Walkthroughs · 3.6

Manage risks and measures

One risk record, read on two consequences, treated, approved and monitored, with the technical and organisational measures under Article 32.

Steps

Risk and security holds the risks and the measures. The wording follows ISO/IEC 27005 and clause 6.1 of ISO/IEC 27701:2025, so treatment is stated as an outcome rather than a stage number.

A risk is one record from identification to closure. It is never split into a copy for the assessment and another for the treatment, so the register always answers with a single reading.

  1. 01Identify the riskState the contributing condition, the event and the consequence in one sentence, and record where the risk came from, so the chain of reasoning stays traceable. Name the scope: where likelihood, consequences or controls differ, scope a separate risk.
  2. 02Assess it on both consequencesRecord the likelihood once, then the consequence for data subjects under Articles 24(1) and 35(1), and separately the consequence for the organisation. The two are never averaged, because a serious harm to a person is not offset by a small cost to the company. Each rating is derived on a five by five scale and is never typed in.
  3. 03Name the owner and the approverChoose them from the people in the workspace. A risk carried without an owner, or accepted without an approver, is raised as a gap.
  4. 04Choose the treatment and link the measuresState the treatment strategy and the reasons for it, then attach the technical or organisational measures that address the risk, or raise a privacy action where the measure does not exist yet.
  5. 05Rate what remains, then monitor or acceptRecord the residual likelihood and both residual consequences once the measures operate, with the evidence that their effectiveness was confirmed. A residual high risk to data subjects requires an authorised acceptance and, where it stands, prior consultation under Article 36.
The risk register. The matrix is read on one consequence at a time, before or after treatment, and selecting a cell filters the register below it.
The risk register. The matrix is read on one consequence at a time, before or after treatment, and selecting a cell filters the register below it.

When an assessment stops being current

The context an assessment was made in is recorded with it. Where the processing, the categories of data or the measures move on, the assessment is marked as no longer current and the risk is returned for reassessment. Earlier assessments are retained as written, so what was decided, by whom and on what basis remains readable.

Technical and organisational measures

Each measure records what it is, where it applies, its state of implementation and how its effectiveness was tested, as Article 32(1)(d) asks.

The register of technical and organisational measures.
The register of technical and organisational measures.

Privacy actions

A privacy action is an owned, dated task raised from a gap, a review or an assessment. It is how the outstanding work is tracked to completion.

The privacy actions register.
The privacy actions register.