Templates / Data protection (GDPR) risk register template
Data protection (GDPR) risk register template
A data-protection risk register records the risks to personal data — breaches, over-collection, sending data to external AI models, biased automated decisions. The worked example below is free to download or open live, and supports GDPR accountability.
No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.
Worked example: data protection (gdpr) risk register template
| Risk | Category | Likelihood | Impact | Rating | Suggested remediation |
|---|---|---|---|---|---|
| Breach of personal or customer dataPersonal data about customers, users or staff is exfiltrated and leaked or sold, triggering notification duties and loss of trust. | legal | medium | high | Encrypt personal data at rest and in transit and apply least-privilege so only staff who need it can reach it. | |
| Sensitive data sent to an external AI modelPrompts, documents or records sent to a hosted model for inference leave your security boundary — retained in logs, exposed to the provider, or transferred across borders — even when the AI use is sanctioned. | legal | high | medium | Classify what may and may not be sent to an external model, and minimise or redact personal and confidential data in prompts. | |
| Biased or unfair AI outcomesAn AI system produces systematically worse or discriminatory outcomes for some groups — in hiring, pricing, eligibility or moderation — exposing people to harm and the organisation to legal and reputational risk. | legal | medium | high | Assess, before deployment, who the system affects and how it could cause unfair or discriminatory outcomes; record the risks and mitigations. | |
| Shadow or unsanctioned AI useStaff paste confidential documents, customer data or code into public AI tools to get work done faster, sending that data to a third party outside any agreement or oversight. | legal | high | high | Publish a short AI-use policy: which tools are approved, and the data categories that must never be pasted into a public service. | |
| Insider threat or misuse of accessA current or former staff member, contractor or privileged user misuses their access — to steal data, cause damage, or act carelessly — and the activity blends into normal work. | security | medium | high | Grant least-privilege access and review it regularly, especially after a role change; revoke everything promptly when someone leaves. | |
| Cloud misconfiguration or exposed storageA storage bucket, database or admin interface is left publicly reachable or without authentication through a configuration mistake, exposing data or a way in. | security | high | high | Build systems from a hardened, documented baseline that turns off public access and default credentials, and block deployments that drift from it. |
Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.
Questions
What is a data protection risk register?
A record of the risks to personal data your organisation holds — each rated and treated. It supports the accountability principle under GDPR and feeds Data Protection Impact Assessments.
Does GDPR require a risk register?
GDPR requires you to assess and mitigate risks to personal data and to demonstrate accountability. A documented data-protection risk register is the standard way to evidence this, and underpins DPIAs for higher-risk processing.
Free?
Yes — CSV download, no sign-up, or open it live in Urna. No card.
Build your own in Urna — free
Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.