Answers to the questions practitioners most commonly ask about Likelihood and Impact.
Does a high likelihood-and-impact rating on its own tell us whether a DPIA is required?
Not exactly, and it is worth being precise about how the two relate. Under the EU and UK GDPR, a DPIA is required whenever a type of processing is likely to result in a high risk to the rights and freedoms of individuals. A likelihood-and-impact assessment is one of the analytical tools used to reach that 'high risk' judgment, so the two are closely linked. Where your combined likelihood and impact analysis indicates high risk, that generally triggers the DPIA obligation. What the rating does not do is override the obligation: you cannot conclude that high-risk processing escapes a DPIA simply because it is not named in the illustrative lists in the regulation or in a supervisory authority's list. Those lists inform the assessment but do not exhaustively define when high risk exists. This entry addresses the risk-scoring concept and does not set out the full procedural requirements of conducting a DPIA.
Is likelihood-and-impact analysis in a privacy context the same as the risk scoring used in information security?
They share a common structure but should not be treated as identical. Information security risk assessment typically evaluates threats to confidentiality, integrity, and availability of information assets, often framing impact in terms of harm to the organization. Privacy or data protection risk assessment under frameworks such as the EU and UK GDPR centers impact on the rights and freedoms of natural persons, meaning harm to individuals rather than only to the organization. The likelihood and impact axes may look similar, but the object being protected and the definition of impact differ. Governance and security overlap here without collapsing into one another: a control that reduces security risk may also reduce privacy risk, but a privacy assessment must still weigh harms to data subjects that a purely security-focused analysis might not surface. This entry does not cover the specific methodologies of either discipline in detail.
How should likelihood and impact be combined to reach an overall risk rating?
A common approach is to assess likelihood (how probable a given adverse event is) and impact (the severity of harm if it occurs) on separate scales and then combine them, often via a matrix, to produce an overall risk level. The scales, the number of levels, and the combination logic are matters of methodology chosen by the organization; no single scheme is mandated across jurisdictions. What matters is that the method is applied consistently and that the reasoning is documented so the rating is defensible on review. Accountability under governance frameworks generally requires demonstrable evidence of how a rating was reached, not merely a stated conclusion. This entry does not prescribe a specific scoring scale or matrix.
Who should be involved in setting likelihood and impact ratings?
Ratings are generally more reliable when they draw on multiple perspectives rather than a single owner. Business or process owners understand the purpose and context of the processing, security teams can inform likelihood assessments tied to controls and threats, and privacy or data protection specialists help frame impact in terms of harm to individuals. Where a data protection officer is appointed, that role typically advises on and monitors the assessment rather than owning the underlying processing decision. Accountability for the processing itself generally rests with the controller. This entry describes the collaborative nature of the assessment and does not assign specific role obligations under any single instrument.
How often should likelihood-and-impact ratings be reviewed?
Ratings reflect a point in time and can become outdated as processing, technology, threats, or controls change. Good practice is to revisit them when a material change occurs, such as a new processing purpose, a change of processor, a new data category, or a change in the control environment, and to review periodically even absent a triggering change. The appropriate cadence depends on the sensitivity of the processing and the organization's risk posture rather than a fixed universal interval. Maintaining a record of when and why a rating was reviewed supports the demonstrable accountability expected under governance frameworks. This entry does not specify retention periods for assessment records.
What evidence should be retained to support a likelihood-and-impact rating?
Because accountability under governance frameworks generally requires demonstrable evidence rather than stated intent, it is advisable to retain the reasoning behind each rating: the factors considered for likelihood, the harms considered for impact, the assumptions made, the controls credited, and the identity of those who contributed to and approved the assessment. Retaining the version history helps show how ratings evolved over time. This documentation supports defensibility on review and can feed into broader assessments where required. This entry does not address specific record-retention rules or the format of any mandated documentation, which vary by jurisdiction and instrument.