Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Privacy risk treatment options of reduce, avoid, share and accept with owners, dates and residual risk approval

Privacy Risk Treatment: Options and Plans for 2026

Privacy risk treatment is what happens after a risk has been identified and scored: deciding what to do about it, doing it and recording what remains. Many privacy programmes are good at finding risks and weak at treating them, so registers fill with high-rated items that never change. A treatment plan turns findings into action, with owners, dates and evidence.

This guide explains the four treatment options, how to choose between them, how to write an actionable plan, which privacy controls are most useful, how to handle risk acceptance and how to track progress. It is general guidance that draws on frameworks such as the NIST Privacy Framework and can be adapted to your organization.

What privacy risk treatment is

Risk treatment is the process of selecting and implementing measures to modify risk. In privacy, that means changing how data is collected, used, shared, stored or deleted so that the likelihood or the impact of harm to individuals falls to an acceptable level. It follows the assessment and scoring of the risk, and it feeds the register and reporting.

Free privacy risk assessment

Which privacy risks would hurt the people whose data you hold?

List your personal data and processing, pick from 38 privacy risk scenarios, rate them for the people concerned and for you, and plan treatment with ISO 27701 controls. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free privacy risk assessment →  or  View premium report sample

Frameworks such as ISO 31000 and the NIST Privacy Framework, available at the NIST Privacy Framework, both treat treatment as a core step, and the GDPR expects controllers to implement appropriate technical and organizational measures. Good privacy risk treatment is specific, owned and evidenced, not a list of good intentions.

Choose the privacy risk treatment option

For each risk above your threshold, choose an option. Reduce is the most common: add controls. Avoid is the strongest: stop the activity or redesign it so the risk disappears, for example by not collecting the data at all. Share moves part of the risk through contracts or insurance, but it does not remove responsibility for individuals’ data. Accept keeps the risk knowingly, within appetite.

Consider cost, benefit and feasibility, but do not let cost alone decide when risks to individuals are high. Use your privacy risk appetite to decide which risks can be accepted and who has authority to accept them. Avoidance is often cheaper before launch than after.

Prioritise privacy measures that remove risk at source

The most effective controls change what data exists. Collect less. Keep it for a shorter time. Restrict who can see it. Pseudonymise or anonymise where possible. Process on the device instead of centrally. Limit purposes, and block reuse. Because there is less data and fewer people with access, there is less to go wrong. These measures follow the privacy by design principle described in privacy by design.

Then add layers: encryption, access management, logging, secure development, vendor controls, transparency and rights processes, training and incident response. Choose measures that address the specific cause of each risk. A measure that does not link to a cause is decoration.

OptionWhat it meansPrivacy example
Reduce (mitigate)Add controls to cut likelihood or impactMinimise data, encrypt, shorten retention, add access controls
AvoidStop or redesign the activityDrop a feature that collects unnecessary sensitive data
Share (transfer)Move part of the risk to another partyProcessor contract, insurance for breach costs
Accept (retain)Knowingly keep the risk within appetiteLow residual risk approved by the owner
  • Data minimisation and shorter retention
  • Pseudonymisation or anonymisation
  • Access and purpose limitation
  • Clear notices, choices and rights handling

Write an actionable privacy risk treatment plan

A treatment plan lists, for each risk, the chosen option, the specific actions, the owner, the due date, the expected effect on the score and the evidence that will show completion. Use verbs that can be checked: “delete records older than 24 months by 30 June; owned by head of customer operations; evidence: deletion log”. Avoid “consider”, “review” and “improve”.

Group actions into phases if needed: immediate fixes, medium-term projects and longer-term improvements. Include dependencies and resources. Link the plan to the privacy risk register so each risk shows its plan and status.

Involve the right people

Treatment usually needs collaboration. Privacy specialists advise, but the business owner decides and delivers. IT and security implement technical controls, legal reviews contracts and notices, HR handles staff issues and procurement manages suppliers. Involve them early so the plan is realistic.

Consult affected individuals or their representatives where the risk is high or the effect on them is substantial. For high-risk processing, connect the plan to a DPIA and the DPO’s advice; see DPIA mitigation measures for how measures are chosen and evidenced.

Residual risk and risk acceptance

After treatment, re-score the risk to show what remains. Compare it with your appetite. If it is within appetite, the owner may accept it, recording the reasoning, the approver and a review date. If it is above appetite, either add more treatment or escalate for senior decision.

Acceptance must be explicit. Silence or delay is not acceptance. Give it an expiry, since circumstances change. For processing that remains high risk after all reasonable measures, the GDPR requires prior consultation with the supervisory authority; see DPIA prior consultation.

Track privacy risk treatment and verify effectiveness

Track actions in a register with status and due dates, and report overdue items to the governance forum. Verify that measures work: test the deletion job, check access logs, review the notice, sample the consent records. Evidence of effectiveness is what turns a plan into a control.

Re-assess the risk when actions complete. If the score has not fallen as expected, find out why. Perhaps the measure was implemented partly, or the risk had another cause. Close the risk formally only when evidence supports it.

Treat privacy risks in projects and vendors

Embed treatment in project and procurement processes. For new projects, run a privacy review early, as described in the privacy review process, and build treatments into requirements and testing. For vendors, treat risks through due diligence, contract terms and monitoring, and record any accepted residual risk.

Where personal data leaves your organization, consider whether you can rely on the supplier’s controls, and plan for what happens if they fail. See the third-party risk management framework for the broader approach.

Common mistakes in privacy risk treatment

Frequent errors include vague actions with no owner, treating awareness training as a universal fix, crediting controls that are not in place, accepting risks without authority or expiry, choosing measures unrelated to the cause, never verifying effectiveness and letting plans stall. Another is treating every risk the same regardless of severity, which starves the serious ones of attention.

Avoid these by linking measures to causes, assigning owners, requiring evidence, setting authority levels for acceptance and reporting on overdue items.

Balancing treatment with business value

Privacy measures have costs, and the business will ask whether they are proportionate. Present options with their effect on the risk score, their cost and their effect on the project. Often a design change achieves more than an expensive control, and sometimes a modest measure removes most of the risk. Be honest about what cannot be fixed and what the remaining exposure means for individuals, so that decision-makers understand the trade-off they are accepting.

Where the business need is strong and the risk cannot be reduced enough, consider a smaller pilot, a narrower audience or extra transparency and choice for people. Phased approaches let you learn from real use while limiting the harm if something goes wrong.

A short worked example

A company’s privacy risk assessment rates customer call recordings as high risk: recordings are kept indefinitely, widely accessible and sometimes contain payment details. The treatment plan reduces the risk: retention limited to 90 days with automatic deletion; access restricted to a quality team with logging; pause-and-resume tooling to avoid recording payment details; a revised notice.

Owners and dates are set, evidence is defined, and residual risk is re-scored as medium. The head of operations accepts it for twelve months. After deletion jobs run, the team verifies that old recordings are gone and closes the action.

Reporting and governance

Report treatment status to leaders regularly: number of risks by rating, treatments on track, overdue actions, accepted risks and upcoming expirations. Show the trend in residual risk. Highlight decisions needed and resource gaps. Include treatment progress in your governance calendar so it does not depend on individual initiative.

Review the treatment approach itself once a year. Which measures reduced risk most, which were slow, which risks recurred? Feed lessons into standards, templates and training. Over time, treatment gets faster because common risks have standard responses.

Structuring the assessment

If you want a report and workbook that link risks, scores, treatment options, owners and residual ratings in one place, the Privacy Risk Assessment Report and Workbook provides a structured layout for privacy risk assessment. Whatever tool you use, effective privacy risk treatment chooses the right option, assigns real owners and proves that measures work.

Privacy risk treatment FAQ

What are the options for treating privacy risk?

Reduce it with controls, avoid it by stopping or redesigning the activity, share part of it through contracts or insurance, or accept it knowingly within appetite.

Who can accept a privacy risk?

A named person with authority under your risk framework, usually a senior owner of the processing, with advice from the DPO or privacy lead. Accepted risks need an expiry date.

Does insurance treat privacy risk?

It transfers some financial consequences to an insurer, but it does not remove your obligations to individuals or reduce harm to them, so it complements rather than replaces controls.

How do we know a treatment worked?

Collect evidence such as logs, test results and records, and re-score the risk after implementation.

What if residual risk remains high?

Add measures, redesign, escalate for senior decision or, for high-risk processing under the GDPR, consult the supervisory authority before proceeding.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.