PERSONAL RESEARCH / THREAT CATALOG
Elementary threats
to data protection.
Twenty-one proposed threats that give a more specific view of personal-data misuse.
Open an entry to read more. Keep several open to compare them.
G DP.01Disclosure of personal dataInformation about a person becomes visible to people who should not receive it.
Exposure can stem from mistakes, insecure settings or attacks in digital and paper-based processes. It compromises the confidentiality of the affected personal data.
LINK TO THIS THREATG DP.02Unauthorised access to personal dataA person or system obtains personal information without the required permission.
Weak access controls, compromised credentials or vulnerabilities can permit retrieval outside an authorised role. Access is a distinct event even if the information is not subsequently disclosed.
LINK TO THIS THREATG DP.03Unauthorised alteration of personal dataExisting personal records are changed in ways that undermine their accuracy or reliability.
Deliberate manipulation, software faults or operating errors can corrupt data without being noticed. Decisions based on the altered records can then disadvantage the person concerned.
LINK TO THIS THREATG DP.04Loss or destruction of personal dataPersonal information becomes unavailable or cannot be recovered.
The event can involve permanent destruction or temporary loss of access. Technical failures, deletion, malware or physical damage can interrupt processing and the exercise of data subject rights.
LINK TO THIS THREATG DP.05Misuse of personal dataLegitimately obtained data are used within the controller for an unauthorised purpose.
Permitted access does not make every subsequent use appropriate. This entry concerns purpose-contrary use within the original processing context, rather than data leaving that context.
LINK TO THIS THREATG DP.06Unlawful disclosure or change of purpose in the processing of personal dataPersonal data are shared or repurposed without an appropriate legal basis.
The concern is departure from the original processing context. Further use needs to be compatible with the original purpose or supported by another legal basis.
LINK TO THIS THREATG DP.07Processing without knowledge or valid consentPeople are kept unaware of processing, or required consent is missing or invalid.
Information gaps and misleading consent processes can prevent informed choices. The consent aspect applies where consent is required for the processing.
LINK TO THIS THREATG DP.08Storage of personal data beyond the necessary periodPersonal records remain stored after the justified retention period has ended.
Missing retention rules or ineffective deletion processes can leave data available longer than necessary or permissible. Continued storage increases exposure to access, repurposing and misuse.
LINK TO THIS THREATG DP.09Loss of control over personal dataThe location, access and further use of personal data can no longer be traced.
Untracked copies and complex processing chains can obscure who holds or uses the information. The catalog treats this loss of control both as an event and as a dimension of harm.
LINK TO THIS THREATG DP.10Non-transparent processing of personal dataPeople cannot understand what happens to their data or why it is processed.
Unclear documentation and opaque processes hinder oversight and the exercise of rights. A formal notice can exist while the nature, scope and purpose of the processing remain unintelligible.
LINK TO THIS THREATG DP.11Restriction or violation of data subject rightsPeople cannot fully exercise the rights available to them over their personal data.
Missing processes, unclear responsibilities or system barriers can obstruct requests. The concern includes access, correction, erasure, restriction, objection and portability.
LINK TO THIS THREATG DP.12Limited erasability or technical immutabilityA system cannot completely remove or correct personal information.
Immutable storage or data memorised by models can make full removal technically difficult. This concerns the ability to erase or rectify, rather than a failure to act when deletion is possible.
LINK TO THIS THREATG DP.13Inadequate level of data protection in third-country transfersPersonal data are transferred outside the EEA without adequate protection.
The report includes processing and support access where effective safeguards are absent. Such transfers can undermine the affected person's ability to enforce their rights.
LINK TO THIS THREATG DP.14Unlawful profiling or behavioural analysisPersonal information is used to create intrusive or impermissible profiles of individuals.
Combining ordinary records can reveal sensitive characteristics or produce extensive behavioural profiles. The concern is inappropriate profiling and inference about individuals.
LINK TO THIS THREATG DP.15Fully automated decisions with significant effectsA system makes consequential decisions about people without human review of the individual case.
Legal or similarly significant effects make the absence of human scrutiny especially important. Poor data, faulty models and weak opportunities to challenge the decision can compound the risk.
LINK TO THIS THREATG DP.16Reconstruction of personal data from AI systemsPersonal information is inferred from an AI system rather than disclosed as an existing record.
Model queries and privacy attacks can reveal identifiable information or whether someone's data were used in training. This includes sensitive or pseudonymised information.
LINK TO THIS THREATG DP.17Generation of false personal data by AIAI produces new, inaccurate claims about an identifiable person.
Fabricated or misleading personal statements can influence later decisions. This differs from corrupting an existing record: the system generates the false assertion itself.
LINK TO THIS THREATG DP.18Identity theft or identity fraudSomeone uses personal data or identity attributes to impersonate another person.
Compromised accounts or synthetic imitations can enable deception and unauthorised acts. The catalog treats impersonation both as a distinct event and as a harm to the person.
LINK TO THIS THREATG DP.19Discrimination or disadvantage of individualsProcessing leads to unfair treatment or reduced opportunities for particular people.
Scoring, biased records or the choice of assessment criteria can disadvantage individuals. This can arise from how processing is designed, even without a technical bias in the model.
LINK TO THIS THREATG DP.20Reputational damage or social disadvantagePersonal information harms a person's reputation when it is exposed, misread or taken out of context.
Even a small fragment of data can affect social standing when redistributed in a new setting. The catalog treats reputational harm as both an event and a consequence when assessing severity.
LINK TO THIS THREATG DP.21Economic or societal disadvantagePersonal-data processing causes financial loss or reduces a person's opportunities.
This entry focuses primarily on the harm experienced by the individual. It is treated as an event only where the disadvantage results directly from processing.
LINK TO THIS THREATREFERENCES / 05
Sources and basis.
Selected references cited in my version 1.0 report. The threat grouping and working identifiers are my own proposal.
LINKS CHECKED /
- EU — General Data Protection Regulation (opens in a new tab)
Regulation (EU) 2016/679 · 27 April 2016
Legal foundation: processing principles, data subject rights and risks to rights and freedoms (Recital 75; Articles 5, 13–22, 32–35 and 44–46).
- BayLfD — Risikoanalyse und Datenschutz-Folgenabschätzung (opens in a new tab)
Systematik, Anforderungen, Beispiele · v1.0 · 1 May 2022
Protection goals and a method for assessing risks to individuals. Pages 19–20 and 29–33 provide the SDM protection-goal framework used in the proposal.
- Isabel Barberá — AI Privacy Risks & Mitigations: Large Language Models (opens in a new tab)
EDPB Support Pool of Experts · author report updated March 2025
Privacy risks across the LLM lifecycle, including repurposing and barriers to data subject rights (pp. 25, 53–56 and 60). This is an expert report under the SPE program, rather than adopted EDPB guidelines.
- ISO/IEC — Guidelines for privacy impact assessment (opens in a new tab)
ISO/IEC 29134:2017 · consulted adoption: BS EN ISO/IEC 29134:2020
Privacy impact assessment and scenarios of unauthorised access, alteration and loss (pp. 47–49 of the consulted edition). This historical edition informed the report; ISO/IEC 29134:2023 supersedes it. The full standard requires access through its publisher.
- BSI — Generative KI-Modelle: Chancen und Risiken für Industrie und Behörden (opens in a new tab)
Version 2.0 · 17 January 2025
Technical privacy attacks: reconstruction of training data and embedding inversion (R22 and R23). Their data-protection classification is my synthesis.