Identify your role for each activity
An organisation may be a controller for its own employee administration and a processor for a service supplied to customers. GDPR Article 30 distinguishes the records for these roles. Start by describing the activities you perform, for whom and under whose responsibility. A software inventory or supplier list alone does not provide that overview.
What information belongs in the records?
For controllers, Article 30 includes contact details, purposes, categories of individuals and personal data, categories of recipients and applicable transfers to third countries or international organisations. Where possible, include erasure time limits and a general description of security measures. Applicable transfers also require the destination and safeguards information specified in Article 30.
Processors record contact details for themselves and the controllers they serve, categories of activities performed for each controller, applicable transfers and, where possible, a general description of security measures. Use the appropriate fields for each role. Records must be in writing, which can be electronic, and made available to the supervisory authority on request.
Practical organisation and maintenance
The following approach supports maintenance; it is not a verbatim standard template. Alongside the statutory fields, add an internal owner, change date and links to relevant decisions. A legal basis is useful in the wider privacy administration, but Article 30 does not list it as a separate mandatory record field.
| Check | Working question |
|---|---|
| New activity | Has the processing been described before records drift away from practice? |
| New supplier | Do recipients, countries or agreements change? |
| Changed purpose | Should earlier privacy decisions be reassessed? |
| Retention | Does the description match the configured deletion process? |
| Alignment | Do the register, DPIA and contract identify the same activity? |
Fictional example: payroll administration
A fictional company moves payroll processing to another provider. The record owner checks what data is disclosed, who receives access and whether storage locations change. The company connects the updated entry to the contract and the transition decision. Previous and current versions remain distinguishable, making it clear which arrangement applied at a particular time. This is an example of a working method, not a completed customer project.
A small organisation is not automatically exempt
The exemption for organisations employing fewer than 250 people has significant limits. It does not apply where processing is likely to create a risk to rights and freedoms, is not occasional, or includes special-category or criminal-conviction and offence data. Assess the actual activities; employee numbers alone cannot establish an exemption.
Connect the records to privacy management without creating conflicting copies. Read about DPIAs and GDPR and ISO 27701. A completed register does not by itself demonstrate that every processing activity is lawful.