In risk analysis and decision theory: Stochastic dominance is a method of comparing two uncertain outcomes (e.g., risk distributions) to see which is preferable. Instead of comparing only averages (expected value), stochastic dominance looks at the entire probability distribution of outcomes. A distribution A stochastically dominates distribution B if A is better (less risky or more beneficial) for all risk-averse decision makers.
1. What is Stochastic Dominance?
In risk analysis and decision theory:
- Stochastic dominance is a method of comparing two uncertain outcomes (e.g., risk distributions) to see which is preferable.
- Instead of comparing only averages (expected value), stochastic dominance looks at the entire probability distribution of outcomes.
- A distribution A stochastically dominates distribution B if A is better (less risky or more beneficial) for all risk-averse decision makers.
Example:
- Risk Profile A: 90% chance of a small loss, 10% chance of a medium loss.
- Risk Profile B: 70% chance of no loss, 30% chance of a severe loss.
Even if averages look similar, stochastic dominance helps determine which risk exposure is safer across all possible outcomes.
2. Stochastic Dominance in ISO/IEC 27005
ISO/IEC 27005:2022 (Information security, cybersecurity, and privacy protection — Information security risk management):
- Encourages organizations to use quantitative and qualitative methods to compare risk treatments.
- When multiple risk treatment options exist (e.g., stronger encryption vs. additional monitoring), stochastic dominance provides a structured way to choose the option with consistently lower risk across the probability distribution of outcomes.
- It helps avoid decisions based only on averages, which may mask “tail risks†(rare but catastrophic events).
3. Applicability to GDPR
GDPR requires controllers and processors to implement appropriate technical and organizational measures (Article 32) based on:
- The likelihood and severity of risks to rights and freedoms of natural persons.
- The principles of confidentiality, integrity, and availability (CIA).
Using stochastic dominance in GDPR compliance means:
- When choosing between different security measures (controls), organizations evaluate entire risk profiles to ensure that data subjects' rights are protected under all conditions, not just “on average.â€
- It supports Data Protection Impact Assessments (DPIAs) under Article 35, by providing a rigorous method to show regulators that chosen measures consistently minimize risks.
- It aligns with GDPR's accountability principle (Art. 5(2)), because decisions are documented with a structured, risk-based rationale.
4. Practical Example in GDPR Context
- Scenario: A healthcare provider must choose between two patient data storage solutions.
- Option A: Local servers with strong encryption, but some chance of physical damage.
- Option B: Cloud storage with redundancy, but some chance of service outage.
- Instead of only comparing costs or average downtime, stochastic dominance compares the probability distributions of data loss/availability impacts.
- If one option has a consistently lower probability of high-impact failures, it stochastically dominates and should be chosen — ensuring GDPR's requirement for “appropriate measures†is met.
✅ In summary:
- Stochastic dominance = method of comparing risk profiles using probability distributions.
- ISO/IEC 27005: Provides the risk management framework where this method can be applied to evaluate information security risk treatments.
- GDPR applicability: Ensures decisions on security and privacy controls minimize risks to data subjects' rights across all scenarios, not just in averages — supporting DPIAs, Article 32 security, and accountability.
1. The Legal Provision
Article 16 GDPR states:
“The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her.â€
So, controllers must correct inaccuracies promptly once notified by the data subject.
2. What Does “Undue Delay†Mean?
- Not defined numerically in GDPR, but interpreted as:
- “As soon as reasonably possible†in light of the context, risk, and resources.
- Controllers cannot stall or create unnecessary obstacles.
- The principle is about urgency — balancing operational feasibility with protecting the data subject's rights.
3. Timeline Guidance from GDPR and Supervisory Authorities
While GDPR does not fix a specific number of days for rectification, it aligns with timelines for data subject rights requests under Article 12(3):
- Controllers must respond to data subject requests “without undue delay and in any event within one monthâ€.
- This one-month period is considered the maximum reasonable timeframe.
- Extension: In complex or multiple requests, the deadline may be extended by two further months, but the data subject must be informed within the first month.
Therefore, in practice:
- Simple corrections (e.g., updating an address, phone number, or spelling mistake) should be done within days.
- Complex rectifications (e.g., involving linked systems, third parties, or large-scale datasets) may take longer, but should still be completed within one month unless a justified extension is communicated.
4. Practical Examples
- Banking: A customer notices their surname is misspelled. Correction should take a few days at most, since it's a simple administrative update.
- Healthcare: A patient requests correction of their allergy record. Rectification must be prioritized to protect health and safety — “undue delay†here means immediate action.
- Insurance: A client disputes financial records. Investigation across multiple systems may justify more time, but rectification should still be finalized within one month.
✅ Conclusion
- “Undue delay†= as quickly as possible considering urgency and complexity.
- Reasonable timeline:
- Simple rectifications → a few days.
- Complex/multi-system rectifications → within one month.
- Extensions (max +2 months) only if justified and communicated.
- Controllers should document actions and timelines to demonstrate compliance with the accountability principle (Art. 5(2)).