Mino / Learn
← All guides

Compliance

De risk ladder: laat zien welk risico nu telt en welk kan wachten

Vijftien compliance-issues, één budget. Een prompt die je impliciete prioritering expliciet maakt — zodat een cliënt ziet waarom je € 50k hier uitgeeft en € 5k daar uitstelt.

Sjors Dobbelaar ·18 December 2025

Your client is launching a new data-processing feature. You have flagged fifteen GDPR issues. The CEO asks the only question that matters to them: “which ones do we handle first?”

You know the answer. After fifteen years advising founders, prioritising risk is reflex. But explaining why the cross-border transfer mechanism is more urgent than the privacy-policy footer — in a way a non-lawyer can act on — takes time you do not have in the meeting. So the conversation collapses into one of two unhelpful shapes: everything is urgent, or you make gut calls without showing the reasoning. The first paralyses; the second breeds mistrust.

The fix is to make the prioritisation you are already doing in your head systematic and visible. The model does not know GDPR better than you. Its value is that it works through your list, makes the hierarchy explicit, and has no professional-liability anxiety pushing it to hedge — so the output is clear enough for a client to spend a budget against.

The prompt

Organise the compliance risks below into a risk ladder, highest to
lowest priority.

Context:
[company, what they're doing, which regime applies, the issues you've
identified]

Use four tiers:

TIER 1 — CRITICAL: material liability or clear violations with real
enforcement odds; do this before launch.
TIER 2 — SERIOUS: gaps that grow with scale or surface under audit;
address before expansion.
TIER 3 — STANDARD: best practice that should be fixed but isn't urgent.
TIER 4 — MINIMAL: technical non-compliance with very low practical risk;
defer or monitor.

For each risk: explain the placement, note what would move it up or down
(scale, visibility, other factors), and give a rough timeline.

Be honest about what actually matters versus what's theoretically
required.

What it produces

Feed it a 50-person SaaS company adding usage-data analysis for personalised recommendations, with a €75k budget and eight issues — from missing DPAs through an incomplete legitimate-interest assessment to a vague data-retention period.

The ladder sorts them. Tier 1: the legal basis for the new processing is unclear, and a US sub-processor handles EU data without updated SCCs — both block launch. Tier 2: no DPIA has been done, and the privacy policy is too generic for the new feature; serious, but they follow within 30 to 60 days. Tier 3 and 4 are the rest — incomplete documentation, employee training, retention wording — real hygiene, but not what a regulator targets first. Crucially, each entry says what would move it: if the recommendations start influencing pricing or access, the DPIA jumps to Tier 1; if marketing starts using the insights without consent, that minimal item becomes critical.

Now the client conversation is concrete: “spend the budget on the DPAs and the transfer mechanism before launch, the DPIA and policy update in the first two months, the rest on normal timelines — here is why.”

When to use it

When budget is tight and the client needs to understand why €50k here and not €5k there. When multiple issues compete and sequencing matters. When a CFO is questioning your advice and wants to see the reasoning. And when a startup has to launch but cannot fix everything at once — the ladder is what lets them launch responsibly instead of either recklessly or not at all.

The earlier you run it the better, while the client still has room to make informed trade-offs. You are not outsourcing the judgement. You are putting it in a form a non-lawyer can actually use.