A privacy risk register is a tool that allows you to collate, record, track and manage all your data protection, information security and privacy risks information in one place. This Practice Note guides you through the process of creating a privacy risk register. See Precedent: Privacy risk register. There is no requirement in the UK GDPR to have a privacy risk register, but Information Commission’s Office (ICO) guidance suggests the regulator considers this to be good practice. To create a privacy risk register, you must first identify data protection risks within your organisation. This involves reviewing what personal data you hold, how you process that data, why you process that data, who you share personal data with, how data moves within your organisation, whether you transfer personal data outside the UK, how you ensure personal data remains accurate and up to date, how long you keep personal data and your process for destroying personal data. Armed with this information, you can identify your data protection and privacy risks and populate a privacy