Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Privacy risk scoring matrix combining likelihood and impact of privacy harms to individuals into risk levels

Privacy Risk Scoring: A Practical 2026 Guide

Privacy risk scoring gives organizations a consistent way to compare very different privacy risks, from an over-broad marketing database to a leaky HR system, and to decide which ones to fix first. Done well, it centres on harm to individuals rather than only on legal exposure to the organization. Done badly, it produces a colourful matrix that nobody trusts.

This guide explains how to design privacy risk scoring: what to score, how to rate likelihood and impact, how to combine them, how to treat controls and residual risk, and how to use the results. It is general guidance that draws on frameworks such as the NIST Privacy Framework and can be adapted to your organization.

What privacy risk scoring is for

A privacy risk register can hold dozens or hundreds of entries. Scoring lets you sort them, compare them and decide where effort will reduce the most harm. It supports decisions on launch, controls, budgets and risk acceptance, and gives leaders a shared language for privacy.

Free privacy risk assessment

Which privacy risks would hurt the people whose data you hold?

List your personal data and processing, pick from 38 privacy risk scenarios, rate them for the people concerned and for you, and plan treatment with ISO 27701 controls. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free privacy risk assessment →  or  View premium report sample

The NIST Privacy Framework, described at the NIST Privacy Framework, frames privacy risk in terms of problems individuals can experience as a result of data processing, and asks organizations to consider both the likelihood and the impact of those problems. That approach is consistent with the GDPR’s focus on risks to the rights and freedoms of individuals.

Score risks to people first

The core question is what could happen to individuals. Harms include loss of confidentiality, discrimination, financial loss, identity theft, reputational damage, embarrassment, loss of autonomy, surveillance effects and physical or psychological harm. Organizational consequences, such as fines, litigation and reputational damage, matter too, but they are a separate dimension that should be scored separately or added deliberately.

Mixing the two without saying so hides trade-offs. For instance, a risk that would cause severe harm to a few individuals but little legal exposure could rank low if you only score organizational impact. See privacy risk vs cybersecurity risk for why the perspectives differ.

Rate likelihood in privacy risk scoring

Likelihood in privacy is often about how probable it is that a problematic data action will occur and cause a problem for people. Define levels such as unlikely, possible, likely and almost certain, with descriptions and evidence prompts. Consider the nature of the data and processing, the number of people, access by staff and suppliers, technical safeguards, past incidents and the strength of governance.

Some privacy problems are not events but ongoing conditions. If data is being collected without a valid notice, the likelihood of the problem is not “possible”; it is happening. Rate such cases accordingly. Use evidence from assessments and audits to support ratings, and record the reasons.

Minimal impactModerate impactMajor impactSevere impact
UnlikelyLowLowMediumMedium
PossibleLowMediumMediumHigh
LikelyMediumMediumHighHigh
Almost certainMediumHighHighCritical

Rate impact in privacy risk scoring

Impact asks how serious the effect would be on the person. Define levels such as minimal, moderate, major and severe, with examples across harm types. Include factors that raise impact: sensitive data, vulnerable individuals, irreversibility, large scale, and difficulty of redress.

Provide domain examples. Exposure of a newsletter list is minimal for most people. Exposure of health records or precise location data for people at risk may be severe. Test the scale on real cases with the privacy team and the business, and refine any wording that causes confusion.

  • Sensitivity of data and context
  • Vulnerability of the individuals affected
  • Irreversibility and duration of harm
  • Number of people affected

Combine into a rating and define what it triggers

Use a matrix like the one above to combine likelihood and impact into low, medium, high or critical. Write what each level means for decisions: low may be accepted by the process owner, medium needs a documented treatment, high needs senior approval and a dated plan, and critical means the processing should not proceed or must be paused.

Align scales and labels with your enterprise risk framework so privacy risks can appear on the wider register. See the privacy risk register for how to record them, and privacy risk appetite for setting thresholds.

Inherent, current and residual risk

Score risk before additional controls, to show exposure, and again after existing and planned controls, to show what remains. Only credit controls that are in place and evidenced. Typical privacy controls include minimisation, retention limits, access controls, encryption, transparency, consent mechanisms, contracts with processors and staff training.

Record the residual score with the reasoning and the approver. Where a DPIA is required, keep the scoring consistent with it; see DPIA risk scoring and privacy risk assessment vs DPIA. A residual high score for a high-risk processing activity may trigger prior consultation with a supervisory authority.

Calibrate and review privacy risk scoring

Different assessors score differently, so run calibration sessions with sample cases and agree interpretations. Use a second reviewer for high and critical ratings. Track how scores compare with real incidents, complaints and audit findings, and adjust the scales when they are consistently too generous or too harsh.

Re-score when the processing, data, suppliers or context change, and on a schedule. Make review triggers part of your privacy review process, so scores stay current instead of freezing at the date of the first assessment.

Use the scores in decisions and reporting

Use scores to prioritise treatments, set budgets and decide on launches and vendor approvals. Report the distribution of scores, the highest risks, overdue actions and trends to leaders. A simple heat map with commentary is usually enough. Highlight decisions needed, such as risks above appetite that require approval.

Avoid presenting scores as precise measurements. They are structured judgements, and the discussion they prompt is often as valuable as the number. Explain the method briefly in each report so readers understand what the scores mean.

Common mistakes in privacy risk scoring

Frequent errors include scoring only organizational exposure, vague scale definitions, treating ongoing non-compliance as a future possibility, crediting planned controls, using very complex formulas, assigning everything medium to avoid debate, never recalibrating and failing to link scores to action. Another is scoring in isolation from the business, so ratings do not reflect how data is really used.

Avoid these with clear definitions, evidence-based ratings, simple mechanics and a firm link between rating and decision.

Scoring special cases: children, employees and AI

Some contexts need extra care. Children and other vulnerable people are less able to understand or protect themselves, so raise impact accordingly. Employees have limited choice, so monitoring and profiling risks deserve higher ratings. AI and profiling add opacity and scale, so consider the potential for unfair outcomes. Record these factors in the scoring guide so every assessor applies them the same way, and ask the DPO to review ratings in these areas.

Linking scoring to your record of processing

Each scored risk should point to the processing activity it relates to, so the score and the record stay consistent. When a review changes an activity in the record, such as a new recipient or a longer retention period, re-check the linked risk. See a ROPA example for how activities are described, and use the same names in both documents so that anyone can move from one to the other without guessing which activity is meant.

A short worked example

A company plans to add location tracking to its delivery app to improve route planning. The risk of location data being retained indefinitely and used for staff performance monitoring is scored. Likelihood is likely, since no retention limit exists. Impact is major, because location traces reveal home addresses and routines. The inherent rating is high.

Controls include limiting collection to working hours, deleting traces after thirty days, restricting access and telling staff how the data is used. Residual likelihood becomes unlikely and impact moderate, giving a low to medium rating. The owner accepts the residual risk, and the record is reviewed in twelve months.

Documenting the method for audit

Write a short scoring guide that sets out the harm types, scales, matrix, thresholds and calibration approach. Approve it through your governance process, version it and train assessors. When a regulator, auditor or customer asks how you rate privacy risk, you can show a consistent method and the results.

Keep the individual scoring records with the reasons, evidence and approver. That record shows how decisions were made, supports learning from incidents and helps new team members apply the method consistently.

Structuring the assessment

If you want a report and workbook that carry data flows, risks, scores, controls and treatments in one place, the Privacy Risk Assessment Report and Workbook provides a structured layout for privacy risk assessment. Whatever tool you use, sound privacy risk scoring focuses on harm to people, is applied consistently and leads to decisions.

Privacy risk scoring FAQ

What should privacy risk scoring measure?

Primarily the likelihood and impact of harm to individuals from data processing, with organizational consequences considered separately or deliberately added.

Can we use the same scale as our enterprise risk framework?

Yes, aligning scales lets privacy risks be combined with other risks. Add privacy-specific guidance for harms and data sensitivity.

How do we score risks that are already occurring?

Rate likelihood as certain or likely, because the problem is not a future possibility. Prioritise treatment accordingly.

Who approves residual privacy risk?

A named senior person accountable for the processing, with advice from the DPO or privacy lead.

How often should scores be reviewed?

At least annually and whenever the processing, data, suppliers or context change, or after incidents.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.