How to Build a GDPR Risk Register

A risk register is the document at the heart of GDPR accountability — the evidence you can show a regulator that you've identified, assessed and acted on your data risks. Most SMEs don't have one, and it's the first thing asked for after a breach or complaint.

What a risk register must contain

A useful GDPR risk register isn't a spreadsheet of fears — it's a structured log where every data-related risk has a clear owner, rating and action. The minimum fields:

How to score risks without overcomplicating it

Use a five-by-five grid. Score likelihood (how likely is a breach of this asset?) and impact (how badly would data subjects be harmed?) each 1–5, multiply them, and treat anything scoring 12+ as urgent. Colour-coding high/medium/low makes it reviewable at a glance.

The risks most SMEs forget

  1. Third-party processors — your accountant, CRM, payroll and email provider all process your data.
  2. Retention — holding data longer than you need is itself a breach.
  3. Home workers and BYOD — personal devices touching company data.
  4. Disposal — old laptops and phones with data still on them.

Risk Register Workbook

A pre-scored, structured risk register template — fill in your risks and it does the rating, tiering and prioritisation for you.

Get it now

This guide is general information, not legal advice. For your specific obligations, consult a qualified data-protection professional.