Skip to main content
Category: Breach and Risk Assessment

Likelihood and Impact

Also known as: Probability and Impact, Likelihood and Severity
Simply put

Likelihood and impact are the two core dimensions used to measure risk. Likelihood is how probable it is that a given risk event will happen, usually within a defined timeframe, while impact is an estimate of the harm or severity of consequences if that event does occur. Combining the two helps organizations rank risks and decide where to focus attention and resources.

Formal definition

In risk assessment, likelihood is the estimated probability that a risk event will materialize within a defined period, and impact is the estimated severity of the resulting harm should the event occur. Both are commonly rated on ordinal scales (for example, High/Medium/Low or a five-level 1-to-5 scale) and plotted on a risk matrix to derive a composite risk level for prioritization. These dimensions are typically applied qualitatively, though quantitative methods also exist; some frameworks add further factors such as velocity (the speed at which a risk would materialize). Scale definitions and rating criteria vary by organization and framework, and the calibration of a likelihood or impact rating depends on the assessment context and time horizon chosen. This entry defines the two dimensions generally and does not address how likelihood and impact are used within any specific data protection instrument; in particular, it does not cover the threshold criteria for when a data protection impact assessment (DPIA) is required, nor jurisdiction-specific risk methodologies, which should be assessed against the relevant regime.

Why it matters

Likelihood and impact are the foundational dimensions of nearly every risk assessment, and how well an organization calibrates them directly shapes where it invests limited attention and resources. Rating a risk on both axes rather than one prevents two common distortions: treating a catastrophic-but-improbable event with the same urgency as a near-certain minor one, or overlooking a low-severity risk that occurs so frequently its cumulative harm becomes significant. Combining the two into a composite level gives decision-makers a defensible basis for prioritization rather than an ad hoc ranking driven by whichever risk is most visible at the time.

Who it's relevant to

Risk and Compliance Officers
Those responsible for maintaining risk registers rely on likelihood and impact ratings to rank exposures and justify where controls and budget are directed. Because scale definitions and rating criteria vary by organization and framework, they should document the calibration basis, including the time horizon chosen, so that ratings remain consistent and demonstrable rather than subjective.
Data Protection Officers and Privacy Teams
Likelihood and impact are widely used to characterize risk to individuals, but this general definition does not set the threshold for when a data protection impact assessment is required under any specific instrument. Under the EU and UK GDPR, a DPIA is mandatory whenever a type of processing is likely to result in a high risk to the rights and freedoms of natural persons; that determination should be assessed against the relevant regime rather than inferred from a generic risk matrix.
Governance and Assessment Leads
Teams designing assessment methodologies must decide whether to apply these dimensions qualitatively or quantitatively, and whether to add further factors such as velocity, the speed at which a risk would materialize. Because the calibration of any rating depends on the assessment context and chosen time horizon, the underlying criteria should be defined explicitly and evidenced, since accountability requires demonstrable support rather than stated intent.

Inside Likelihood and Impact

Likelihood
The probability or reasonable expectation that a given risk to the rights and freedoms of natural persons will materialize from a processing activity. Under the EU and UK GDPR, likelihood is one of the two dimensions assessed when determining whether processing poses a risk or a high risk. It is a qualitative or semi-quantitative judgment, not a precise statistical figure, and depends on factors such as the nature, scope, context, and purposes of processing.
Impact (Severity)
The magnitude of harm or adverse consequence to data subjects should a risk materialize. In data protection risk assessment, impact is evaluated in terms of harm to individuals' rights and freedoms (for example, discrimination, identity theft, financial loss, reputational damage, or loss of confidentiality), rather than solely organizational impact as in traditional information security risk models.
Risk as a Function of Likelihood and Impact
Risk is generally derived by combining likelihood and impact. Higher likelihood combined with higher severity yields a higher overall risk rating. This framing is common to both information security risk methodologies and data protection risk assessment, though the object of harm differs: security frameworks typically focus on the organization's assets, while data protection focuses on harm to individuals.
High Risk Threshold
Under the EU and UK GDPR, where processing is likely to result in a high risk to the rights and freedoms of natural persons, a data protection impact assessment (DPIA) is required. High-risk processing therefore triggers a DPIA obligation, whether or not the processing appears in the illustrative examples in the regulation or on a supervisory authority's list of processing operations requiring a DPIA.
Rights and Freedoms Focus
In the EU and UK GDPR context, the assessment of likelihood and impact centers on risks to the rights and freedoms of natural persons, not exclusively on confidentiality, integrity, and availability of data. This distinguishes data protection risk assessment from a purely information security risk assessment, though the two overlap and are often conducted together.

Common questions

Answers to the questions practitioners most commonly ask about Likelihood and Impact.

Does a high likelihood-and-impact rating on its own tell us whether a DPIA is required?
Not exactly, and it is worth being precise about how the two relate. Under the EU and UK GDPR, a DPIA is required whenever a type of processing is likely to result in a high risk to the rights and freedoms of individuals. A likelihood-and-impact assessment is one of the analytical tools used to reach that 'high risk' judgment, so the two are closely linked. Where your combined likelihood and impact analysis indicates high risk, that generally triggers the DPIA obligation. What the rating does not do is override the obligation: you cannot conclude that high-risk processing escapes a DPIA simply because it is not named in the illustrative lists in the regulation or in a supervisory authority's list. Those lists inform the assessment but do not exhaustively define when high risk exists. This entry addresses the risk-scoring concept and does not set out the full procedural requirements of conducting a DPIA.
Is likelihood-and-impact analysis in a privacy context the same as the risk scoring used in information security?
They share a common structure but should not be treated as identical. Information security risk assessment typically evaluates threats to confidentiality, integrity, and availability of information assets, often framing impact in terms of harm to the organization. Privacy or data protection risk assessment under frameworks such as the EU and UK GDPR centers impact on the rights and freedoms of natural persons, meaning harm to individuals rather than only to the organization. The likelihood and impact axes may look similar, but the object being protected and the definition of impact differ. Governance and security overlap here without collapsing into one another: a control that reduces security risk may also reduce privacy risk, but a privacy assessment must still weigh harms to data subjects that a purely security-focused analysis might not surface. This entry does not cover the specific methodologies of either discipline in detail.
How should likelihood and impact be combined to reach an overall risk rating?
A common approach is to assess likelihood (how probable a given adverse event is) and impact (the severity of harm if it occurs) on separate scales and then combine them, often via a matrix, to produce an overall risk level. The scales, the number of levels, and the combination logic are matters of methodology chosen by the organization; no single scheme is mandated across jurisdictions. What matters is that the method is applied consistently and that the reasoning is documented so the rating is defensible on review. Accountability under governance frameworks generally requires demonstrable evidence of how a rating was reached, not merely a stated conclusion. This entry does not prescribe a specific scoring scale or matrix.
Who should be involved in setting likelihood and impact ratings?
Ratings are generally more reliable when they draw on multiple perspectives rather than a single owner. Business or process owners understand the purpose and context of the processing, security teams can inform likelihood assessments tied to controls and threats, and privacy or data protection specialists help frame impact in terms of harm to individuals. Where a data protection officer is appointed, that role typically advises on and monitors the assessment rather than owning the underlying processing decision. Accountability for the processing itself generally rests with the controller. This entry describes the collaborative nature of the assessment and does not assign specific role obligations under any single instrument.
How often should likelihood-and-impact ratings be reviewed?
Ratings reflect a point in time and can become outdated as processing, technology, threats, or controls change. Good practice is to revisit them when a material change occurs, such as a new processing purpose, a change of processor, a new data category, or a change in the control environment, and to review periodically even absent a triggering change. The appropriate cadence depends on the sensitivity of the processing and the organization's risk posture rather than a fixed universal interval. Maintaining a record of when and why a rating was reviewed supports the demonstrable accountability expected under governance frameworks. This entry does not specify retention periods for assessment records.
What evidence should be retained to support a likelihood-and-impact rating?
Because accountability under governance frameworks generally requires demonstrable evidence rather than stated intent, it is advisable to retain the reasoning behind each rating: the factors considered for likelihood, the harms considered for impact, the assumptions made, the controls credited, and the identity of those who contributed to and approved the assessment. Retaining the version history helps show how ratings evolved over time. This documentation supports defensibility on review and can feed into broader assessments where required. This entry does not address specific record-retention rules or the format of any mandated documentation, which vary by jurisdiction and instrument.

Common misconceptions

A DPIA is only required when processing appears on a supervisory authority's list or matches one of the examples named in the regulation.
Under the EU and UK GDPR, a DPIA is mandatory whenever a type of processing is likely to result in a high risk to the rights and freedoms of natural persons. High-risk processing always triggers the DPIA obligation, even where it does not fall within the illustrative examples in the regulation or on a supervisory-authority list. Those lists are aids to identifying high risk, not the exclusive triggers.
Likelihood and impact in data protection risk assessment measure harm to the organization, as in a standard information security risk model.
In the EU and UK GDPR context, the assessment focuses on risks to the rights and freedoms of natural persons (the data subjects), such as discrimination, financial loss, or loss of confidentiality. This differs from traditional information security risk assessment, which typically centers on organizational assets. The two overlap and are commonly performed together, but they should not be collapsed into one another.
A quantified low likelihood score means the processing is compliant and no further action is required.
A risk rating is an input to decision-making, not a determination of compliance. Compliance depends on context, jurisdiction, lawful basis, and implementation. A low assessed likelihood does not remove the need to identify a valid lawful basis, apply appropriate safeguards, or meet other obligations, and it does not by itself guarantee compliance.

Best practices

Assess likelihood and impact in terms of harm to the rights and freedoms of natural persons, not solely in terms of harm to the organization's assets, when conducting data protection risk assessments under the EU or UK GDPR.
Treat any processing likely to result in a high risk to individuals as triggering a DPIA obligation under the EU and UK GDPR, rather than relying only on supervisory-authority lists or illustrative examples to decide whether a DPIA is needed.
Use consistent, documented criteria for rating likelihood and impact so that assessments are repeatable, comparable across processing activities, and defensible to a reviewer or supervisory authority.
Retain demonstrable evidence of how likelihood and impact were assessed, since accountability under data protection and governance frameworks generally requires evidence rather than stated intent.
Coordinate data protection risk assessment with information security risk assessment where they overlap, while keeping the object of harm distinct, and note explicitly which risks fall outside the assessment's scope.
Avoid presenting risk ratings as compliance determinations; record that a low or acceptable risk rating does not by itself establish a lawful basis or guarantee compliance, which depends on context, jurisdiction, and implementation.