Skip to content

Glossary

Records of processing

The internal register of what personal data an organisation handles, why, and where it goes, maintained rather than assembled on request.

In plain terms

A list of what you do with people's information. It is often treated as a compliance chore, and it is the only document in most organisations that attempts to answer where personal data actually goes, which turns out to be a question nobody else has written down.

01

Why it matters

Because it is expected to exist already rather than to be produced on request, and because an organisation that cannot describe its own processing has a bigger problem than the missing document. The register is where the absence shows up first, which is why it functions as a diagnostic as much as an obligation.

02

How it works

It records activities rather than systems, which is the distinction that decides whether it stays accurate. A system appears once and the things done with it change, so a register organised by software drifts out of date invisibly while one organised by activity has somewhere for a new use to be written down.

It is maintained rather than compiled. The expectation is that it reflects current practice, so a register assembled when somebody asks describes the organisation on the day of the request, which is precisely the version least likely to match what has been happening.

AI adoption makes it wrong faster than anything else, because these tools arrive as products rather than as processing decisions. A team adopts an assistant, material starts flowing somewhere new, and nothing in that sequence involves anybody who thinks of the register as their responsibility.

Its internal value exceeds its regulatory value, which is the part organisations discover late. Answering where material goes is needed for a security review, a vendor question, a customer request or an incident, and each of those otherwise starts with the same expensive archaeology.

Keeping it current is a process question rather than a documentation one. The register goes stale because nothing connects adopting a tool to updating it, so the durable fix is a step in how tools get adopted rather than a periodic effort to catch up.

Two ways to organise the same register

Two ways to organise the same registerThe choice looks like a formatting preference and decides whether the document survives contact with a year of ordinary change. Systems are a stable list, which is exactly why organising around them feels sensible and why the register then fails silently: the tools do not change much, the things done with them change constantly, and a row that says a customer database exists remains accurate no matter how many new purposes it is put to. Activities move, so a register built from them is visibly incomplete the moment somebody starts doing something new, and visible incompleteness is the only property that gets a document updated. The AI case is where this bites hardest. An assistant adopted by a team is one new system and potentially several new activities, and under the left-hand arrangement it produces a single row that looks like progress. Under the right-hand one it produces several rows somebody has to think about, which is more work and is the work the register exists to make somebody do.By systemOne row per piece of software.A new use changes nothingvisible.Drift is invisible untilaudited.By activityOne row per thing you do.A new use is an obviouslymissing row.Drift shows up as a gap.The left-hand arrangement iseasier to build because softwareis easy to enumerate. Theright-hand one is the onlyversion where somebody noticesthat it has stopped being true.
The choice looks like a formatting preference and decides whether the document survives contact with a year of ordinary change. Systems are a stable list, which is exactly why organising around them feels sensible and why the register then fails silently: the tools do not change much, the things done with them change constantly, and a row that says a customer database exists remains accurate no matter how many new purposes it is put to. Activities move, so a register built from them is visibly incomplete the moment somebody starts doing something new, and visible incompleteness is the only property that gets a document updated. The AI case is where this bites hardest. An assistant adopted by a team is one new system and potentially several new activities, and under the left-hand arrangement it produces a single row that looks like progress. Under the right-hand one it produces several rows somebody has to think about, which is more work and is the work the register exists to make somebody do.
03

Seen in the wild

  • Discovering during a customer request that nobody recorded an assistant now holding pasted material.

    ChatGPT
  • A search deployment reaching systems the register lists separately and never connects.

    Glean
  • An automation moving personal data to a destination that appears in no register entry.

    Make
04

Common misconceptions

People assume

It can be assembled when somebody asks for it.

In fact

The expectation is that it already exists and reflects current practice. A register compiled on request describes the organisation on that day, which is the version least likely to match what has actually been happening.

People assume

It is a compliance document with no other use.

In fact

It is usually the only place that answers where personal data goes, which a security review, a vendor question, a customer request and an incident response all need. Most organisations discover that value while doing one of those without it.

05

Questions

Why does AI adoption make it stale so quickly?
Because these tools arrive as product decisions rather than processing ones. A team adopts something useful, material begins flowing to a new destination, and nobody in that sequence considers the register their responsibility, so the change happens without any prompt to record it.
How should it be organised?
By activity rather than by system. A system appears once while what is done with it changes repeatedly, so a register arranged by software drifts silently, whereas one arranged by activity has an obvious place for a new use to be added when it starts.
What actually keeps it current?
A step in how tools get adopted, rather than a periodic catch-up exercise. The register goes stale because nothing connects adoption to recording, and a review scheduled twice a year finds the drift long after the material started going somewhere new.
06

Key takeaways

  • Organise by activity: systems stay put while what you do with them changes.
  • It is expected to exist already, not to be assembled on request.
  • AI tools arrive as product decisions, so nothing prompts an update.
  • Its internal value usually exceeds its regulatory value.
08

Tools that use this

  • ChatGPT

    An assistant holding pasted material that nobody recorded.

  • Glean

    Reaching systems the register lists separately and never connects.

  • Make

    Moving personal data to a destination in no register entry.

Last checked August 2026

All glossary terms