Skip to content
What You Have to Produce

Home / The breach

Assessing Risk to People

The assessment that determines whether to notify, and the one organisations instinctively get backwards by assessing risk to themselves.

The breach · Procedure

RISK ASSESSMENT

Completed inside the window, attached to the record

  • Data type
    What exactly was exposedSpecial category changes everything
  • Sensitivity
    What could be done with itSalary and health are different from a work address
  • Volume
    How many peopleScale affects likelihood of harm, not whether harm is possible
  • Identifiability
    Could individuals be identifiedEncrypted and unreadable is a different position
  • Recipient
    Who received or accessed itA known colleague differs from an unknown party
  • Recovery
    Was it recovered, deleted, confirmedConfirmed deletion by a trusted recipient reduces risk genuinely
  • Likely harm
    Named, specificallyDiscrimination, distress, financial loss, identity fraud
  • Vulnerability
    Are any affected people particularly at riskAddresses of people at risk of violence, for instance
  • Conclusion
    Likely risk, high risk, or neitherWhich determines notification to regulator and to people

Two assessments follow a breach. Whether to notify the regulator, and whether to tell the people affected. Both turn on risk to those people.

The breach workflow in “Assessing Risk to People” is easier to operate when systems, owners and evidence are known in advance. If view the solution supports step rate compensation, its records should sit inside the incident inventory with clear access, retention and escalation rules rather than being treated as an unexplained source of employee data.

The instinct to resist

The first question most organisations ask is how bad this is for us.

For a separate benchmark relevant to “Assessing Risk to People”, consult the AWS incident-response guide. Use it to test purpose, data flow, retention, access and response procedures rather than substituting a generic checklist for the organisation’s actual records.

That is a legitimate question and it is not this one. The test is about consequences for the individuals whose data was exposed, and an assessment framed around organisational exposure reaches the wrong answer in both directions — sometimes over-notifying out of caution, more often under-notifying because the business impact looks manageable.

What raises the risk

Special category data. Health, union membership, beliefs, sexual orientation, ethnicity. A breach involving these is materially more serious regardless of volume.

Financial detail, which enables fraud.

Home addresses, where anybody affected may be at risk from somebody.

Combinations. A name alone is low risk; a name with a salary, a home address and a performance rating is a different matter.

An unknown or untrusted recipient.

What lowers it

Encryption, where the data is genuinely unreadable to the recipient.

Prompt recovery with confirmation — a recipient who confirms deletion and is credible.

Narrow exposure: one colleague who reported it immediately is not the same as publication.

Named harms rather than general concern

The assessment should say what could actually happen: this person could be identified as having made a complaint; these salaries could be used in a dispute; this address could reach somebody from whom the person is hiding.

A general statement that there is a risk to privacy is not an assessment and reads as one that was not done.

The two thresholds

Likely to result in a risk: notify the regulator.

Likely to result in a high risk: also tell the people affected.

High risk is a higher bar and it is met more often than organisations want it to be, which is the subject of the next note.

Recording the decision not to notify

Where the conclusion is that the threshold is not met, the reasoning goes in the record with the same care as a notification.

A decision not to notify is the one most likely to be examined later, and the only defence is a contemporaneous assessment showing it was taken properly.

This person could be identified as having complained; these salaries could be used in a dispute; this address could reach somebody they are hiding from. A general statement that privacy is at risk reads as an assessment that was not done.

Recording a decision not to notify

With the same care as a notification. It is the decision most likely to be examined later, and a contemporaneous assessment is the only defence.

Assessing risk to them, not to you

The first question most organisations ask is how bad this is for us. Legitimate, and not this one. An assessment framed around organisational exposure reaches the wrong answer in both directions.

What raises and lowers it

Special category data, financial detail, home addresses, combinations, an unknown recipient. Against: genuine encryption, prompt recovery with confirmation, narrow exposure to one person who reported it.

Two thresholds, not one

Likely to result in a risk: notify the regulator. Likely to result in a high risk: also tell the people affected. The second is a higher bar and is met more often than organisations want.