Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Privacy harms taxonomy grouping harms into physical, economic, psychological, reputational and autonomy categories

Privacy Harms Taxonomy: A Practical 2026 Guide

A privacy harms taxonomy is a structured list of the ways that handling personal data can hurt people. Privacy assessments often start with legal checklists, such as whether a notice exists or a lawful basis is recorded, and end up missing what actually matters to individuals: being denied a job, followed, embarrassed, defrauded or treated unfairly. A taxonomy gives assessors a shared vocabulary for those harms, so nothing important is overlooked and ratings are comparable.

This guide explains what a privacy harms taxonomy contains, how to build or adapt one, how to link harms to data actions and controls, how to use it in workshops and scoring and how to keep it useful. It is general guidance that draws on public catalogues and can be tailored to your organization.

What a privacy harms taxonomy is

A privacy harms taxonomy is a classification of the negative effects that personal data processing can have on individuals and groups. It sits alongside a risk taxonomy for the organization, but looks in the other direction: not what could hurt the company, but what could hurt the person whose data is involved.

Frameworks such as the NIST Privacy Framework use the idea of problematic data actions and the problems people can experience as a result. The related NIST catalog, at the NIST catalog of problematic data actions and problems, lists actions such as excessive collection, unanticipated revelation and re-identification, with resulting problems like embarrassment, discrimination, loss of trust and economic loss. A privacy harms taxonomy builds on this thinking.

Why it improves privacy assessments

Without a taxonomy, assessments tend to be checklists of compliance controls. They can show that a notice exists yet miss the fact that a feature could reveal someone’s health condition to their family. A harms list prompts assessors to imagine consequences for real people, especially those with less power or more to lose.

It also improves consistency and scoring. If everyone uses the same categories and examples, ratings of impact are easier to compare, and reports show patterns, such as many risks that involve unfair treatment or loss of control. See privacy risk scoring for how harms feed into scores.

Common categories of privacy harm

Most taxonomies include several broad categories. Economic harms cover financial loss, fraud and lost opportunity. Physical harms cover risks to safety, such as stalking or violence enabled by disclosure of location. Psychological harms include distress, embarrassment and anxiety. Reputational harms damage standing. Harms to autonomy and fairness include loss of control over information, manipulation, discrimination and chilling effects on behaviour.

Some frameworks add societal harms, such as erosion of trust and democratic participation, and relationship harms, such as loss of confidentiality in intimate or professional contexts. Choose categories that fit your business and the people you serve.

Harm categoryExamplesTypical data actions that cause it
EconomicFraud, identity theft, loss of income or opportunityBreach, over-sharing, inaccurate data
PhysicalStalking, violence, unsafe treatmentLocation disclosure, surveillance, leaks of addresses
PsychologicalDistress, embarrassment, anxietyExposure of sensitive facts, unwanted profiling
ReputationalDamage to standing or relationshipsDisclosure, misattribution, unfair inferences
Autonomy and fairnessLoss of control, discrimination, chilling effectsOpaque profiling, coercive consent, unfair automated decisions
  • Economic: fraud, identity theft, loss of opportunity
  • Physical: stalking, violence, unsafe treatment
  • Psychological and reputational: distress, embarrassment, damage to standing
  • Autonomy and fairness: loss of control, discrimination, manipulation

A useful taxonomy connects harms to the data actions that cause them. Data actions include excessive collection, indefinite retention, secondary use, unauthorised access, disclosure, aggregation, inference, re-identification, inaccurate processing, opaque automated decisions and denial of rights. For each action, list typical harms.

That mapping tells assessors where to look. If a project involves aggregation of data from many sources, ask about re-identification and unwanted profiling. If it involves location data, ask about stalking and safety. Use the mapping in workshops, alongside your privacy risk assessment methodology.

Free privacy risk assessment

Which privacy risks would hurt the people whose data you hold?

List your personal data and processing, pick from 38 privacy risk scenarios, rate them for the people concerned and for you, and plan treatment with ISO 27701 controls. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free privacy risk assessment →  or  View premium report sample

Adapt the privacy harms taxonomy to your context

A generic list is a starting point. Tailor it to your sector and users. A health provider will emphasise harms from disclosure of conditions and treatment errors. A school will emphasise child safety. An employer will emphasise unfair monitoring and discrimination. A financial firm will emphasise fraud and exclusion.

Involve people who understand your users, such as customer service, HR, community representatives and specialists. Add examples drawn from your own incidents and complaints. Keep the list short enough to use, and review it annually.

Use the privacy harms taxonomy in assessments and workshops

In each assessment, walk through the categories for the processing activity: which harms are plausible, for whom, and how severe? Record the results against specific data actions, rather than generic statements. For high-risk processing, use the results in the DPIA; see DPIA risk scoring.

In workshops, use the categories as prompts, together with real scenarios. Ask the group to think about the most vulnerable person affected and to describe what would go wrong for them. That perspective often exposes risks that compliance-focused discussions miss.

Connect harms to controls

For each harm, identify the controls that prevent, reduce or repair it: minimisation, access controls, encryption, purpose limitation, transparency, rights processes, redress and incident response. Record the mapping so that each control has a reason and each harm has an answer.

This also helps to test whether your control set is complete. If a harm category has no controls, either the risk is out of scope or there is a gap. Use the mapping in the privacy risk register to keep risks, harms and controls aligned, and in privacy risk treatment planning.

Consider groups and society

Some harms fall on groups, not just individuals: discriminatory outcomes for a community, chilling effects across a population under surveillance or the erosion of trust in a service. Add group and societal harms to your taxonomy and consider them in assessments, especially for large-scale profiling and AI.

Where automated decisions are involved, compare with approaches used for AI systems, such as the AI harm taxonomy. The two lists overlap, and using consistent terms across privacy and AI assessments saves time.

Common mistakes with a privacy harms taxonomy

Frequent errors include using the list as a checkbox with no discussion, listing harms so generic they do not help, ignoring psychological and autonomy harms because they are hard to quantify, forgetting group harms, not linking harms to data actions and never updating the list. Another is copying a taxonomy without adapting it to your users.

Avoid these by tying harms to real scenarios, involving people close to users and refreshing the list after incidents and complaints.

Involving affected people

The best source of insight into harm is the people who experience it. Where possible, talk to customers, employees, patients or community groups about what worries them, and add their concerns to the taxonomy. Complaints, support tickets and social media comments are also rich sources. If a type of concern keeps appearing, such as fear of being tracked or embarrassment about disclosure, make sure the taxonomy and your assessments address it explicitly.

Record how input from people shaped the assessment. It demonstrates that the analysis rests on real experience and helps you explain your reasoning to regulators and customers.

A short worked example

A fitness app plans to add a social feature that shows nearby users on a map. Using the taxonomy, the assessment considers physical harm from stalking, psychological harm from unwanted contact and reputational harm from exposure of habits. The data actions are location disclosure and aggregation over time.

The team changes the design: locations are shown at a coarse level, sharing is off by default, users can block others and location history is deleted after seven days. Residual harm is rated low to medium and accepted. The taxonomy prompted a design change that a compliance checklist would probably have missed.

Keeping the privacy harms taxonomy current

Review the taxonomy annually and after significant incidents, regulatory developments and new technologies. New harms emerge, such as those from generative AI, biometric analysis or connected devices. Note the changes and communicate them to assessors.

Track which harms appear most often in your assessments. If one category dominates, it may reflect a real weakness in your practices, or a bias in how assessors think. Either way, the pattern is useful information for leaders.

Structuring the assessment

If you want a report and workbook that connect processing activities, harms, controls and residual ratings, the Privacy Risk Assessment Report and Workbook provides a structured layout for privacy risk assessment. Whatever tool you use, a well-used privacy harms taxonomy keeps assessments focused on people, not just on paperwork.

Privacy harms taxonomy FAQ

What is a privacy harms taxonomy?

A structured list of the ways that processing personal data can harm individuals or groups, used to prompt and organise privacy risk assessments.

How is it different from a list of legal requirements?

Legal requirements describe what you must do. A harms taxonomy describes what can go wrong for people, which helps you see risks that a compliance checklist may miss.

Do we need to build our own?

Not from scratch. Start with a public catalogue and tailor it to your sector, users and incidents.

How does it help scoring?

It gives assessors shared categories and examples for impact, which makes ratings more consistent and reports easier to compare.

How often should we update it?

At least annually and after major incidents, new technologies or regulatory developments.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.