A critical indicator would show when
either inherent, residual, or behavioural risk is defined as Critical. This
means one of the risk indictors shows an issue with the information captured or
shows a potential problem with your processes and requires immediate focus.
If your Inherent risk is Critical, this means your company holds a high volume of
personal information some of which may relate to GDPR members or children.
Typically, there is nothing that can be done
to resolve this, but it may help to check retention periods of documents as
stated on retention policy as well as ensuring your residual risk is lower and
shows your control measures are sufficient.
If your residual risk is critical, this indicates a huge issue and immediately action is required to safeguard
the information in your possession by applying control measures.
If your behavioural risk is critical, this may mean you are not complying to seven pillars of lawful
processing. This should be investigated, and measures taken to ensure you take
these several measures into account in your company’s processes.