How to Build a GDPR Risk Register
A risk register is the document at the heart of GDPR accountability — the evidence you can show a regulator that you've identified, assessed and acted on your data risks. Most SMEs don't have one, and it's the first thing asked for after a breach or complaint.
What a risk register must contain
A useful GDPR risk register isn't a spreadsheet of fears — it's a structured log where every data-related risk has a clear owner, rating and action. The minimum fields:
- The risk — described in plain English (e.g. "customer database held on an unpatched laptop").
- Likelihood & impact — scored on a simple 1–5 scale.
- Overall rating — likelihood × impact, so you can prioritise.
- Mitigation — what you're doing to reduce it.
- Owner & review date — who's responsible, and when it's next reviewed.
How to score risks without overcomplicating it
Use a five-by-five grid. Score likelihood (how likely is a breach of this asset?) and impact (how badly would data subjects be harmed?) each 1–5, multiply them, and treat anything scoring 12+ as urgent. Colour-coding high/medium/low makes it reviewable at a glance.
The risks most SMEs forget
- Third-party processors — your accountant, CRM, payroll and email provider all process your data.
- Retention — holding data longer than you need is itself a breach.
- Home workers and BYOD — personal devices touching company data.
- Disposal — old laptops and phones with data still on them.
Risk Register Workbook
A pre-scored, structured risk register template — fill in your risks and it does the rating, tiering and prioritisation for you.
Get it nowThis guide is general information, not legal advice. For your specific obligations, consult a qualified data-protection professional.