Risk & Accountability
Data Protection Risk Assessments for Small Businesses
How Jamaican MSMEs can assess privacy risk proportionately, what increases risk, and how to turn a risk register into real action.
What you will learn
- Why not all personal data creates the same risk
- What factors increase privacy risk
- How to weigh impact and likelihood
- Why a risk register must lead to action
A mailing list containing first names and email addresses does not necessarily present the same privacy risk as a database containing medical records, biometric identifiers or financial information. Privacy risk management should therefore be proportionate.
What increases risk?
Examples include:
- sensitive personal data;
- children or vulnerable individuals;
- large numbers of records;
- financial information;
- identification documents;
- biometric information;
- international transfers;
- numerous third parties;
- weak access controls;
- long retention;
- automated processing; and
- internet-accessible systems.
Think about impact and likelihood
For each risk, ask: what could happen? How likely is it? How serious would the consequence be? What controls already exist? What additional action is needed?
Example
- Risk: Payroll spreadsheet emailed to an unauthorised recipient.
- Potential impact: Disclosure of salary and banking information.
- Existing controls: Password-protected file.
- Additional measures: Secure file-sharing platform, access controls and staff training.
- Owner: Finance Manager.
- Review: Quarterly.
A risk register should create action
A risk assessment that produces a score and then sits unused is of little value. Every material risk should have an owner, action, due date and status.
Put this into practice
Identify, score and assign owners to your privacy risks with clear actions.
Assess My Privacy Risks Coming soonFrequently asked questions
Key takeaways
- Privacy risk management should be proportionate to the data involved.
- Sensitive data, children, large volumes and weak controls all increase risk.
- For each risk, weigh what could happen, how likely it is and how serious it would be.
- Every material risk should have an owner, an action, a due date and a status.
