Point of law
The record of processing activities
The difficulty with a record of processing activities usually lies not in creating it for the first time but in keeping it up to date. Maintenance handled purely centrally tends to reflect an outdated state, because the substantive information arises in the individual departments. The record stays reliable only once new processing activities are captured where they are introduced or changed.
A spreadsheet nobody maintains
On the table lies a spreadsheet someone drew up three years ago who has since left the organisation. It lists systems that have been replaced, and it omits the ones added since. It still has to be produced, exactly as it stands.
The exemption for smaller organisations rarely applies, and never fully
Whether an organisation with fewer than 250 employees has to keep a record at all is not decided by that number. Art. 30(1) GDPR binds every controller and Art. 30(2) every processor. Paragraph 5 exempts smaller units, but only in so far as three kinds of processing are absent.
Three cases, and one is enough
| The processing falls under it | Merkmal | The processing does not |
|---|---|---|
| Record requiredAny risk suffices, not only the high risk of Art. 35 GDPR. | Risk to rights and freedoms | Exempt in that respect |
| Record requiredProcessing is occasional only outside the regular course of business. | Processing that is not occasional | Exempt in that respect |
| Record requiredThe same goes for data on criminal convictions under Art. 10 GDPR. | Special categories under Art. 9(1) GDPR | Exempt in that respect |
The three cases stand side by side and not cumulatively. An organisation with staff processes employee data continuously and thereby meets the second. The number of employees is then beside the point.
The German wording of paragraph 5 is hard to read here because it packs the three cases into a negation. The English version places them side by side with or. The Article 29 Working Party stated expressly in its position paper of 19 April 2018, adopted by the European Data Protection Board the same day, that any one of them triggers the obligation.
Conversely, the exemption does not fall away as a whole. According to the same paper, the obligation in a small organisation extends to processing of the three kinds named and not necessarily to every other activity. Little of that survives in practice, because drawing the line costs more effort than making the entry.
Where possible is no invitation to leave the column empty
How far the seven items have to go is left open by the text of the regulation and turns on two words. The retention periods and the description of the measures sit under the reservation “where possible”. The reservation concerns the entry, not the care taken.
The seven items under Art. 30(1) GDPR
The controller and contact details
This includes the representative and the data protection officer where applicable. Where a group has several companies, each would keep its own record, because responsibility rests with the individual entity and not with the group.
The purposes of the processing
The purpose is what separates one activity from the next. Recruitment and payroll pursue different purposes and are therefore two activities, even where the same software handles both.
Categories of data subjects and of data
Categories, not individual cases. Employees, applicants, customers and visitors are categories of data subjects. Master data, contract data and health data are categories of data. Special categories under Art. 9(1) GDPR should be identified as such, because they materially shape the data protection impact assessment and the measures.
Categories of recipients
Recipients include processors. The entry should be precise enough that a third-country transfer can be read off it. “Service provider” does not achieve that, “data centre in Ireland, support in India” does.
Transfers to third countries
What has to be named is the third country and the safeguard, so the adequacy decision, the standard contractual clauses or a derogation under Art. 49 GDPR. This line is the entry point to the transfer impact assessment and often the occasion for noticing it at all.
The envisaged retention periods
Where a period is not yet settled, the criteria that determine it would belong here. Where a period is stated that no system carries out, the entry is wrong rather than incomplete.
The technical and organisational measures
The German data protection authorities offer a workable standard. The description of the measures under Art. 32 GDPR should be concrete enough for a supervisory authority to carry out an initial review of lawfulness. A list of buzzwords does not achieve that.
The hardest cut runs between processing activity and system. An activity is an operation with a purpose of its own, not a piece of software. Conversely it would be a mistake to record every form separately. Nobody maintains two hundred entries, and an unmaintained record weighs more heavily in an inspection than a concise one.
Without a record the processing does not become unlawful
The consequences of a missing record of processing activities are frequently overestimated in both directions. While one view treats every processing activity without a record as impermissible, the other assumes that a breach of the documentation obligation has no practical consequences.
The Court of Justice rejected the first on 4 May 2023. An infringement of Art. 26 and Art. 30 GDPR does not constitute unlawful processing within the meaning of Art. 17(1)(d) and Art. 18(1)(b) GDPR and therefore gives the data subject no right to erasure or to restriction.
The reasoning lies in the structure. The regulation separates the principles of its Chapter II, which include Art. 5 and Art. 6 GDPR, from the general obligations of Chapter IV, to which Art. 30 GDPR belongs. The record is accordingly not a condition of lawfulness.
A record does not age by the calendar but with the change
What the upkeep depends on, and who supplies the information, is left unsettled in most organisations. Under Art. 30(1) GDPR the controller keeps the record. The data protection officer monitors compliance under Art. 39(1)(b) GDPR. The two are distinct, and in practice they collapse into one.
The departments hold the information. Central maintenance therefore produces a copy of the last known state and not an inventory.
Four occasions on which an entry arises by itself
Procurement
New software is selected. Purpose, categories of data and recipients are settled at that moment and never again as precisely.
Release of a procedure
A department takes up a new operation. Whoever releases it knows the purpose.
Change to the estate
An interface is added, a recipient changes, a retention period shifts.
Retirement of a system
The entry is closed, and the question of legacy data arises with it.
A record stays up to date only where its upkeep is built into existing working processes. Where entries are created as soon as a processing activity is introduced or changed, they arise both at the right moment and where the necessary knowledge sits.
The record of processing activities and the retention schedule rest on the same basis, namely the documented processing activities. Where the two are maintained separately, experience shows that they diverge within a short time.
How we support you with the record of processing activities
Our recommendation goes beyond the legal obligation. A structured overview of an organisation’s own processing is the core element of a data protection programme, and without it no further obligation can be allocated. The form is open to argument, the question of whether is not.
What an inventory delivers
Liste zu erledigender Punkte
- The list of activities, cut by purpose rather than by system
- The allocation of which department supplies which entry
- The occasions on which an entry is created, changed and closed
- The reconciliation with the retention schedule, so both use the same list
Frequently asked questions
Does the exemption for organisations under 250 employees apply?
Rarely, and then only in part. Art. 30(5) GDPR excludes three kinds of processing from the exemption, and any one of them triggers the obligation. Employee data is not processed occasionally. The obligation then covers those activities and not necessarily every other one.
Does the record have to be produced?
On request by the supervisory authority, Art. 30(4) GDPR. Failure to produce it carries its own penalty under Art. 83(4)(a) GDPR, regardless of whether a record exists.
Is a spreadsheet enough?
What is required is writing, including an electronic format, Art. 30(3) GDPR. A spreadsheet is enough as long as it is maintained. The tool matters less than the question of who touches it when something changes.
How often does the record have to be updated?
The GDPR sets no interval. A fixed interval does not replace the trigger, because a record does not age by the calendar but with the next change. What works in practice is tying it to procurement and to the release of a new procedure, with an annual reconciliation on top.
More questions from this area
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.