Join our Newsletter — 33% off our NHI Course

Problematic Data Action

A problematic data action is a data collection, use, sharing, storage, or processing activity that creates privacy harm or increases the chance of adverse events. The concept focuses attention on both the action itself and the likelihood of harm, which helps organisations assess risk more realistically than by policy checks alone.

What Makes a Data Action Problematic

A data action becomes problematic when the activity itself, not just the surrounding policy, increases the chance of privacy harm. That can include collecting too much, using data in unexpected ways, sharing it too broadly, retaining it too long, or processing it in a way that raises the likelihood of adverse outcomes.

The useful idea here is that the action is judged by its real-world effect. A technically permitted process can still be problematic if it creates avoidable exposure, weakens user expectations, or makes downstream misuse more likely.

Why the Harm Likelihood Matters

The term shifts attention from a binary compliant versus non-compliant view toward a more realistic assessment of risk. An action may be low concern in one context and problematic in another if the data is sensitive, the audience is broader than expected, or the processing outcome is hard to predict.

This matters because privacy harm is often cumulative. A single collection or sharing step may seem minor, but repeated use across systems, inference from multiple sources, or retention beyond the original purpose can make the overall exposure materially worse.

Common Patterns Behind Problematic Data Actions

Problematic data actions often show up as overcollection, purpose drift, excessive retention, uncontrolled sharing, or secondary use that was never clearly justified to the person or organisation involved. They can also appear when processing is technically lawful but still creates disproportionate exposure.

These patterns are especially important where the data can be combined, linked, or repurposed. In those cases, the action itself may be the source of harm even before any breach or misuse occurs.

  • Collecting more data than is needed for the stated purpose.
  • Using data for a new purpose that is difficult to explain or justify.
  • Sharing data with parties that do not need the full detail.
  • Keeping data longer than the operational need requires.
  • Processing data in ways that increase the chance of reidentification, profiling, or unwanted exposure.

How Organisations Should Interpret the Term

For practitioners, the value of the term is that it encourages closer review of the actual data action and its likely consequences, rather than relying only on policy checkboxes. That means asking whether the activity is necessary, proportionate, expected, and defensible in context.

It also supports better governance conversations. A team may be able to describe why a processing step exists, but still need to justify why that step should continue if it increases the probability of harm. In that sense, the term is a useful lens for review, not just a label for violations.

Risk and Threat Considerations

Problematic data actions create risk because they expand the surface for privacy harm even when no single event looks severe on its own. Excessive collection, broad sharing, and long retention can increase exposure, widen the impact of a later breach, and make harmful downstream use more likely.

Failure mechanism: The action creates unnecessary data persistence, reuse, or disclosure paths, which increases the chance that data will be misused, inferred, linked, or exposed beyond the original expectation.

Impact: Organisations can face privacy injury, trust loss, regulatory scrutiny, and larger blast radius if the same data is later compromised or repurposed in a way that affects more people or more sensitive attributes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while GDPR defines the regulatory obligations.

Framework Control / Reference Relevance
GDPR A.5.15 — Data Protection by Design and by Default Addresses designing processing to minimise privacy harm from the action itself
A.5.1 — Lawfulness, Fairness and Transparency Directly governs whether the data action is justified and understandable to affected people
Recommendation — Apply data protection by design to reduce collection, use, sharing and retention to what is necessary. Assess whether each processing action is lawful, fair and transparent before you proceed.
NIST SP 800-53 Rev 5 PT-2 — Authority to Process Personally Identifiable Information Requires defined authority for processing that can create privacy harm if not controlled
PT-5 — Privacy Notice Supports disclosure of how data will be collected, used, shared and retained
PT-9 — Individual Data Lifecycle Management Covers collection, use, retention and disposal decisions that define a problematic data action
Recommendation — Define and document the authority for each sensitive data processing activity. Provide clear notice that matches the actual data action and its intended use. Set lifecycle rules that limit retention, use and disposal to the approved purpose.
NIST CSF 2.0 PR.DS-01 — Data-at-rest is protected Protects stored data whose retention or storage can increase privacy exposure
GV.OC-03 — Legal, regulatory, and contractual requirements are understood and managed Anchors review of whether a data action creates privacy obligations or prohibited exposure
Recommendation — Protect stored data and limit where retained data can be exposed. Map each problematic data action to the legal and contractual obligations it must satisfy.

Practitioner Guidance

Why practitioners should care: This term is useful when a team needs to decide whether a data practice is merely permitted or actually defensible in context. It pushes review beyond policy compliance and toward proportionality, necessity, and likely harm.

What to watch for: Pay close attention when a data action changes audience, purpose, retention, or sensitivity. Those are the points where a routine process often becomes difficult to justify and where privacy risk tends to accumulate.