A privacy risk assessment asks a different question from a security one. Not only “what could happen to the data?” but “what would that do to the people it is about?” ISO/IEC 27701 builds a privacy information management system on exactly that: criteria set in advance, an owner for every privacy risk, a rating you can explain, and a treatment decision for everything you are not prepared to accept. GDPR expects the same risk-based thinking in Articles 24, 25 and 32.
This tool takes you through it in that order. List the personal data you hold and what you do with it, pick risks from a library of 38 privacy scenarios, each mapped to the ISO/IEC 27701:2025 Annex A controls that usually treat it, rate them against your own scales and decide what to do about each one. It is free, and your answers save as you go.
Premium report
See what the premium privacy risk assessment report looks like
A worked sample for a fictional organization: the ranked register of privacy risks, heat maps before and after treatment, the treatment plan with ISO 27701 Annex A references, every finding with the document that closes it, an AI-assisted analysis with a 30/60/90-day roadmap, plus the live Excel workbook with a Statement of Applicability starter.
Other free risk assessments: Information Security Risk Assessment (ISO 27001) Business Continuity Risk Assessment (ISO 22301) Enterprise Risk Assessment (ISO 31000) AI Risk Assessment (ISO 42001) Data Protection Impact Assessment (GDPR) Transfer Impact Assessment (GDPR) AI System Impact Assessment (ISO 42005) Legitimate Interests Assessment (GDPR) Third-Party Risk Assessment (ISO 27001)
What this tool covers
- Scope and criteria. Your likelihood and impact scales, with impact described for the people concerned as well as for the organization, and the appetite line.
- What is in scope. Categories of personal data, processing activities, the systems they run on, processors and recipients, the people with access and where the data is held. Rate how much confidentiality, integrity and availability matter for each.
- Risks. Scenarios from the library, from processing without a lawful basis and invalid consent to late access requests, processors without a contract, transfers abroad and breaches reported too late, or your own.
- Analysis. Likelihood and impact for each risk, with the controls already in place and the reason for the rating.
- Treatment. Modify, avoid, share or retain, the ISO 27701 controls the treatment relies on, an owner, a date, a target level and the risk owner’s acceptance.
What you get, free
Your heat map against your own appetite line, the highest risks in priority order, a process score out of 100 that shows how complete and defensible the assessment is, and the findings an auditor would raise, such as a risk above the line with no decision or a processor with no agreement. Sign in and it stays in your account, ready for next year’s review.
The full report adds the complete register, heat maps before and after treatment, the treatment plan by owner and due date, an AI-assisted analysis with a 30/60/90-day roadmap, and an ISO 27701 Statement of Applicability starter, with the register as a live Excel workbook.
Where this fits
The controls you choose here feed your ISO 27701 Statement of Applicability, and the risks you rate high point to where a data protection impact assessment is needed for a specific processing operation. When one is, run it with our free DPIA template. To see how far your privacy programme is from the standard, run the ISO 27701 gap assessment or the GDPR gap assessment; for the approach in general, read about privacy by design.
For a side-by-side comparison of the two assessments, read privacy risk assessment vs DPIA.
Frequently asked questions
Is this the same as a DPIA?
No. A DPIA looks at one high-risk processing operation in depth before it starts. A privacy risk assessment looks across all of your processing, so you can see where the risks sit and where a DPIA is needed. Many organizations use the second to decide on the first.
Why rate impact for people as well as for the organization?
Because the harm in a privacy incident falls first on the people whose data it is: distress, discrimination, fraud or loss of control over their information. ISO/IEC 27701 and GDPR both expect those consequences to be weighed, not only fines and reputational damage.
Which controls does it use?
The 78 controls in ISO/IEC 27701:2025 Annex A, covering controllers and processors. Each scenario suggests the ones that usually treat it, and you can add any other.
Does this satisfy GDPR?
It helps you show the risk-based decisions GDPR asks for, but no tool makes an organization compliant. It is a self-assessment built from the information you enter, and Governance Docs does not review or verify it.
What happens to the information I enter?
It is stored with your assessment so you can come back to it, and it is never shared. Describe personal data by category rather than entering any real personal data. You can delete an assessment permanently from your account at any time.
