Fiche 10/54
Part I — General Introduction
Intermediate
Reviewed 2026-08-23
The Risk-Based Approach
The Risk-Based Approach (Recital 75 & Art. 24)
⚡ In 30 seconds
The GDPR does not impose uniform, one-size-fits-all requirements. Under Articles 24, 25, and 32, controllers must implement measures taking into account the nature, scope, context, and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons.
Standard Risk Processing
Standard security hygiene: TLS encryption, role-based access control, clear retention policies, breach reporting protocols.
High-Risk Processing (Art. 35)
Systematic monitoring, AI profiling, large-scale sensitive data: mandatory Data Protection Impact Assessment (DPIA) and potential DPA consultation (Art. 36).