Skip to content

Processing register and ISO 27701

Records of processing describe how personal data is used and your role in that use. Capture the applicable GDPR Article 30 information and keep changes traceable.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Get started with ISO Ready

Identify your role for each activity

An organisation may be a controller for its own employee administration and a processor for a service supplied to customers. GDPR Article 30 distinguishes the records for these roles. Start by describing the activities you perform, for whom and under whose responsibility. A software inventory or supplier list alone does not provide that overview.

What information belongs in the records?

For controllers, Article 30 includes contact details, purposes, categories of individuals and personal data, categories of recipients and applicable transfers to third countries or international organisations. Where possible, include erasure time limits and a general description of security measures. Applicable transfers also require the destination and safeguards information specified in Article 30.

Processors record contact details for themselves and the controllers they serve, categories of activities performed for each controller, applicable transfers and, where possible, a general description of security measures. Use the appropriate fields for each role. Records must be in writing, which can be electronic, and made available to the supervisory authority on request.

Practical organisation and maintenance

The following approach supports maintenance; it is not a verbatim standard template. Alongside the statutory fields, add an internal owner, change date and links to relevant decisions. A legal basis is useful in the wider privacy administration, but Article 30 does not list it as a separate mandatory record field.

CheckWorking question
New activityHas the processing been described before records drift away from practice?
New supplierDo recipients, countries or agreements change?
Changed purposeShould earlier privacy decisions be reassessed?
RetentionDoes the description match the configured deletion process?
AlignmentDo the register, DPIA and contract identify the same activity?

Fictional example: payroll administration

A fictional company moves payroll processing to another provider. The record owner checks what data is disclosed, who receives access and whether storage locations change. The company connects the updated entry to the contract and the transition decision. Previous and current versions remain distinguishable, making it clear which arrangement applied at a particular time. This is an example of a working method, not a completed customer project.

A small organisation is not automatically exempt

The exemption for organisations employing fewer than 250 people has significant limits. It does not apply where processing is likely to create a risk to rights and freedoms, is not occasional, or includes special-category or criminal-conviction and offence data. Assess the actual activities; employee numbers alone cannot establish an exemption.

Connect the records to privacy management without creating conflicting copies. Read about DPIAs and GDPR and ISO 27701. A completed register does not by itself demonstrate that every processing activity is lawful.

Primary sources for this topic

Frequently asked questions

Is a supplier list the same as records of processing?
No. A supplier list describes organisations, while records of processing describe activities and the personal data involved. One supplier may support several activities and one activity may involve several suppliers. Connect the records using clear references, but separately check that the information required for your role under GDPR Article 30 is present.
Do organisations with fewer than 250 employees need processing records?
They may still be required. The Article 30 exemption has limits for processing that is not occasional, is likely to create risk, or involves special-category or criminal-conviction and offence data. Assess the activities and their characteristics. Having a small workforce is not, by itself, sufficient reason to omit the records.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)