Problematic Data Action
A problematic data action is any handling of personal information during processing that could cause harm or an adverse effect for the individuals the data is about. It is a concept used to help organizations identify where their use of data might create problems for people, so those risks can be assessed and addressed.
In the NIST Privacy Framework and associated Privacy Risk Assessment Methodology (PRAM), a problematic data action is a data action performed on personally identifiable information through the information lifecycle that could cause an adverse effect, or problem, for individuals. It is the analytical unit used in privacy risk analysis: practitioners map data actions across processing, identify those that could produce individual-level problems, and pair them with the potential problems in order to estimate privacy risk. NIST publishes a non-exhaustive, illustrative catalog of problematic data actions and problems to support this analysis. This term originates in NIST guidance and is distinct from information security concepts; it concerns adverse effects on individuals arising from processing rather than confidentiality, integrity, or availability failures. Note that this concept is a risk-analysis construct within a voluntary NIST framework and does not itself define legal obligations, lawful bases, or compliance requirements under regimes such as the EU GDPR, UK GDPR, or CCPA/CPRA, which treat privacy risk differently. This entry does not cover the specific catalog contents, risk-scoring methods, or cross-jurisdictional mapping.
Why it matters
The problematic data action concept reframes privacy risk in a way that many security-oriented teams initially find unfamiliar. Traditional risk analysis often centers on threats to the organization's data, breaches of confidentiality, integrity, or availability. A problematic data action, as used in the NIST Privacy Framework and its Privacy Risk Assessment Methodology (PRAM), instead directs attention to adverse effects experienced by the individuals the data is about, even when the organization is processing data exactly as intended and no security failure has occurred. This distinction matters because entirely authorized, technically secure processing can still create problems for people, and those problems can go undetected if analysis only asks whether data is protected rather than whether its use could harm individuals.
For privacy engineers and governance teams, the value of the construct is that it provides a discrete analytical unit. By mapping data actions across the information lifecycle and identifying which of them could produce an adverse effect, practitioners can pair specific data actions with specific potential problems and reason about privacy risk in a structured way rather than treating privacy as a vague, holistic concern. This supports demonstrable, evidence-based accountability by making the reasoning behind a risk determination explicit and reviewable.
It is important to keep the concept in its proper scope. A problematic data action is a risk-analysis construct within a voluntary NIST framework. It does not by itself create legal obligations, establish a lawful basis, or determine compliance under regimes such as the EU GDPR, UK GDPR, or CCPA/CPRA, which frame and address privacy risk differently. Identifying a problematic data action informs where to focus assessment and mitigation effort; it does not substitute for the separate legal analysis those regimes require.
Who it's relevant to
Inside PDA
Common questions
Answers to the questions practitioners most commonly ask about PDA.