Skip to main content
Praxikon

Article 30: Records of processing activities

Praxikon tracks Article 30 (Records of processing activities) under the GDPR, alongside the EU AI Act, citing the source for every statement.

Chapter IVIn force since 25-05-2018

What does Article 30 govern?

Article 30 requires organisations to keep a record of their processing activities: an overview of which personal data they process, why, about whom, to whom the data are disclosed and how they are secured. The controller keeps a record of the processing under its responsibility (paragraph 1), the processor a record of the categories of processing it carries out for each controller (paragraph 2). The record is kept in writing or electronically (paragraph 3) and must be made available to the supervisory authority on request (paragraph 4). The article exists because the GDPR expects organisations to be able to demonstrate compliance; recital 82 names the record as the means to do so and as the basis for supervision. Organisations with fewer than 250 employees are exempt, but that exemption falls away as soon as the processing is likely to result in a risk, is not occasional, or involves special categories of data or criminal data (paragraph 5).

Key term: Record of processing activities: the overview of all processing of personal data with which an organisation can show what it does with which data (paragraphs 1 and 2)

Directly affects:controllerprocessordata protection officersupervisory authority

Praxikon’s reading of the text and the recitals; the official text below prevails.

Official text

/
Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information: (a) the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the data protection officer; (b) the purposes of the processing; (c) a description of the categories of data subjects and of the categories of personal data; (d) the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations; (e) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards; (f) where possible, the envisaged time limits for erasure of the different categories of data; (g) where possible, a general description of the technical and organisational security measures referred to in Article 32(1).
Each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing: (a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's representative, and the data protection officer; (b) the categories of processing carried out on behalf of each controller; (c) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards; (d) where possible, a general description of the technical and organisational security measures referred to in Article 32(1).
The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.
The controller or the processor and, where applicable, the controller's or the processor's representative, shall make the record available to the supervisory authority on request.
The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.

Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.

What does this mean for you?

Controller

Record the seven elements of paragraph 1 for each processing activity: contact details, purposes, categories of data subjects and data, categories of recipients, transfers outside the EU, retention periods and a general description of security. Keep the record in writing or digitally (paragraph 3) and make sure you can produce it immediately if the supervisory authority asks for it (paragraph 4). If you have fewer than 250 employees, check whether one of the exceptions in paragraph 5 still obliges you.

Processor

Record for each controller which categories of processing you carry out on its behalf, with contact details of all parties, any transfers outside the EU and a general description of your security measures (paragraph 2). You too make the record available to the supervisory authority on request (paragraph 4).

Data Protection Officer

Your name and contact details appear in the record of the controller and of the processor (paragraph 1(a) and paragraph 2(a)). Check that those details are up to date.

Compliance checklist

Related recitals

Cross-references

Frequently asked questions

Connections

What connects to Article 30 GDPR