ROPA Risk Assessment

WORKING REGISTER
GDPR Art. 30 · ISO 27001/27701/27017/27018

A live reference for the risk-rating step of each processing entry — not a substitute for the ROPA itself. Screen for DPIA triggers, rate residual risk to data subjects, trace it back to your ISMS/PIMS controls, then export the summary in Section 5 as evidence for the ROPA entry.

01

DPIA screening

Art. 35(3) mandatory triggers plus the WP248 rev.01 / EDPB nine criteria. Two or more criteria checked → DPIA flag. Any single item marked "mandatory" triggers a DPIA regardless of count. GDPR Art. 35(3), 35(4) · WP248 rev.01

No criteria selected
Check the criteria that apply to this processing activity.
0
02

Risk-to-data-subject rating

Below the DPIA threshold, this is the rating that populates the ROPA risk column — likelihood × severity of harm to the individual, not to the organisation. Keep this separate from your ISMS CIA risk score. Recital 76 · ISO/IEC 27701 §5.4.1.2

Classification rubric — weighted, not summed. Severity follows ENISA's published breach-severity formula directly: sensitivity and identifiability multiply (a highly identifiable but low-sensitivity dataset shouldn't score the same as a moderately identifiable, highly sensitive one), and aggravating circumstances add on top only if present. Likelihood has no published ENISA equivalent — it's built here by the same structural logic (control weakness × threat capability, plus additive amplifiers) rather than adopted from a standard, and is flagged as such. Override the matrix manually if judgment differs. ENISA, Dec. 2013 — SE = DPC × EI + CB

Severity

SE = DPC × EI + CB — sensitivity × identifiability, plus aggravators.
Data / impact criticality (DPC) ×1–4
Ease of identification (EI) ×0.25–1
Aggravating circumstances (CB) + if present
Severity tier SE = —

Likelihood

LI = weakness × capability + amplifiers — structural analogy, not an ENISA standard.
Control weakness ×1–4
Threat source capability & motivation ×0.25–1
Contextual amplifiers + if present
Likelihood tier LI = —

Matrix highlights from the rubric above. Click any cell directly to override.

Severity of impact on data subject →
Resulting rating
Select a cell
Answer the rubric or click a cell directly to see the suggested treatment and documentation action.
03

Framework crosswalk

Where each step of the ROPA risk process is picked up by your existing certifications, so you're not building parallel documentation.

StepGDPRISO coverage
04

Recommended ROPA risk fields

Beyond the Art. 30(1) minimum, these are the fields that make the risk rating auditable rather than decorative.

05

Executive summary & reasoning

Auto-generated from your answers in Sections 1–2 above. Add identifying fields for this processing activity below, then export as PDF to attach to the ROPA entry as evidence of this assessment.

DPIA screening

Not yet completed — see Section 1.

Severity

Not yet rated — see Section 2.

Likelihood

Not yet rated — see Section 2.

Overall rating & recommended action

Complete the screening and rubric above to generate a rating.