Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. The Risk-Based Approach
Courses Guides Blog Resources News
Français English Nederlands
Fiche 10/54 Part I — General Introduction Intermediate Reviewed 2026-08-23

The Risk-Based Approach

The GDPR is a proportionate regulation: it scales organizational obligations to the inherent risks of the processing. Low-risk operations require baseline measures, whereas high-risk activities mandat

Open in interactive reader
⚖️ Proportionality Principle 📋 EDPB Risk Methodology

The Risk-Based Approach (Recital 75 & Art. 24)

⚡ In 30 seconds

The GDPR does not impose uniform, one-size-fits-all requirements. Under Articles 24, 25, and 32, controllers must implement measures taking into account the nature, scope, context, and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons.

Standard Risk Processing

Standard security hygiene: TLS encryption, role-based access control, clear retention policies, breach reporting protocols.

High-Risk Processing (Art. 35)

Systematic monitoring, AI profiling, large-scale sensitive data: mandatory Data Protection Impact Assessment (DPIA) and potential DPA consultation (Art. 36).

⚡ Key Takeaways
  • Risk evaluation focuses on the individual's fundamental rights, not enterprise business exposure.
  • Recital 75 provides a detailed catalogue of harm: discrimination, identity theft, financial loss, reputational damage.
  • Security investments must be tailored and documented under accountability (Art. 5.2).
⚠️ Common Pitfall

Confusing information security risk (asset loss for the company) with GDPR risk (harm to natural persons).

🛠️ In Practice

Adopt a standardised DPIA template based on EDPB guidelines for all novel automated technologies.

⚖️ Official Sources: Art. 24, 25, 32, 35 GDPR · Recitals 75–77 · WP29 Guidelines on DPIA (WP248) ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Compliance burden scales with the severity and likelihood of risks to the rights and freedoms of individuals.
  • A DPIA (Art. 35) is mandatory whenever processing is likely to result in a high risk.
  • Technical and organizational measures must reflect the criticality of the operational context.

⚠ Common pitfall: Deploying disproportionate bureaucratic procedures for low-risk systems, while neglecting rigor on massive customer databases.

→ Actionable practice: Evaluate risk levels systematically at product design stage to calibrate security investments appropriately.

← Compatibility of Further Purposes (Art. 6.4) Legal Qualification Decision Tree →