KVKK obliges the data controller to take "appropriate technical and administrative measures" to prevent the unlawful processing of and access to personal data. But the word "appropriate" is relative: a measure that suffices for one company may be inadequate for another that processes higher-risk data. This relativity can only be made objective through a systematic risk assessment. A risk assessment makes measurable how much protection each dataset needs and documents the rationale for the controls chosen. This guide offers a principle-based and repeatable five-step method.
Why a Risk-Based Approach?
With limited budget and time it is impossible to protect every dataset with equal intensity. A risk-based approach lets you direct resources to the areas with the highest potential for harm. It also provides, after a data breach, a documented logic showing "why the measures were deemed sufficient." This is both a requirement of the accountability principle and the strongest defense in a possible audit.
Step 1: Asset and Data Inventory
The precondition for measuring risk is knowing what you are protecting. In this step all personal-data processing activities and the assets that hold them (servers, databases, laptops, cloud services, physical files) are listed. For each record the following is clarified:
- The category of data processed (identity, contact, health, financial, etc.)
- The sensitivity level of the data (is there special-category data?)
- Where the data is stored and who accesses it
- The parties to whom transfers are made (domestic/international)
The inventory also overlaps with registry obligations and forms the foundation for all subsequent steps.
Step 2: Threat and Vulnerability Analysis
For each asset, the threats that could affect it (e.g. unauthorized access, ransomware, human error, physical theft, insider threat) and the vulnerabilities those threats could exploit (e.g. weak password policy, unpatched software, lack of access control, untrained staff) are identified. A risk materializes only when a threat meets an existing vulnerability. Threat-vulnerability pairing is therefore the heart of the assessment.
Step 3: Likelihood Assessment
In this step the likelihood of each threat-vulnerability pair occurring is rated. A simple and repeatable scale (e.g. 1-Low, 2-Medium, 3-High) is sufficient. Likelihood is determined by the strength of existing controls, the frequency of the threat and the exploitability of the vulnerability. For example, the likelihood of unauthorized access to an internet-facing system without multi-factor authentication is high.
Step 4: Impact Assessment
Impact is the magnitude of harm the risk would cause to data subjects and the organization if it materialized. The assessment should consider not only organizational harm (fines, reputational loss) but, first and foremost, the harm that could befall data subjects (discrimination, financial loss, identity theft, privacy violation). The impact of special-category data is usually rated higher. Impact uses the same scale (1-3) as likelihood.
Step 5: Risk Score and Controls
In the final step the likelihood and impact values are combined to calculate the risk score. The common method is multiplication: Risk Score = Likelihood × Impact. The resulting score lets you prioritize risks. There are four strategies for each risk: mitigation (applying controls), transfer (e.g. insurance), avoidance (stopping the activity) or acceptance (documenting and accepting low risks). Technical and administrative controls are deployed for high-scoring risks, and the remaining (residual) risk is reassessed.
Risk Score Matrix
| Likelihood \\ Impact | 1 - Low | 2 - Medium | 3 - High |
|---|---|---|---|
| 2 - Medium | 2 (Low) | 4 (Medium) | 6 (High) |
| 1 - Low | 1 (Low) | 2 (Low) | 3 (Medium) |
Implementation Checklist
- Inventory all processing activities and assets.
- Pair threats and vulnerabilities for each asset.
- Rate likelihood on a consistent scale.
- Assess impact primarily through harm to the data subject.
- Calculate the risk score (likelihood × impact) and prioritize.
- Choose a control strategy (mitigate/transfer/avoid/accept) for each high risk.
- After applying controls, re-measure residual risk and repeat the cycle periodically.
Example Scenario
An e-commerce company keeps customer credit-card and address details in a database. The inventory (Step 1) surfaces this asset. Analysis (Step 2) shows the database is internet-facing and lacks encryption; the threat is unauthorized access and the vulnerability is the missing encryption. Likelihood is rated high (3). Because financial data is involved, impact is also high (3). The risk score comes out at 9 (critical). The company chooses the mitigation strategy: it moves the database inside the network, encrypts the data and adds multi-factor authentication. On reassessment likelihood drops to 1, the residual risk score falls to 3 (medium) and is documented.
Frequently Asked Questions
How often should a risk assessment be done?
As a principle, at least once a year and additionally on significant changes (new system, new processing activity, after a data breach). A risk assessment is not a one-off document but a continuous cycle.
Are complex tools essential for a small business?
No. The five-step method can be applied even with a simple scale (1-3) and a table. What matters is consistency and documentation, not the complexity of the tool.
What should I prioritize when assessing impact?
Focus first on the harm that could reach data subjects (privacy, discrimination, financial loss). Organizational harm matters, but KVKK's protective priority is the data subject.
Can I ignore low risks?
Rather than ignoring them, you should consciously "accept" them. Accepted risks must also be documented for accountability.
This content is for general information purposes only and does not constitute legal advice.
With JUS. you can run the entire assessment process from inventory to risk score and controls on a single dashboard; request a demo.