Templates / Data protection (GDPR) risk register template

Data protection (GDPR) risk register template

A data-protection risk register records the risks to personal data — breaches, over-collection, sending data to external AI models, biased automated decisions. The worked example below is free to download or open live, and supports GDPR accountability.

Open live in Urna — free Download the CSV

No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.

Worked example: data protection (gdpr) risk register template

RiskCategoryLikelihoodImpactRatingSuggested remediation
Breach of personal or customer dataPersonal data about customers, users or staff is exfiltrated and leaked or sold, triggering notification duties and loss of trust.legalmediumhighhighEncrypt personal data at rest and in transit and apply least-privilege so only staff who need it can reach it.
Sensitive data sent to an external AI modelPrompts, documents or records sent to a hosted model for inference leave your security boundary — retained in logs, exposed to the provider, or transferred across borders — even when the AI use is sanctioned.legalhighmediumhighClassify what may and may not be sent to an external model, and minimise or redact personal and confidential data in prompts.
Biased or unfair AI outcomesAn AI system produces systematically worse or discriminatory outcomes for some groups — in hiring, pricing, eligibility or moderation — exposing people to harm and the organisation to legal and reputational risk.legalmediumhighhighAssess, before deployment, who the system affects and how it could cause unfair or discriminatory outcomes; record the risks and mitigations.
Shadow or unsanctioned AI useStaff paste confidential documents, customer data or code into public AI tools to get work done faster, sending that data to a third party outside any agreement or oversight.legalhighhighhighPublish a short AI-use policy: which tools are approved, and the data categories that must never be pasted into a public service.
Insider threat or misuse of accessA current or former staff member, contractor or privileged user misuses their access — to steal data, cause damage, or act carelessly — and the activity blends into normal work.securitymediumhighhighGrant least-privilege access and review it regularly, especially after a role change; revoke everything promptly when someone leaves.
Cloud misconfiguration or exposed storageA storage bucket, database or admin interface is left publicly reachable or without authentication through a configuration mistake, exposing data or a way in.securityhighhighhighBuild systems from a hardened, documented baseline that turns off public access and default credentials, and block deployments that drift from it.

Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.

Questions

What is a data protection risk register?

A record of the risks to personal data your organisation holds — each rated and treated. It supports the accountability principle under GDPR and feeds Data Protection Impact Assessments.

Does GDPR require a risk register?

GDPR requires you to assess and mitigate risks to personal data and to demonstrate accountability. A documented data-protection risk register is the standard way to evidence this, and underpins DPIAs for higher-risk processing.

Free?

Yes — CSV download, no sign-up, or open it live in Urna. No card.

Build your own in Urna — free

Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.

Start free See how it works