Steps
Risk and security holds the risks and the measures. The wording follows ISO/IEC 27005 and clause 6.1 of ISO/IEC 27701:2025, so treatment is stated as an outcome rather than a stage number.
A risk is one record from identification to closure. It is never split into a copy for the assessment and another for the treatment, so the register always answers with a single reading.
- 01Identify the riskState the contributing condition, the event and the consequence in one sentence, and record where the risk came from, so the chain of reasoning stays traceable. Name the scope: where likelihood, consequences or controls differ, scope a separate risk.
- 02Assess it on both consequencesRecord the likelihood once, then the consequence for data subjects under Articles 24(1) and 35(1), and separately the consequence for the organisation. The two are never averaged, because a serious harm to a person is not offset by a small cost to the company. Each rating is derived on a five by five scale and is never typed in.
- 03Name the owner and the approverChoose them from the people in the workspace. A risk carried without an owner, or accepted without an approver, is raised as a gap.
- 04Choose the treatment and link the measuresState the treatment strategy and the reasons for it, then attach the technical or organisational measures that address the risk, or raise a privacy action where the measure does not exist yet.
- 05Rate what remains, then monitor or acceptRecord the residual likelihood and both residual consequences once the measures operate, with the evidence that their effectiveness was confirmed. A residual high risk to data subjects requires an authorised acceptance and, where it stands, prior consultation under Article 36.


