privacy *risk* is estimated differently - it takes into account the observed behaviours of an adversary - like the EU
the impact is also huge when the scaler is EU scale
the risk also includes the adversaries capabilities - which include future legislation