidentiality, identity theft, reputational harm, loss of control over data, physical or psychological harm. Business risk to your own organization, such as fines or reputational damage, is a separate matter, even though the two often move together.
Teams that score the organization’s exposure instead of the individual’s tend to under-rate harms that fall on people but cost the company little. Keep the individual at the centre of every rating. Our comparison of a DPIA and an LIA and of privacy risk assessment and DPIA shows how the scope differs.
Free DPIA template and tool
Does this processing need a DPIA, and what would it say?
Screen the processing against Article 35 and the nine WP248 criteria, describe it, test necessity and proportionality, rate the risks to the people concerned and record the DPO's advice and sign-off. Free, with findings and the Article 36 check.
Rating likelihood in DPIA risk scoring
Likelihood asks how probable it is that a harmful event happens. Use a small scale with plain definitions, for example remote, possible, probable and almost certain, and attach a rough meaning to each so that two assessors give similar ratings. Avoid false precision: a four-point scale is easier to defend than percentages nobody can support.
Base likelihood on evidence. Consider the nature of the data, the number of people, the threat sources, past incidents and the strength of existing controls. A dataset shared with many processors over the internet has a higher chance of exposure than a small internal database with tight access.
| Minimal severity | Significant severity | Serious severity | Severe severity | |
|---|---|---|---|---|
| Remote likelihood | Low | Low | Medium | Medium |
| Possible likelihood | Low | Medium | Medium | High |
| Probable likelihood | Medium | Medium | High | High |
| Almost certain | Medium | High | High | High |
Rating severity in DPIA risk scoring
Severity asks how bad the impact would be for the person if the event did happen. Again, use a short scale such as minimal, significant, serious and severe, with examples. A leaked newsletter list is minimal for most people. A leaked list of patients with a sensitive condition may be severe.
Severity depends on the individual and the context, not just the data type. Vulnerable people, such as children or those in unequal relationships with the controller, may suffer more from the same event. Our guides on DPIAs for children’s data and CCTV DPIAs show how context changes severity.
Combining the scores into a rating
Multiply or map likelihood and severity into an overall rating using a matrix like the one above. Keep the outputs to low, medium and high, and write down what each level triggers. For instance, low may be accepted, medium may need measures and owner sign-off, and high may require senior approval and possibly consultation.
A matrix is a communication tool, not a mathematical truth. If a risk feels worse than the matrix says, explain why and adjust with a written reason. If you lean on the numbers without judgement, you will miss combinations such as a rare but catastrophic event. Review the scale once a year and adjust it when your experience shows that ratings are too generous or too harsh.
Measures, residual risk and acceptance
After scoring the inherent risk, list the measures that reduce it: minimisation, pseudonymisation, encryption, access controls, shorter retention, better transparency and human review. Then re-score. The result is the residual risk, which is what the decision-maker actually accepts. See residual risk in a DPIA for a fuller treatment.
Measures must be real, assigned and dated. A measure marked “will encrypt in future” with no owner should not reduce the score. Only credit controls that exist or have a committed delivery date. The final sign-off should name a person with authority to accept the residual risk on behalf of the organization.
- Inherent risk: the score before any additional measures
- Measures: specific, owned and dated actions that reduce likelihood or severity
- Residual risk: the score after measures are in place
- Acceptance: a named approver, with the DPO’s advice recorded
When a high score means consultation
Article 36 requires prior consultation with the supervisory authority where the DPIA shows that processing would result in a high risk and you cannot mitigate it. So the practical question in DPIA risk scoring is whether the residual score stays high after all reasonable measures. If it does, you should not start the processing without consulting. Read DPIA prior consultation for the process and timing.
Document how you decided that the risk was or was not high after measures. That reasoning is what an authority will look at first. It is also why early scoring matters: finding a high residual risk late in a project is expensive.
Building a scoring sheet your team will actually use
A scoring approach only works if people use it the same way. Put the scales, definitions and matrix on a single page, and include two or three worked examples from your own organization so assessors can calibrate. Ask each assessor to score independently first, then compare and discuss differences. The disagreements are usually the most valuable part, because they expose different assumptions about the data or the controls.
Record the reasoning next to every score. A rating of “high” with a one-line explanation, such as “data shared with four processors and no retention limit”, is far more useful in a review than a number alone. If you need to explain the assessment to a regulator, the reasoning is what shows the process was genuine.
Scoring risks that affect groups and society
Some harms fall on groups rather than on individuals: discriminatory outcomes from profiling, chilling effects from surveillance, or loss of trust in a service. These are easy to miss if you score record by record. Ask explicitly whether the processing could disadvantage a particular group, and if so, rate the impact on that group as well as on the average person.
Where automated decisions or AI are involved, link the DPIA to your wider assessments, as described in DPIAs for AI systems. The same scoring logic applies, but the sources of harm, such as bias, opacity and model drift, need their own consideration.
Common mistakes to avoid
Common failures include scoring only the average person, giving every risk a medium rating to avoid debate, ignoring harm to groups, treating a control as effective without testing it and scoring once at the start and never again. Another is failing to record who took part. Involve the DPO, the business owner, security and, where suitable, representatives of the people affected, as described in consulting the DPO and data subjects.
Finally, keep the scoring proportionate. A simple internal tool needs a simple scoring sheet, not a twenty-page methodology. Match the depth to the risk.
A short worked example
A retailer plans a loyalty scheme that tracks purchases to personalise offers. Likelihood of over-collection is probable, since data is gathered at every till, and severity is significant because profiling could reveal sensitive habits. The inherent rating is medium to high. Measures include limiting fields, keeping purchase data for two years, offering an opt-out and excluding sensitive product categories from profiling.
With those measures the likelihood drops to possible and the severity to minimal for most customers, giving a low to medium residual rating. The DPO records that no consultation is needed, the business owner signs off and a review is set for twelve months. The whole scoring exercise took an afternoon and is easy to explain.
Using a ready structure for scoring
If you want scales, matrices and residual risk sections already laid out, the DPIA Report and Workbook provides a structured report with scoring built in, based on the ICO guidance on DPIAs and the regulation. Whichever tool you use, consistent DPIA risk scoring depends on clear scales, evidence-based ratings and honest treatment of what remains after measures.
DPIA risk scoring FAQ
Is scoring mandatory in a DPIA?
The GDPR requires an assessment of risk but does not prescribe a scoring method. Scoring is a common way to make the assessment consistent and easy to review.
Should we score likelihood and severity separately?
Yes. Rating them separately shows why a risk is high and which measures address it, for example reducing likelihood through security or reducing severity through minimisation.
Who approves the residual risk?
A named senior person accountable for the processing, after taking the DPO’s advice into account. The DPO advises but does not accept risk for the organization.
How often should we rescore?
Whenever the processing, the data or the risk landscape changes, and on a fixed schedule such as annually. Record each review.
What if we cannot reduce a high risk?
You must consult the supervisory authority before starting the processing, as set out in Article 36, or redesign the project so the risk falls.