Compliance

Data Breach Severity Calculator

Estimate the severity of a personal data breach using the ENISA methodology based on data processing context, ease of identification and circumstances.

Last reviewed by the Radiatus Cloud team

Estimate personal data breach severity using the ENISA methodology.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Estimate data breach severity

When a personal data breach occurs, assessing its severity guides how to respond and whether it must be reported. This calculator uses the methodology published by ENISA, the European agency, which computes a severity score from three factors: the data processing context, reflecting how sensitive the data is; the ease of identification, how easily individuals can be identified from the breached data; and the circumstances of the breach, such as whether confidentiality, integrity or availability were affected and whether it was malicious.

The score is the data processing context multiplied by the ease of identification, plus the circumstances factor, and it maps to severity levels from low to very high.

Responding to breaches

Breach severity informs the critical decisions after an incident: whether to notify the supervisory authority within seventy-two hours, as the GDPR requires for breaches likely to risk individuals rights, and whether to inform the affected individuals. A structured, repeatable scoring method supports consistent, defensible decisions and documentation. Higher severity generally means a stronger case for notification and more urgent remediation.

This is a structured estimate to support your assessment, not a substitute for a full evaluation of the specific circumstances and legal obligations. All calculation happens locally in your browser.

Related tools

Frequently Asked Questions

What is the ENISA breach severity formula?

Severity equals the data processing context multiplied by the ease of identification, plus a circumstances factor, giving a score mapped to severity levels.

What is the data processing context?

It reflects how sensitive the breached data is, from simple data up to sensitive categories like health or financial information.

How does severity affect reporting?

Higher severity strengthens the case for notifying the authority within seventy-two hours and informing affected individuals under the GDPR.

Is this a substitute for a full assessment?

No. It is a structured estimate to support your evaluation, not a replacement for assessing the specific circumstances and legal duties.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Choose the three factors to compute the severity score.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.