
Updated content of the article:
Risk Assessment in accordance with GDPR
Every organization processing data is exposed to the influence of internal and external factors that may lead to a security breach, resulting in accidental or unlawful: destruction, loss, alteration, unauthorized disclosure, unauthorized access to data that is transmitted, stored, or otherwise processed. This situation is referred to as “Risk” because there is a possibility of failing to achieve the organization’s objectives due to the occurrence of certain events. Generally, risk can be divided into business (or for some entities - statutory activity risk), which is a category recognized long ago, and operational risk, which was identified at the end of the 20th century. Business risk is the possibility of incurring losses due to poor decisions regarding client selection, the shape of products and services, or obligations towards business partners, or due to dysfunction or inconsistency in the socio-economic system of the state. Operational risk is the risk of loss resulting from improper or erroneous actions of processes, people, and systems or the impact of external threats. Operational risk also includes the risk of failing to fulfill legal obligations in ongoing activities, which will be further discussed based on the announced Regulation of the European Parliament and of the Council on the protection of natural persons in relation to the processing of personal data and on the free movement of such data (Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016) (GDPR).
Requirement or good practice?
The General Data Protection Regulation addresses the aspect of risk associated with the processing of personal data multiple times, both in the preamble and in the main text, thereby indicating the importance that must be attached to the risk management process. Risk management is the process of identifying, assessing, responding to, and controlling potential events or situations, providing reasonable assurance that the organization’s objectives will be achieved. The requirement to conduct such a process is indicated, among others, in Article 24 “Responsibilities of the data controller” of the Regulation.
Concept and objectives of risk
In the literature, various definitions of the concept of risk can be found. The most accurate seems to be the definition according to the IIA (Institute of Internal Auditors) which states, “The possibility of an event occurring that will impact the achievement of set objectives. Risk is measured by the impact (consequences) and the probability of occurrence.” The Regulation in Article 32 defines the objectives regarding the security of processing, which are:
- pseudonymization and encryption of personal data,
- the ability to ensure the confidentiality, integrity, availability, and resilience of processing systems and services on an ongoing basis,
- the ability to quickly restore the availability of personal data and access to it in the event of a physical or technical incident,
- regular testing, measuring, and evaluating the effectiveness of technical and organizational measures to ensure the security of processing.
In this context, the risk in data processing is associated with a potential situation in which a specific threat exploits a vulnerability (e.g., unsecured computer hardware), thereby causing harm to the organization (e.g., theft or disclosure of information). A well-conducted risk analysis is the starting point for carrying out a professional Data Protection Impact Assessment (DPIA).

