Return on Control (RoC) in GDPR Context
1. Definition of RoC
- RoC measures the effectiveness of a security or privacy control compared to its cost.
- It quantifies the reduction in risk exposure (both likelihood and impact) achieved by implementing a control versus the investment made.
- In ISO/IEC 27005 terms, it's a way of evaluating risk treatment options not only on qualitative grounds but also on economic efficiency.
In GDPR terms, RoC helps organizations justify that their implemented technical and organizational measures (Art. 32 GDPR) are:
- Proportionate to the risk to personal data.
- Effective in reducing residual risk to an acceptable level.
- Efficient in resource allocation.
2. Formula (simplified)
Where:
- Inherent risk = baseline exposure without the control.
- Residual risk = remaining exposure after control.
- Cost of control = financial and operational investment.
3. Practical GDPR Examples
Example 1: Encryption of Customer Data
- Inherent Risk: High likelihood of data breach if laptop is stolen (impact: €500,000 fines + reputational damage).
- Residual Risk: Encrypted laptop reduces breach impact to negligible (€10,000 possible IT costs only).
- Cost of Control: €50,000 annual investment in encryption licenses and training.
High RoC. Encryption is a proportionate and justified GDPR control.
Example 2: Multi-Factor Authentication (MFA) for Employee Systems
- Inherent Risk: Unauthorized access to HR system → possible GDPR fine of €1 million.
- Residual Risk: With MFA, risk is reduced to €50,000 (e.g., phishing bypass).
- Cost of Control: €150,000 implementation.
Strong RoC, control should be prioritized.
Example 3: Biometric Access to Data Centre
- Inherent Risk: Unauthorized access by intruders → €5 million potential impact.
- Residual Risk: Reduced to €4.5 million (intrusion risk remains but lower).
- Cost of Control: €2 million setup + €0.5 million yearly maintenance.
Very low RoC. May not be proportionate under GDPR. Instead, stronger CCTV + access logs may provide a better RoC.
4. GDPR Relevance of RoC
- Accountability (Art. 5(2)): Organizations must show regulators that investments in controls are proportionate to the risks to data subjects.
- Data Protection by Design and Default (Art. 25): RoC helps select controls that embed privacy protections without waste.
- Data Protection Impact Assessments (Art. 35): RoC strengthens the justification for why certain controls were selected during high-risk processing.
✅ In summary:
RoC bridges ISO 27005's risk assessment with GDPR's accountability principle by providing a quantifiable measure of whether a control is both effective and proportionate in protecting personal data.