The record of processing activities is the central tool for managing compliance and demonstrating accountability. It is mandatory for controllers and processors under GDPR Article 30, in written form (paper or electronic), and must be produced on request by the supervisory authority.
Definition and scope
Article 30 of Regulation (EU) 2016/679 requires a record listing each processing activity, with specified information (purposes, categories of individuals and data, recipients, transfers, retention periods, security measures). Consult the text on EUR-Lex (GDPR — art. 30).
The CNIL emphasises that this record is a management tool for both compliance and risk management. Official templates help microbusinesses/SMEs implement it (France Num / CNIL).
Exception for businesses with < 250 employees: the exemption applies only if processing is occasional, includes no special categories of data (or criminal data) and is unlikely to pose a risk to individuals' rights and freedoms (art. 30(5) GDPR — EUR-Lex). In practice, the CNIL continues to recommend keeping a record for all organisations.
Two distinct records according to role: controller versus processor
Controller's record (art. 30(1))
- Contact details of the controller, any joint controllers, representative (if outside the EU) and DPO.
- Processing purposes.
- Descriptions of categories of data subjects and data.
- Recipient categories, including transfers to third countries/international organisations and safeguards.
- Envisaged deadlines for erasure of different data categories.
- General description of technical and organisational security measures.
References: EUR-Lex — GDPR art. 30, CNIL.
Processor's record (art. 30(2))
- Name and contact details of each controller on whose behalf it acts, representative (if outside the EU) and DPO.
- Categories of processing performed on behalf of each controller.
- Transfers to third countries/international organisations and safeguards.
- General description of technical and organisational security measures.
References: EUR-Lex — GDPR art. 30, CNIL.
Ready-to-use template (adapted for microbusinesses/SMEs)
The CNIL provides a basic sample record (ODS, RTF, PDF) with one sheet per processing activity identified by its purpose. Download and adapt the template: CNIL example (PDF) and France Num guide (microbusiness/SME template).
Essential fields for a processing sheet
- Processing identifier and internal owner (responsible department).
- Precise purpose(s) and corresponding legal basis/bases.
- Categories of individuals (customers, prospects, employees, applicants, users, etc.).
- Data categories (identity, contact, product use, billing, HR, etc.).
- Internal and external recipients (including processors) and transfers outside the EU.
- Retention periods by data category and criteria for determining them.
- Security measures (access controls, encryption, logging, backups, testing).
- Link to the relevant information notice/privacy policy.
- Whether a DPIA is required and its reference if completed.
Sample “Candidate recruitment” sheet
- Owner: HR — Talent Acquisition.
- Purpose: managing applications and the interview process.
- Legal basis: employer's legitimate interest; consent for retaining CVs in a talent pool beyond the process.
- Individuals: applicants.
- Data: identity, contact, CVs, letters, interview notes, tests (non-sensitive).
- Recipients: HR, hiring managers; ATS processor (SaaS).
- Transfers outside the EU: none, or Standard Contractual Clauses if the ATS hosts in the United States/third countries.
- Retention: unsuccessful applications 2 years after last contact with consent; otherwise closure + 6 months; hires: HR file according to statutory obligations.
- Security: restricted access, MFA authentication, encryption at rest and in transit, automated deletion, access logging.
- Information: link to candidate policy on the careers website.
Tip: the sheet must remain operational; avoid vague wording. See France Num's practical advice on “How to make the record a genuinely useful tool” (France Num).
A 7-step method to compile and maintain your record
- Appoint a lead (ideally the DPO) and define scope, format (spreadsheet versus SaaS tool) and review frequency. The accountability principle is promoted by the EDPB (European Data Protection Board).
- Map by purpose: workshops/interviews with HR, Sales/Marketing, Product/Tech, Finance, Legal and Support to list uses (CRM, billing, support, analytics, cookies, logs, recruitment, payroll, security, etc.).
- Identify legal bases and recipients; identify processors and any transfers outside the EU.
- Define retention periods by data category, aligning compliance and business needs (intermediate archiving, anonymisation/pseudonymisation).
- Complete one sheet per processing activity (CNIL template) and have business owners validate it.
- Check risks: is a DPIA needed? Are security measures sufficient? Are cookie records consistent? Adapt as needed with your DPO's assistance.
- Governance and updates: quarterly/six-monthly review, integration into project-launch processes, checks before engaging any new processor.
For smooth deployment, the tool-supported, iterative approach recommended by France Num is effective (guide).
Technical points not to forget
- Processors and transfers: the record must list providers, their locations and safeguards. Cover GDPR obligations contractually (DPA). See our advice on processing agreements and good practice.
- Cookies and analytics: create dedicated sheets (audience measurement, A/B testing, retargeting), consistent with your CMP.
- Products and logs: do not overlook event logs, telemetry, monitoring and support. Specify distinct purposes and retention periods.
- AI and datasets: if using personal data to train/evaluate models, document purposes, legal bases, minimisation and retention. See our guide to GDPR obligations applied to AI.
- Information for individuals: the record and privacy policy must remain consistent (purposes, periods, rights).
Update frequency, inspections and penalties
Update the record for every new processing activity, substantial change (new purpose, provider, transfer, changed retention periods) and at least annually. During an inspection, the CNIL may require its production. An absent or incomplete record may attract penalties of up to €10m or 2% of worldwide annual turnover (GDPR art. 83 — EUR-Lex). Also see institutional reminders on Service Public Pro and CNIL.
Tools, organisation and the DPO's role
A spreadsheet based on the CNIL template is often sufficient initially. Growing businesses may prefer a dedicated GRC/Privacy tool linking the record, DPIAs, breach records and processor inventory. Establish governance (access rights, history, exports, evidence). The DPO leads or oversees record keeping, facilitates reviews and advises on risks. If internal resources are unavailable, consider an outsourced DPO. For the supplementary national framework (French Data Protection Act), consult Legifrance.
Further reading
Related resources
Frequently asked questions
FAQ
Are processing records mandatory for small businesses?
Yes, subject to a narrow exception (occasional processing, no sensitive/criminal data and no risk). The CNIL recommends keeping them in all cases.
What must a processing sheet compliant with GDPR Article 30 contain?
Purposes, legal bases, categories of individuals and data, recipients, transfers, retention periods, security measures, controller/DPO contact details.
Is a separate record needed when acting as a processor?
Yes. The processor's record lists categories of processing performed for each controller, any transfers and security measures.
How often should the GDPR record be updated?
For each major change (new purpose, processor, retention period, transfer) and at least annually through a structured compliance review.
What penalties apply for having no record?
Up to €10m or 2% of worldwide turnover (art. 83 GDPR). The CNIL may require production of the record during an inspection.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.