Start with twelve fields
- Service and internal owner
- Business purpose
- Personal-data categories
- Fact-specific role assessment
- Contract and instruction reference
- Primary hosting and remote-access locations
- Sub-processors or connected services
- Privileged roles
- Retention and deletion event
- Export and backup behaviour
- Exit owner and steps
- Last review and next review
Reconcile against reality
Compare the register with accounts payable, single sign-on applications, browser extensions, integration lists and team spreadsheets. A vendor missing from the register is a discovery question—not an automatic legal conclusion.
Review at operating events
- Before procurement or material configuration change
- When a new integration or sub-processor appears
- When data categories, purpose, access or location changes
- At contract renewal and service exit
- After a rights request, incident or deletion exercise exposes a gap
Evidence to save
Save the current register version, accountable review, contract reference, configuration result and unresolved question. Link to controlled evidence rather than copying sensitive records into the register.