Skip to main content

Privacy Risk

Assess data actions that can create problems for people, then combine likelihood and impact without reducing privacy to breach risk.

Risk from data processing

Privacy risk is the likelihood that a data action creates a problem for people and the impact of that problem. Harm can include discrimination, exclusion, loss of autonomy, unwanted observation, identity exposure, economic loss, reputational damage, physical danger, or inability to use a service.

Privacy risk includes authorized processing. It is not limited to confidentiality breach.

Data action and context

Describe collection, generation, transformation, association, use, disclosure, retention, deletion, or observation. Identify people and groups affected, purpose, setting, scale, sensitivity, power relationship, reasonable expectations, recipients, and downstream decisions.

Map identifiers, metadata, derived data, inferred attributes, and repeated releases. Consider people who never use the system directly but appear in data or are affected by group decisions.

Likelihood and impact

Estimate likelihood from system behavior and contextual factors, not only malicious attack. A designed continuous collection has high likelihood even with perfect access control. Estimate impact from the person's perspective and include aggregation, persistence, inability to contest, and group effects.

Record uncertainty and disagreement. Avoid false precision in numeric scores. Prioritize high-impact irreversible or difficult-to-detect problems even when exact frequency is uncertain.

Failure and residual risk

Teams can mistake policy compliance for low risk or treat encryption as complete privacy protection. A risk register can omit derived data and downstream decisions. Benefits to the organization can obscure costs to individuals. People can lack practical choice or information.

A control can shift risk. Strong identity verification can reduce fraud and increase collection, exclusion, and irreversible biometric exposure.

Pomerium boundary

Pomerium can restrict access and produce evidence for covered routes. Operators still decide which identity and device attributes to request, how policy and logs use them, who receives claims, and how long systems retain them. Those authorized data actions need a privacy-risk assessment separate from access security.

Evaluation checklist

  • Which collection, association, inference, disclosure, retention, or decision can create a problem for which person or group?
  • Does likelihood include normal authorized operation, not only breach or attacker action?
  • Does impact include autonomy, exclusion, discrimination, observation, persistence, and inability to contest?
  • Which benefit and control cost fall on different parties?
  • What residual or shifted privacy risk remains after security, minimization, and user controls?

Sources and further reading

Keep learning

Security Engineering FoundationsSecurity Operations and Risk

Security Risk

Connect a credible threat, likelihood, consequence, uncertainty, and stakeholder impact to an explicit risk decision.

Learn this term
Privacy EngineeringCryptography and Data Protection

Personal Data and Metadata

Treat identifiers, device facts, access events, relationships, timing, locations, and derived attributes as personal when context can link them to people.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo