Article 30: Records of processing activities
Praxikon tracks Article 30 (Records of processing activities) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 30 govern?
Article 30 requires organisations to keep a record of their processing activities: an overview of which personal data they process, why, about whom, to whom the data are disclosed and how they are secured. The controller keeps a record of the processing under its responsibility (paragraph 1), the processor a record of the categories of processing it carries out for each controller (paragraph 2). The record is kept in writing or electronically (paragraph 3) and must be made available to the supervisory authority on request (paragraph 4). The article exists because the GDPR expects organisations to be able to demonstrate compliance; recital 82 names the record as the means to do so and as the basis for supervision. Organisations with fewer than 250 employees are exempt, but that exemption falls away as soon as the processing is likely to result in a risk, is not occasional, or involves special categories of data or criminal data (paragraph 5).
Key term: Record of processing activities: the overview of all processing of personal data with which an organisation can show what it does with which data (paragraphs 1 and 2)
Directly affects:controllerprocessordata protection officersupervisory authority
Praxikon’s reading of the text and the recitals; the official text below prevails.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
Record the seven elements of paragraph 1 for each processing activity: contact details, purposes, categories of data subjects and data, categories of recipients, transfers outside the EU, retention periods and a general description of security. Keep the record in writing or digitally (paragraph 3) and make sure you can produce it immediately if the supervisory authority asks for it (paragraph 4). If you have fewer than 250 employees, check whether one of the exceptions in paragraph 5 still obliges you.
Processor
Record for each controller which categories of processing you carry out on its behalf, with contact details of all parties, any transfers outside the EU and a general description of your security measures (paragraph 2). You too make the record available to the supervisory authority on request (paragraph 4).
Data Protection Officer
Your name and contact details appear in the record of the controller and of the processor (paragraph 1(a) and paragraph 2(a)). Check that those details are up to date.
Compliance checklist
Related recitals
Cross-references
Frequently asked questions
Connections
What connects to Article 30 GDPR
Themes where this returns
The counterpart in the other law
- Article 2 AI Act: Scope
via Using special categories of personal data to detect bias
- Article 10 AI Act: Data and data governance
via Using special categories of personal data to detect bias
- Article 11 AI Act: Technical documentation
via Keeping records: record of processing, technical documentation and logs
- Article 12 AI Act: Record-keeping
via Keeping records: record of processing, technical documentation and logs
- Article 18 AI Act: Documentation keeping
via Keeping records: record of processing, technical documentation and logs
- Article 19 AI Act: Automatically generated logs
via Keeping records: record of processing, technical documentation and logs
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
via Keeping records: record of processing, technical documentation and logs