Skip to main content
Category: Breach and Risk Assessment

High-Risk Processing

Also known as: Processing likely to result in high risk, High-risk data processing
Simply put

High-risk processing refers to the use of personal data in ways that are more likely to cause harm to the people the data is about, such as extensive tracking, profiling, or combining data from many sources. When an organisation plans this kind of processing, data protection rules generally expect it to assess the risks in advance. This entry describes the concept in the UK GDPR context and does not cover the detailed procedural steps of a data protection impact assessment or how other regimes define risk.

Formal definition

Under the UK GDPR, 'processing likely to result in high risk' describes personal data processing operations whose nature, scope, context, or purposes make a significant risk to the rights and freedoms of individuals more probable, thereby generally triggering the obligation to carry out a data protection impact assessment (DPIA) before processing begins. The UK regulator (ICO) publishes non-exhaustive examples of processing considered likely to be high risk, including list brokering, direct marketing, online tracking by third parties, online advertising, and data aggregation. Whether processing is high risk is a case-by-case assessment based on the specific operation rather than a fixed classification, and the presence of one listed example does not by itself determine the outcome. The controller bears the accountability obligation to identify high-risk processing and, where applicable, conduct and evidence a DPIA; a DPIA is not mandatory for all processing. This term should not be confused with 'high-risk payment processing' or 'high-risk merchant accounts,' which are commercial payments concepts concerning fraud and chargeback exposure and are unrelated to data protection law. This entry does not address DPIA methodology, prior consultation requirements, cross-border transfer mechanics, retention, or how the EU GDPR, CCPA/CPRA, or other frameworks treat comparable concepts.

Why it matters

High-risk processing sits at the centre of the accountability principle under the UK GDPR. When an organisation's use of personal data is more likely to cause harm to individuals, the regulatory expectation shifts from routine record-keeping to a demonstrable, forward-looking assessment of those risks. Getting this classification wrong in either direction carries consequences: treating genuinely high-risk processing as routine may leave individuals exposed to harms the organisation never evaluated, while an inability to show why processing was or was not treated as high risk undermines the demonstrable evidence that accountability requires. Stated intent to protect individuals is not enough; controllers generally need a documented rationale for their risk judgements.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy teams typically advise on whether a planned processing operation meets the 'likely to result in high risk' threshold and, where it does, on the need to conduct and evidence a DPIA before processing begins. Because a DPIA is not mandatory for all processing, their role includes documenting the reasoning behind the risk judgement so it can withstand later scrutiny.
Data controllers and accountable owners
The controller bears the accountability obligation to identify high-risk processing and, where applicable, carry out and evidence a DPIA. This responsibility cannot be discharged by intent alone; it generally requires demonstrable documentation of how the risk assessment was reached, particularly for activities such as data aggregation, profiling, or extensive tracking.
Marketing, advertising, and data operations teams
Teams engaged in direct marketing, online advertising, third-party online tracking, list brokering, or data aggregation should be aware that these are among the ICO's non-exhaustive examples of processing likely to be high risk. Early engagement with privacy colleagues helps ensure that a risk assessment is considered before such processing is deployed.
Compliance and governance functions
Compliance and information governance leads rely on clear high-risk determinations to prioritise oversight and to maintain the evidence base that accountability under the UK GDPR expects. Note that this concept is distinct from 'high-risk payment processing' or 'high-risk merchant accounts,' which are commercial payments concepts concerning fraud and chargeback exposure and are unrelated to data protection law.

Inside High-Risk Processing

Concept of high risk to rights and freedoms
Under the EU GDPR, high-risk processing refers to processing operations that are likely to result in a high risk to the rights and freedoms of natural persons. This is an assessment of likelihood and severity of potential impact on individuals, not merely a risk to the organization. Treatment of this concept under the UK GDPR is broadly aligned, but other regimes such as the CCPA/CPRA, HIPAA, or the NIST Privacy Framework do not use this identical construct.
Trigger for a data protection impact assessment (DPIA)
Where processing is likely to result in a high risk, the EU GDPR generally requires the controller to carry out a DPIA prior to processing. The obligation to conduct a DPIA rests with the controller, not the processor, although a processor typically must assist the controller. A DPIA is not required for every processing activity, only where the high-risk threshold is met or where a supervisory authority list indicates one is needed.
Indicative criteria and factors
Assessment of high risk typically considers factors such as large-scale processing, systematic monitoring, use of special category data, evaluation or scoring including profiling, automated decision-making with legal or similarly significant effects, processing of vulnerable individuals' data, and the use of new technologies. These are indicative factors used in guidance; the precise weighting and combination that constitute high risk depend on context and jurisdiction.
Prior consultation with a supervisory authority
Where a DPIA indicates that processing would result in a high risk that the controller cannot mitigate by reasonable means, the EU GDPR generally requires the controller to consult the competent supervisory authority before proceeding. This is distinct from the DPIA itself and applies only to residual, unmitigated high risk.
Relationship to accountability
Identifying and documenting high-risk processing supports the accountability principle. Under governance and regulatory frameworks, accountability requires demonstrable evidence, such as a documented DPIA and mitigation decisions, rather than a stated intent to process safely.

Common questions

Answers to the questions practitioners most commonly ask about High-Risk Processing.

Does high-risk processing always require a Data Protection Impact Assessment?
Not automatically, though the two concepts are closely linked and frequently conflated. Under the EU and UK GDPR, a DPIA is generally required where processing is likely to result in a high risk to the rights and freedoms of individuals, so identifying processing as high-risk typically triggers the assessment obligation. However, the DPIA is the mechanism for evaluating and mitigating that risk, not a synonym for the risk itself. Some processing may be assessed as high-risk yet fall within recognised exceptions or prior-consultation pathways, and treatment differs across regimes such as the CCPA and CPRA, HIPAA, or the NIST Privacy Framework, which do not use the identical DPIA construct. This entry does not cover the specific circumstances under which a DPIA may be waived or when prior consultation with a supervisory authority is required.
Is processing considered high-risk simply because it involves special category or sensitive data?
Not necessarily. Involving special category data (or sensitive personal information under other regimes) is one factor that can indicate elevated risk, but high-risk processing is generally assessed against the nature, scope, context, and purposes of the processing taken together, not the data type alone. Ordinary personal data processed at large scale, through systematic monitoring, or in ways that produce significant effects on individuals can also qualify as high-risk. Conversely, limited processing of sensitive data in a narrow, well-controlled context may not reach a high-risk threshold. The determination is contextual and depends on the applicable framework; this entry does not enumerate every criterion any single supervisory authority applies.
How do we determine whether a given processing activity should be treated as high-risk?
In most jurisdictions applying a GDPR-style model, the assessment weighs factors such as the scale of processing, whether systematic monitoring or profiling is involved, the use of special category data, the vulnerability of the data subjects, and the potential for significant effects on individuals. Supervisory authorities may publish lists of processing types that are considered likely to be high-risk, and consulting the guidance applicable to your jurisdiction is generally advisable. The evaluation should be documented so that the reasoning is demonstrable rather than merely asserted. This entry does not provide a jurisdiction-specific checklist or reproduce any authority's published list.
Who is responsible for identifying and managing high-risk processing?
Accountability generally rests with the data controller, which determines the purposes and means of processing and therefore bears the obligation to assess risk and implement appropriate measures. A data processor typically acts on the controller's documented instructions and may be required to assist the controller, but the processor does not assume the controller's accountability for the risk determination. A data protection officer, where one is appointed, generally advises on and monitors the assessment rather than owning the decision. Accountability under governance and data protection frameworks requires demonstrable evidence of the assessment and any mitigations, not merely a stated intention to manage risk.
What measures can help mitigate high-risk processing?
Mitigations are typically drawn from both data governance and information security domains and are selected according to the specific risks identified. These may include data minimisation, defined retention and access controls, pseudonymisation, and clear documentation of ownership and lineage on the governance side, alongside confidentiality, integrity, and availability controls on the security side. No single control, consent mechanism, or lawful basis guarantees compliance or eliminates risk; measures should be proportionate to the assessed risk and reviewed over time. Note that pseudonymisation, encryption, or tokenization reduce risk but do not render the data non-personal. This entry does not prescribe a specific control set.
How should high-risk processing be documented for accountability purposes?
Documentation should capture the risk assessment itself, the reasoning behind the high-risk determination, the mitigating measures chosen, and any residual risk accepted, in a form that can be produced to a supervisory authority or auditor. This documentation is generally distinct from records of processing activities and from any data inventory tool; maintaining a tool or inventory does not by itself satisfy the requirement to demonstrate how a high-risk activity was assessed and controlled. Under governance frameworks, accountability requires demonstrable evidence rather than a stated policy alone. This entry does not cover retention periods for such documentation or cross-border transfer implications.

Common misconceptions

A DPIA is always mandatory for any processing of personal data.
A DPIA is generally required only where processing is likely to result in a high risk to individuals under the EU or UK GDPR, or where a supervisory authority list indicates one. Many routine processing activities do not meet this threshold. Whether a DPIA is required depends on context, jurisdiction, and the specific processing.
High-risk processing is about risk to the organization, such as reputational or financial exposure.
In the GDPR sense, high risk refers to the likelihood and severity of harm to the rights and freedoms of natural persons, that is, the affected individuals, not the risk to the controller or processor. Organizational risk is a separate governance concern.
Applying encryption, tokenization, or pseudonymization removes processing from the high-risk category.
Such measures may reduce risk and can be relevant mitigations recorded in a DPIA, but they do not make data non-personal. Pseudonymized data generally remains personal data, and encrypted or tokenized data is typically still in scope. These controls do not by themselves guarantee that processing is no longer high risk.

Best practices

Establish a documented screening process to determine, before processing begins, whether an activity is likely to be high risk using the indicative criteria such as large-scale processing, systematic monitoring, special category data, and automated decision-making.
Assign clear accountability to the controller for conducting DPIAs, and define how processors are expected to assist, retaining demonstrable evidence of both the assessment and the resulting decisions.
Consult any applicable supervisory authority lists of processing operations that require or are exempt from a DPIA within your relevant jurisdiction, and revisit them as guidance evolves.
Where residual high risk cannot be mitigated by reasonable means, engage in prior consultation with the competent supervisory authority before proceeding, and document that determination.
Treat mitigation measures such as pseudonymization or encryption as recorded controls within the DPIA rather than as reasons to exclude data from scope, since they do not render data non-personal.
Review high-risk determinations periodically and when processing changes materially, since the introduction of new technologies or expanded scope can alter the risk profile.