Personal data register with AI use marked on each row by the orange AI symbol and the red prohibited AI symbol

During ISO certification audits the same gap keeps turning up. Ask a company how it controls AI and the answer arrives quickly: there is a policy, there are acceptable use rules, sometimes there is a whole ISO 42001 project under way. Ask for the record that says which personal data an AI tool actually sees, and the picture is usually different. The personal data register, or Record of Processing Activities (RoPA), has often not been updated for the AI now in use. Two documents describing the same business, and only one of them has noticed that staff are using AI on personal data every day.

What Audits Find in the Personal Data Register

Four things, over and over. AI is named nowhere in the record, although it is named in the policy. AI providers are missing from the sharing column, even though they are now the largest single group of processors most companies have. Retention stops at the company's own systems, while the vendor holds prompts, transcripts and chat logs on terms nobody has read. And there is no record of where AI is deliberately barred, which is the entry an auditor most wants to see, because it is the one that proves somebody actually thought about it.

Decision Support Is Not a RoPA Entry

The ICO published its findings on automated decision-making in recruitment on 31 March 2026, drawn from research with more than 30 employers. The headline finding matches what comes up at audit: most employers did not recognise they were carrying out automated decision-making at all. They called it decision support, and the ICO found tools reaching decisions with no meaningful human involvement behind them. A person who cannot realistically overturn the ranking is not reviewing it. Since the Data (Use and Access) Act provisions came into force on 19 June 2026 there is more room to run those decisions lawfully, not less, but the safeguards came with it. The register is where you show which rows are affected and who can challenge them.

Three RoPA Rows That AI Creates

Most advice on this stops at adding AI to the rows already there, and that is only half the job. AI also creates personal data that did not exist before. Prompts and outputs, which may contain personal data from any row in the register. Meeting recordings, transcripts and AI summaries. Website chatbot conversation logs, which carry names, contact details and whatever the visitor decided to type. Three categories, each with its own purpose, processor and retention period, and almost nobody has them written down.

Bringing the Personal Data Register Up to Date

None of this needs a new column or a second register. It needs three questions asked of every row you already have: does an AI tool touch this data, is anything about this person being scored or decided by software, and what copies now exist outside your own systems. Then write down the rows where AI must not go at all.

We have published a worked example of what that looks like: the F-IMS24 Personal Data Register completed for a company using AI tools, with the AI position written into every existing column and three new rows for data that only exists because AI is in use. The file update post sets out what it covers and where to find it.

Data Protection and UK GDPR

ISO 42001 AI Management System Knowledge Base

ISO 42001 Annex A.7 - Data for AI Systems Explained

F-IMS24 Personal Data Register

ISO 42001 Toolkit

Published: 08 September 2026
payment logos