High-Risk Processing
High-risk processing refers to the use of personal data in ways that are more likely to cause harm to the people the data is about, such as extensive tracking, profiling, or combining data from many sources. When an organisation plans this kind of processing, data protection rules generally expect it to assess the risks in advance. This entry describes the concept in the UK GDPR context and does not cover the detailed procedural steps of a data protection impact assessment or how other regimes define risk.
Under the UK GDPR, 'processing likely to result in high risk' describes personal data processing operations whose nature, scope, context, or purposes make a significant risk to the rights and freedoms of individuals more probable, thereby generally triggering the obligation to carry out a data protection impact assessment (DPIA) before processing begins. The UK regulator (ICO) publishes non-exhaustive examples of processing considered likely to be high risk, including list brokering, direct marketing, online tracking by third parties, online advertising, and data aggregation. Whether processing is high risk is a case-by-case assessment based on the specific operation rather than a fixed classification, and the presence of one listed example does not by itself determine the outcome. The controller bears the accountability obligation to identify high-risk processing and, where applicable, conduct and evidence a DPIA; a DPIA is not mandatory for all processing. This term should not be confused with 'high-risk payment processing' or 'high-risk merchant accounts,' which are commercial payments concepts concerning fraud and chargeback exposure and are unrelated to data protection law. This entry does not address DPIA methodology, prior consultation requirements, cross-border transfer mechanics, retention, or how the EU GDPR, CCPA/CPRA, or other frameworks treat comparable concepts.
Why it matters
High-risk processing sits at the centre of the accountability principle under the UK GDPR. When an organisation's use of personal data is more likely to cause harm to individuals, the regulatory expectation shifts from routine record-keeping to a demonstrable, forward-looking assessment of those risks. Getting this classification wrong in either direction carries consequences: treating genuinely high-risk processing as routine may leave individuals exposed to harms the organisation never evaluated, while an inability to show why processing was or was not treated as high risk undermines the demonstrable evidence that accountability requires. Stated intent to protect individuals is not enough; controllers generally need a documented rationale for their risk judgements.
Who it's relevant to
Inside High-Risk Processing
Common questions
Answers to the questions practitioners most commonly ask about High-Risk Processing.