Skip to main content
Category: Breach and Risk Assessment

Triage

Simply put

Triage is the process of sorting items and deciding which ones need attention first when resources are limited. The term originates in medicine, where care providers rank injured patients by the urgency of their need for treatment, especially in emergencies and mass casualty situations. The same idea of prioritizing what to handle first has been adapted to other fields.

Formal definition

Triage is a prioritization process that establishes the order in which items are addressed when demand exceeds available capacity. In its originating medical context, it refers to the systematic assessment and ranking of injured or critically ill patients to allocate treatment according to urgency, particularly during mass casualty incidents such as disasters or pandemics. The evidence provided documents the medical and general sense of the term and does not establish a specific definition scoped to data protection, information governance, or privacy incident handling; accordingly, application of triage to security or data-breach response workflows is out of scope for this entry and would require jurisdiction- and framework-specific sourcing.

Why it matters

Triage matters because it provides a structured way to make defensible decisions about what to address first when demand exceeds available capacity. In its originating medical context, this discipline determines the order of priority for treating injured or critically ill patients, particularly during mass casualty incidents such as disasters or pandemics, where care providers cannot attend to everyone simultaneously and the ordering of attention has direct consequences.

The underlying principle, that limited resources must be allocated according to urgency rather than arrival order or convenience, is what gives triage its enduring relevance across fields that later adopted the term. Where resources are genuinely constrained, a transparent and consistent prioritization method supports both effective outcomes and accountability for the choices made.

It should be noted that the evidence supporting this entry documents the medical and general sense of triage only. Any application of the concept to data protection, privacy incident handling, or security breach response is out of scope for this definition and would require jurisdiction- and framework-specific sourcing before such claims could be made. Readers should not infer a formal information governance meaning from this entry.

Who it's relevant to

Medical and emergency care providers
The evidence documents triage as a medical process by which care providers determine the order of priority for treating injured or critically ill patients, especially in emergency and mass casualty situations. This is the term's originating and best-sourced context.
Readers seeking the general meaning of the term
For a general audience, triage denotes the sorting of items and deciding which need attention first when resources are limited. This plain-language sense is well supported by the evidence and travels across disciplines that have adapted the concept.
Data protection and information governance professionals (with caution)
Practitioners may encounter the word triage in incident-response settings, but the evidence in this entry does not establish a definition scoped to data protection, security, or privacy incident handling. Any such application would require jurisdiction- and framework-specific sourcing and should not be inferred from the medical and general definitions provided here.

Inside Triage

Initial Classification
The step of categorizing an incoming event, request, or incident by type, such as distinguishing a personal data breach from a routine security alert or a data subject request from a general inquiry. Classification typically drives which downstream obligations and timelines apply.
Severity and Risk Assessment
A preliminary evaluation of the likely impact on individuals and the organization, often considering the categories of data involved (for example, whether special category data under the EU or UK GDPR is implicated) and the potential for harm. This assessment is provisional and generally refined during fuller investigation.
Prioritization and Routing
The ordering of matters by urgency and the assignment to the appropriate function, such as security, legal, the data protection officer, or a business owner. Routing reflects the distinct accountability of controllers and processors, who carry different obligations for the same event.
Escalation Criteria
Predefined thresholds that determine when a matter must be raised to senior stakeholders or specialist roles, for example when a potential notifiable breach or a matter requiring a data protection impact assessment is identified. Criteria should be documented rather than left to individual judgment.
Timeline Awareness
Recognition that certain categories of matter carry regulatory clocks, such as breach notification timeframes that vary by regime. Triage flags these time-sensitive matters early, though it does not itself discharge the notification obligation.
Evidence and Record Capture
The logging of the triage decision, its rationale, and the assigned owner. Under accountability-based frameworks, decisions generally must be demonstrable through records rather than stated intent alone.

Common questions

Answers to the questions practitioners most commonly ask about Triage.

Does triaging a personal data breach mean deciding whether it must be reported to a supervisory authority?
Not exactly. Triage is the initial assessment step that categorizes and prioritizes an incident by likely severity, scope, and urgency so that response resources can be allocated. Whether a breach must be notified to a supervisory authority or to affected individuals is a separate determination that generally turns on the risk to the rights and freedoms of individuals, and the applicable test and timing differ across regimes such as the EU GDPR, the UK GDPR, and various U.S. frameworks. Triage may inform that decision by surfacing relevant facts, but it does not replace the formal notification assessment, which typically involves legal and data protection input.
Is triage the same thing as a full risk assessment or a data protection impact assessment?
No. Triage is a rapid, preliminary sorting activity intended to establish priority and route an item to the appropriate handler; it is generally lightweight and time-sensitive. A data protection impact assessment is a more structured, documented evaluation of processing risks that is required only in specific higher-risk circumstances rather than universally, and a full risk assessment is likewise a deeper analytical exercise. Triage may indicate that a fuller assessment is warranted, but it is a precursor to those processes, not a substitute for them.
How can triage be applied to incoming data subject requests?
In practice, triage of data subject requests typically involves confirming the request type (such as access, erasure, or objection), verifying that it is a valid request under the applicable regime, and prioritizing it against any statutory response timelines that apply in the relevant jurisdiction. Organizations often use intake criteria to route requests to the correct team and flag those needing identity verification or legal review. This entry does not cover the substantive handling rules, response deadlines, or exemptions, which vary by regime and should be determined separately.
Who should be responsible for triage within an organization?
Responsibility is generally assigned to a defined intake function or role rather than left ad hoc, so that accountability is demonstrable. Depending on the incident type, triage may sit with a security operations team, a privacy or data protection function, or a shared response team, with escalation paths to the data protection officer or legal where required. Because accountability under governance frameworks generally requires evidence rather than stated intent, organizations typically document who performed triage, on what basis, and when.
What criteria are commonly used to prioritize items during triage?
Common criteria include the sensitivity of the data involved (for example, whether special category or sensitive data may be affected), the estimated number of individuals impacted, the likelihood and potential severity of harm, and any applicable time constraints such as statutory clocks. These criteria are typically defined in advance and applied consistently. The specific thresholds and weightings depend on organizational context and the applicable regime, and this entry does not prescribe particular numeric thresholds.
How should triage decisions be recorded?
Triage outcomes are generally documented with enough detail to show what was assessed, the priority or category assigned, the rationale, the responsible individual, and the time of the decision. Maintaining such records supports the accountability principle found in several governance frameworks, which typically requires demonstrable evidence rather than merely stated intent. This entry does not address specific retention periods for triage records, which should be set according to applicable retention rules.

Common misconceptions

Triage determines final compliance obligations for an incident.
Triage produces a provisional assessment used to prioritize and route matters. Final determinations, such as whether a breach is notifiable or whether a data protection impact assessment is required, generally depend on fuller investigation and on the applicable regime, and can change as facts emerge.
A triage classification of low severity means no further action or notification is needed.
A provisional low-severity rating does not by itself relieve an organization of obligations. Whether notification or other action applies depends on context, jurisdiction, and the nature of the data involved, and severity may be reassessed as more information is gathered.
Triage is a security-only function.
Triage typically spans both information security and data governance concerns. A single event may raise availability or integrity issues handled by security teams as well as data subject rights, lawful basis, or stewardship questions handled by governance and legal functions, and the two should be coordinated without being collapsed into one.

Best practices

Document classification and escalation criteria in advance so triage decisions are consistent, repeatable, and defensible rather than dependent on individual judgment.
Record each triage decision, its rationale, and the assigned owner, since accountability under governance frameworks generally requires demonstrable evidence, not merely stated intent.
Identify time-sensitive matters early and flag applicable regulatory clocks, noting that notification timeframes and their triggers differ across regimes such as the EU GDPR, UK GDPR, and others.
Route matters to the appropriate function based on role, distinguishing controller and processor obligations and involving the data protection officer, security, and legal as the matter type requires.
Treat triage severity ratings as provisional and require reassessment as investigation progresses, so that an initial low rating does not prematurely close obligations.
Coordinate security and governance perspectives during triage without conflating them, ensuring both confidentiality, integrity, and availability concerns and data subject and stewardship concerns are captured.