01

The elements that make a record of processing activities useful

A record of processing activities is useful when it contains, for each activity: the name and contact details of the controller, joint controller, representative and data protection officer; the purposes of processing; the categories of data subjects and personal data; the categories of recipients, including those in third countries; any transfers outside the EU with the safeguards adopted; the envisaged time limits for erasure of data, where possible; a general description of the technical and organizational security measures.

02

What it is concretely for

The record must be kept in writing, including in electronic form, and made available to the supervisory authority upon request. Organizations with fewer than 250 employees may be exempt from the obligation, unless the processing presents a risk to the rights of data subjects, is not occasional, or involves special categories of data or data relating to criminal convictions.

03

How to build a usable record

Steps

  1. Identify the controller, any joint controller, representative and data protection officer with their contact details.
  2. Describe the purposes, categories of data subjects and categories of personal data for each activity.
  3. List the categories of recipients, including those in third countries or international organizations.
  4. Document transfers outside the EU and the safeguards adopted, where applicable.
  5. If you use processors, formalize a written contract defining the subject matter, duration, nature and purpose of the processing.

04

Hypothetical example

A hypothetical HR services company records a processing activity for managing job applications: controller and DPO with their contact details, purpose 'recruitment', data subject category 'applicants', data category 'identification data and resumes', recipients 'human resources office', no transfers outside the EU, erasure after the retention period, security measures described in general terms.

05

Checklist of mandatory elements

  • Name and contact details of the controller, joint controller, representative and DPO, where applicable.
  • Purposes of processing indicated for each activity.
  • Categories of data subjects and categories of personal data processed.
  • Categories of recipients, including third countries or international organizations.
  • General description of technical and organizational security measures.

06

How to set up the record in management software

An organization can configure, together with its software partner, a module that tracks: contact details of the controller and processors, purposes for each activity, categories of data and data subjects, recipients, any transfers outside the EU and related safeguards, erasure timeframes and security measures. It is useful to have distinct roles for those who enter data and those who review it, with a change history to ensure traceability and periodic reviews.

07

Frequently asked questions

The record is kept by the controller and, where applicable, by the processor, for the activities carried out under their responsibility.

The format can be electronic, provided the content remains complete and available upon request from the supervisory authority.

08

Next step

Check which processing activities in your organization still lack a complete description according to the listed elements and plan their documentation.

FAQ

Frequently asked questions

What minimum information must a record of processing activities contain?

It must contain contact details of the controller, joint controller, representative and DPO, purposes, categories of data subjects and data, categories of recipients, any transfers outside the EU, erasure time limits and general security measures.

Must every organization keep the record?

Organizations with fewer than 250 employees may be exempt, unless the processing presents risks to data subjects, is not occasional, or involves special categories of data or criminal data.

In what format must the record be kept?

The record must be kept in writing, including in electronic form, and made available to the supervisory authority upon request.

Sources and verification