Zum Hauptinhalt springen

Create and answer a risk analysis – methodology, assessment and risk level

A risk analysis implements the risk-based approach of Art. 24 and 32 GDPR. preeco separates „Edit" (the methodology: events, damages with criteria, risk levels) from „Answer" (the actual assessment with probability of occurrence and severity of impact). After answering, preeco automatically computes the risk level – the highest level triggers a data protection impact assessment under Art. 35 GDPR.

Last updated:
Video transcript
In this video we create and answer a risk analysis in preeco | datenschutz – the risk-based approach of Articles 24 and 32 GDPR. In „Risk analyses“ you see all of your team's assessments with status, link and last answer. Start new analyses via „New“ – ideally „Load from sample documents“. preeco separates two steps: „Edit“ maintains the methodology, „Answer“ records the actual assessment. Under „General“ the analysis is linked to what is assessed – here the processing activity „Bewerbermanagement“. In „Events“ you define risk types with a type: risk matrix, rating or yes/no. Under „Damage assessment“ you assess damages such as discrimination – via criteria per event. The risk levels – low, medium, high – each get a threshold. The highest level triggers a DPIA under Article 35. Once the analysis is released, you record the assessment via „Answer“. Per event you choose the probability of occurrence – from negligible to maximum. Per criterion you enter the severity of impact – or use rating or yes/no for other types. From the answers, preeco automatically computes the risk level – here a medium risk level – and records the assessment as a revision. With AI and your team.

A risk analysis demonstrates that the risks of a processing operation for the rights and freedoms of data subjects were assessed in a structured way – the risk-based approach of Art. 24 and 32 GDPR. preeco | data protection separates two steps: the methodology (Edit) and the actual assessment (Answer).

  1. Create a risk analysis: In the left menu under „Risks" click „Risk analyses". Via „New" you start an analysis – easiest with „Load from sample documents", which ships proven events, damages and risk levels.
  2. Link what is assessed: Under „General" choose the link type and „Linked to" – usually a processing activity. This anchors the assessment to the concrete operation.
  3. Maintain events, damages and risk levels (Edit): In „Events" you define risk types with the type risk matrix, rating or yes/no. Under „Damage assessment" you add damages such as discrimination and attach an event to each criterion. The „Risk levels" (low, medium, high) each get a threshold.
  4. Release: After saving, you release the analysis. The „Answer" button only appears once the status is „Released".
  5. Answer: Via „Answer" you choose the probability of occurrence per event (negligible to maximum) and the severity of impact per criterion; other types are answered via rating or yes/no.
  6. Result: From the answers, preeco automatically computes the risk level and stamps „Last answered". The assessment is recorded as a revision. If the analysis reaches the highest risk level, this triggers a data protection impact assessment (DPIA) under Art. 35 GDPR.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.