Assessing Risk to People
The assessment that determines whether to notify, and the one organisations instinctively get backwards by assessing risk to themselves.
RISK ASSESSMENT
Completed inside the window, attached to the record
- Data typeWhat exactly was exposedSpecial category changes everything
- SensitivityWhat could be done with itSalary and health are different from a work address
- VolumeHow many peopleScale affects likelihood of harm, not whether harm is possible
- IdentifiabilityCould individuals be identifiedEncrypted and unreadable is a different position
- RecipientWho received or accessed itA known colleague differs from an unknown party
- RecoveryWas it recovered, deleted, confirmedConfirmed deletion by a trusted recipient reduces risk genuinely
- Likely harmNamed, specificallyDiscrimination, distress, financial loss, identity fraud
- VulnerabilityAre any affected people particularly at riskAddresses of people at risk of violence, for instance
- ConclusionLikely risk, high risk, or neitherWhich determines notification to regulator and to people
Two assessments follow a breach. Whether to notify the regulator, and whether to tell the people affected. Both turn on risk to those people.
The breach workflow in “Assessing Risk to People” is easier to operate when systems, owners and evidence are known in advance. If view the solution supports step rate compensation, its records should sit inside the incident inventory with clear access, retention and escalation rules rather than being treated as an unexplained source of employee data.
The instinct to resist
The first question most organisations ask is how bad this is for us.
For a separate benchmark relevant to “Assessing Risk to People”, consult the AWS incident-response guide. Use it to test purpose, data flow, retention, access and response procedures rather than substituting a generic checklist for the organisation’s actual records.
That is a legitimate question and it is not this one. The test is about consequences for the individuals whose data was exposed, and an assessment framed around organisational exposure reaches the wrong answer in both directions — sometimes over-notifying out of caution, more often under-notifying because the business impact looks manageable.
What raises the risk
Special category data. Health, union membership, beliefs, sexual orientation, ethnicity. A breach involving these is materially more serious regardless of volume.
Financial detail, which enables fraud.
Home addresses, where anybody affected may be at risk from somebody.
Combinations. A name alone is low risk; a name with a salary, a home address and a performance rating is a different matter.
An unknown or untrusted recipient.
What lowers it
Encryption, where the data is genuinely unreadable to the recipient.
Prompt recovery with confirmation — a recipient who confirms deletion and is credible.
Narrow exposure: one colleague who reported it immediately is not the same as publication.
Named harms rather than general concern
The assessment should say what could actually happen: this person could be identified as having made a complaint; these salaries could be used in a dispute; this address could reach somebody from whom the person is hiding.
A general statement that there is a risk to privacy is not an assessment and reads as one that was not done.
The two thresholds
Likely to result in a risk: notify the regulator.
Likely to result in a high risk: also tell the people affected.
High risk is a higher bar and it is met more often than organisations want it to be, which is the subject of the next note.
Recording the decision not to notify
Where the conclusion is that the threshold is not met, the reasoning goes in the record with the same care as a notification.
A decision not to notify is the one most likely to be examined later, and the only defence is a contemporaneous assessment showing it was taken properly.
This person could be identified as having complained; these salaries could be used in a dispute; this address could reach somebody they are hiding from. A general statement that privacy is at risk reads as an assessment that was not done.
Recording a decision not to notify
With the same care as a notification. It is the decision most likely to be examined later, and a contemporaneous assessment is the only defence.
Assessing risk to them, not to you
The first question most organisations ask is how bad this is for us. Legitimate, and not this one. An assessment framed around organisational exposure reaches the wrong answer in both directions.
What raises and lowers it
Special category data, financial detail, home addresses, combinations, an unknown recipient. Against: genuine encryption, prompt recovery with confirmation, narrow exposure to one person who reported it.
Two thresholds, not one
Likely to result in a risk: notify the regulator. Likely to result in a high risk: also tell the people affected. The second is a higher bar and is met more often than organisations want.