01
What the record must contain
- Name and contact details of the controller, any joint controller, representative, and DPO, where applicable
- The purposes of the processing
- Categories of data subjects and categories of personal data processed
- Categories of recipients, including those in third countries or international organizations
- Transfers outside the EU, erasure timeframes, and security measures, where possible
02
Who must keep it and in what form
The obligation applies both to the controller and to the processor, who keeps a record of the categories of processing activities carried out on behalf of the controller. Both records must be kept in writing, including in electronic form.
The obligations do not apply to organizations with fewer than 250 employees, unless the processing poses a risk to data subjects' rights, is not occasional, or involves special categories of data or criminal convictions.
03
How to build the record step by step
Steps
- List the controller, any joint controller, representative, and DPO with their contact details
- Document each processing purpose separately
- Describe categories of data subjects and data for each purpose
- Indicate recipients and transfers to third countries, with appropriate safeguards
- Add, where possible, erasure timeframes and technical and organizational security measures
04
Hypothetical example
Hypothesis: a company with more than 250 employees records the processing of staff data for payroll management. The record states the purpose, the categories of employees involved, the external payroll provider as recipient, and the transfer of data to a cloud provider outside the EU with the relevant safeguards.
If payroll is entrusted to an external processor, the contract specifies the subject matter and duration of the processing, its nature and purpose, the type of data and categories of data subjects, and the obligations and rights of the controller.
05
Check before considering it complete
- Name and contact details of the controller, representative, and DPO are included
- Each processing purpose is documented separately
- Categories of data subjects, data, recipients, and transfers are indicated
- The record is in written or electronic form and ready for the supervisory authority
- Contracts with external processors contain the required elements
06
What can be set up in management software
A company can ask its software partner to configure dedicated fields for controller, purposes, categories of data, recipients, and transfers, so information stays up to date and searchable.
It is useful to define distinct roles for those who enter record entries and those who review them, with a change history over time, so the record can be shown on request to the competent authority.
07
Frequently asked questions about the record
Is the record only for large companies? No: it applies to controllers and processors, with a limited exemption for organizations under 250 employees if the processing is not risky or occasional.
Is an electronic file enough? Yes, written form, including electronic, is expressly permitted by the regulation.
What happens if an element such as erasure timeframes is missing? The regulation requires this data 'where possible', so it should be included when available.
08
Practical next step
Review your current record against the elements listed in this article and check that each processing purpose has a complete, up-to-date entry.
FAQ
Frequently asked questions
What minimum information must a controller's record contain?
Name and contact details of the controller (and any joint controller, representative, DPO), purposes, categories of data subjects and data, recipients, transfers outside the EU, erasure timeframes, and security measures, where possible.
Must a small company always keep the record?
Organizations with fewer than 250 employees are exempt, unless the processing poses a risk to data subjects' rights, is not occasional, or involves special or criminal data.
Must the record be shared with anyone?
On request, the controller or processor must make it available to the competent supervisory authority.
✓