Help centre / Registers & safeguarding / Meet UK GDPR with the data protection registers
Meet UK GDPR with the data protection registers
Open Governance to find four registers: the record of processing activities (how you use personal data), the data breach log with the 72-hour ICO decision, the AI-use inventory, and Systems & access. Select Start with the basics to add the entries most charities need.
What the registers are
UK GDPR (the UK's data protection law) asks charities to know how they use personal data and to act quickly when something goes wrong. CharityControl breaks this into four small registers, all under Governance. They are records about your charity: filling them in changes nothing anywhere else, and you can edit them at any time.
Record of processing activities
This is a list of the ways your charity uses personal data. For each activity you record whose data it is, what you hold, the lawful basis, how long you keep it and who it's shared with.
- Go to Governance, then Record of processing activities.
- Select Start with the basics. This adds the entries almost every charity needs: membership, donations and Gift Aid, volunteers, and DBS checks. It only ever adds. It never changes entries you've written, and pressing it twice is safe.
- Select Add activity for anything else your charity does with personal data.
- Edit each entry so it matches what you actually do.
Your ICO registration
Most charities that hold personal data on a computer must register with the Information Commissioner's Office (ICO) and pay a small annual fee. On the same page, record your registration reference (it looks like ZA123456) and its renewal date. A narrow exemption exists for some not-for-profits. If it applies to you, mark yourself exempt and say why.
Data breach log and the 72-hour decision
A data breach is personal data going where it shouldn't, for example an email sent to the wrong person. UK GDPR gives you 72 hours from finding out to tell the ICO, if the breach is serious enough to report. The log is where you make that decision and keep the evidence.
- Go to Governance, then Data breach log, and select Log a breach.
- Give it a short title and the date it happened or was found.
- Note whose personal data was affected.
- Record your answer to Reportable to the ICO? and the date you decided.
- If you report it, record the date you told the ICO.
- Add what you did to put it right, and close the record when you're done.
Deciding "not reportable" is fine for minor breaches. The log shows you considered it properly and on time.
AI-use inventory
A simple list of where your charity uses AI tools. CharityControl's own AI features add themselves as the first entries, with an honest note of what data they see and how a person stays in charge. Select Add AI use to record anything else, for example a volunteer using ChatGPT to draft newsletters.
Systems & access
A record of your key systems (the bank account, your email tool, the website), who owns each one and who has access. Set how often access should be reviewed, and the register flags any review that's overdue. When you check a system, select Reviewed to stamp today's date.
This register never stores passwords. It records who has access, never how to sign in.