Leadership and readiness
Data sharing risk assessment template for external releases
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A data sharing risk assessment template rates a proposed external release on five factors: personal data, confidential business information, competitive sensitivity, contract restrictions and the recipient's security. Each factor is rated low, medium or high, with evidence and a mitigation. Any high rating that survives mitigation stops the release until counsel and the approver decide.
Key takeaways
- Rate five factors separately: personal data, confidential information, competitive sensitivity, contract restrictions and recipient security.
- Every rating needs attached evidence, and every rating above low needs a recorded mitigation.
- Ratings are never averaged; one unmitigated high rating stops the release.
- Accepted residual risk is signed in writing by the approver, with the reason.
- A change of recipient, purpose, fields or date range requires a fresh assessment.
When should you use a data sharing risk assessment?#
A data sharing risk assessment belongs before any external release that goes beyond routine processing by your service providers: a data license, a research collaboration, a pilot with an outside company or a vendor evaluation using real records. It takes the request from the approval workflow and asks what could go wrong and what the company will do about it.
The template is deliberately lighter than a formal data protection impact assessment. Where laws such as GDPR may require a formal assessment for high-risk processing, counsel decides whether one is needed, and this template feeds into it rather than replacing it.
Header fields for the template#
The header fields pin down exactly what is being assessed, so a rating can never drift away from the release it describes. Copy them from the approval request wherever possible.
- Release ID matching the approval workflow entry.
- Requester, business sponsor and assessor, with the assessment date.
- Recipient legal entity, its location and any subprocessors it will use.
- Purpose and permitted use, including whether model training is allowed.
- Systems, record families, fields and date range in scope.
- Format, delivery method and where the recipient will store the data.
- Term, deletion terms and how deletion will be confirmed.
- Name of the approver who will sign the decision.
The five scored factors#
The template rates five factors as low, medium or high: personal data, confidential business information, competitive sensitivity, contract and rights restrictions, and recipient security. Use the descriptions below so different assessors rate the same release the same way.
Rate the release as it will actually leave the company, after the planned preparation, and keep the rating before preparation on file too. The gap between the two shows the approver how much of the risk depends on preparation working as intended, which is exactly where sampling and review effort should go.
| Factor | Low | Medium | High |
|---|---|---|---|
| Personal data | None present after preparation | Pseudonymized identifiers or residual names in free text | Direct identifiers, sensitive categories or records about individuals at scale |
| Confidential business information | Routine operational content | Internal process detail, product plans, vendor terms | Pricing, margins, unreleased plans, trade secrets |
| Competitive sensitivity | Nothing that identifies customers or strategy | Patterns that hint at key accounts or markets | Customer identities, volumes per account or named win-loss reasons |
| Contract and rights restrictions | Company-created records with no conflicting terms | Terms that allow use with conditions | Confidentiality or ownership terms that may prohibit the use |
| Recipient security | Documented controls, independent reports, clear deletion process | Partial documentation or a new vendor | No documentation, unclear storage or onward sharing |
Evidence and mitigations for each factor#
Each rating needs evidence behind it and, for anything above low, a mitigation that could bring it down. Ratings without evidence are opinions, and opinions are hard to defend when a customer or regulator asks later.
| Factor | Evidence to attach | Typical mitigations |
|---|---|---|
| Personal data | Field list, detection tool output, signed review sample, re-identification analysis for structured fields | Remove, pseudonymize, generalize or exclude |
| Confidential business information | Classification from the approval workflow, records owner sign-off | Remove the fields or exclude the record family |
| Competitive sensitivity | Deny-list search results, account manager review | Tokenize accounts, generalize locations, exclude dominant customers |
| Contract and rights restrictions | Counsel's rights memo citing the reviewed contracts and notices | Exclude restricted accounts, obtain consent, narrow permitted use |
| Recipient security | Security questionnaire, independent audit reports such as SOC 2, deletion process | Contractual security terms, restricted access, deletion certificates |
Measuring re-identification risk instead of guessing#
Re-identification risk in structured fields can be measured, which turns the personal data rating into something closer to evidence. The measures look at how many records share the same combination of details, such as job title, city and date, because rare combinations are what let someone pick out a person.
Mainstream cloud tooling includes these measures. Google's Sensitive Data Protection API, for example, offers k-anonymity, l-diversity, k-map and delta-presence analysis, and notes that the last two are estimated with statistical models because the attacker's own data is unknown. Free text still needs human review, since these measures apply to columns, not narratives.
How ratings become a decision#
Ratings become a decision through fixed rules, never an average. One high rating is not offset by four lows, because a single uncontrolled risk is enough to cause the harm the assessment exists to prevent.
All low: the approver can sign. Any medium: record the mitigation, apply it and re-rate. Any high that remains after mitigation: stop the release and escalate to counsel and the CEO. If leadership decides to accept a residual risk, the approver records that acceptance in writing, with the reason, on the assessment itself.
Re-run the assessment whenever the recipient, purpose, fields or date range change. An approval covers the release that was assessed, not a later variation of it.
Illustrative: a staffing firm assesses its placement records#
Illustrative: a fictional professional staffing firm keeps job orders, candidate submissions, interview feedback and placements in Bullhorn. A licensing conversation centered on how its recruiters matched requirements to roles, so the general counsel first assessed the full requested scope.
Personal data rated high: candidate resumes, interview notes and contact details sat at the center of the records, and preparation could not reliably strip identities from resumes. Competitive sensitivity rated medium because client names ran through the job orders. Contract restrictions rated medium after counsel found client terms limiting use of job descriptions in some agreements.
The decision was to drop candidate records entirely and assess a narrower scope: job orders and role requirements with client names tokenized and restricted clients excluded. The narrower scope rated low or medium on every factor, the mitigations were recorded and the approver signed the revised release.
How SourceX documents release risk#
The SourceX five-step transaction addresses the same questions in its Rights and Preparation steps, and the supplier approves the outcome before Delivery. A supplier's own risk assessment can sit alongside that process as its internal record.
For each approved package, the SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization. Filing the completed assessment with it gives counsel one place to show what was considered and why the release went ahead.
Frequently asked questions
Is this the same as a DPIA?
No. A data protection impact assessment is a formal process that laws such as GDPR may require for certain high-risk processing, with specific required content. This template is an internal triage tool for external releases. Counsel decides whether a formal assessment is also needed for a particular release.
Who should complete the assessment?
The records owner or project lead usually drafts it, because they know the systems and the request. Counsel reviews the contract and personal data ratings, IT supplies tool output and samples, and the authorized approver signs the final decision. Keep the assessor and the approver separate.
How do we rate a recipient's security without auditing them?
Use what the recipient can document: a security questionnaire, independent audit reports where available, storage locations, access controls, subprocessors and its deletion process. Gaps in that documentation are a signal in themselves, and contract terms can require specific controls and deletion certificates where evidence is thin.
How long should completed assessments be kept?
Keep each assessment with the release log entry and the agreement for as long as the license and its obligations last, then follow your retention schedule. A completed assessment is evidence of the care the company took, which matters if a question comes up after the release.
Can one assessment cover several releases to the same recipient?
Only if the purpose, fields, date range and terms are identical. Any change means a new or updated assessment. A practical approach is to keep a base assessment of the recipient's security and update the other four factors for each release.
What if the recipient will not answer security questions?
Treat the refusal as a high rating for recipient security until the gap is closed. Some recipients share audit reports only under an NDA, which is reasonable. A recipient that will not describe storage, access or deletion at all is asking the company to accept a risk it cannot see.
Sources
- Google's Sensitive Data Protection API offers four re-identification risk-analysis metrics, k-anonymity, l-diversity, k-map estimation and delta-presence estimation, and notes that k-map and delta-presence are estimated with statistical models because the attacker's dataset is unknown. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.