Data & GDPR
Record of processing activities: what each column must contain
A record of processing activities fits in a spreadsheet. It is the first document the CNIL asks for on an inspection, and the one most often missing — because its owner believed the 250-employee threshold let them off. That threshold lets almost nobody off, and article 30 of the GDPR lists exactly seven headings for the controller and four for the processor.

Who must keep a record — and why the 250-employee exemption almost never applies
The obligation applies to all organisations, public and private, whatever their size. Article 30(1) of Regulation (EU) 2016/679, applicable since 25 May 2018, requires the controller to maintain a record of processing activities carried out under its responsibility. Paragraph 2 requires the processor to maintain its own, separate record.
Then comes paragraph 5, the one people quote from memory and get wrong. Its exact wording is this: the obligations in paragraphs 1 and 2 do not apply to an enterprise or an organisation employing fewer than 250 persons, “unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10”.
One word decides it, and it appears twice: “or”. The three limbs are therefore alternatives, and it is enough for one to be met for the obligation to return. To be excused from recording a processing activity, all three must be ruled out together: it presents no risk, and it is occasional, and it involves neither special category data nor criminal offence data.
Apply that to an ordinary business. Payroll is monthly, the customer database runs continuously: neither is occasional. Nor is handling job applications, CCTV or marketing. The CNIL puts it bluntly: the derogation is confined to very particular cases, and it recommends including the processing in the record where there is any doubt.
The second misunderstanding concerns the scope of the exemption, which is assessed not at the level of the business but processing activity by processing activity. A company with thirty employees is not “exempt from keeping a record”: it is excused from recording its occasional, risk-free processing, and must record everything else. The record therefore exists all the same — simply a shorter one.
That is the first thing we establish when a business calls us on this subject, before even looking at its tools. If you are unsure where you stand, having your processing activities classified and the resulting record built is the usual starting point.
The seven columns of the controller's record
Article 30(1) lists seven headings, at points (a) to (g). They read as the columns of a table in which each row is a processing activity: payroll, recruitment, customer management, marketing, CCTV.
(a) The name and contact details of those responsible
The most mechanical column, and yet the one filled in by halves. The provision asks for the controller, but also, where applicable, the joint controller, the controller's representative and the data protection officer. Joint controllership under article 26 is the entry most often forgotten: it covers two entities that jointly determine the purposes and means — a parent company and its subsidiary, for instance.
(b) The purposes of the processing
A purpose is not a tool. “CRM” is not a purpose; “managing the customer relationship and following up orders” is. If the wording does not say what you are trying to achieve, it describes a means. And one and the same tool often carries two distinct purposes, calling for two rows.
(c) The categories of data subjects and of data
Two pieces of information in a single heading. The people first — customers, prospects, employees, applicants. Then the data, by category rather than item by item: identity, contact details, working life, connection data. This is where the special category data of article 9 is spotted, the data that defeats the derogation in paragraph 5.
(d) The categories of recipients
The provision covers recipients “to whom the personal data have been or will be disclosed, including recipients in third countries”. Two points to watch: processors are recipients — the host, the payroll software publisher, the emailing provider all belong there — and the future counts as much as the present, a planned disclosure being recorded before it happens.
(e) Transfers outside the Union
Point (e) calls for identification of the third country or international organisation and, for transfers based on the second subparagraph of article 49(1), the documentation of suitable safeguards. A mainstream American tool is enough to open that column, and the mechanism relied on — an adequacy decision, standard contractual clauses — is written there in black and white.
(f) The envisaged time limits for erasure
The heading opens with “where possible”, which makes it more flexible, not optional. The storage limitation principle in article 5(1)(e) requires a period to be fixed for each purpose; the record is where it is written down. It follows from the purpose and from the statutory retention obligations attached to it.
(g) A general description of the security measures
The same opening formula, and the same trap: a general description is not an empty one. The reference is to article 32(1) — encryption, access control, backups, logging. A column left blank says that no measure has been identified.
The four columns of the processor's record
Article 30(2) requires a record of a different nature: not of processing activities, but of categories of processing activities carried out on behalf of each controller. The difference is not merely one of drafting — as the processor does not determine the purposes, it does not record them: it records what it does, and for whom.
Four headings: the contact details of the processor and of each controller on whose behalf it acts, together with those of the representatives and of the data protection officer; the categories of processing per controller; transfers outside the Union and the safeguards documentation; and, where possible, the security measures of article 32(1).
Most businesses keep both records: an agency, a software publisher, an accountancy firm are controllers for their own payroll and processors for the data their clients entrust to them. The two documents coexist and are not copies of one another. The contract framing that processing falls under article 28(3) and is dealt with separately.
The columns the Regulation does not require and the CNIL recommends
The basic record template published by the CNIL, in spreadsheet form and intended for small organisations, contains more columns than article 30 requires. That is not a mistake: the authority expressly recommends enriching the record. It is still worth knowing what comes from the Regulation and what comes from advice.
The most important column is the lawful basis. Look for it in article 30: it is not there. Nowhere do the seven headings ask on which ground in article 6 the processing rests — consent, contract, legal obligation, legitimate interests. It nonetheless appears in every serious template, and for a sound reason: article 5(2) requires controllers to be able to demonstrate compliance, and a processing activity whose basis nobody knows cannot be demonstrated.
In the same category of recommendation come the record of the information given under articles 13 and 14, the attachment of the processing to an internal department, and the reference of the processing contract. None is required; all of them help on the day you have to answer the CNIL within days rather than weeks.
A template is therefore read for what it is: a tool, not the text. That is also why we do not circulate ours — a record is built on real processing activities, and a pre-filled file mainly gives the illusion of having dealt with the question.
What the record is not
It is not a notification. Nothing is sent to the CNIL: article 30(4) merely requires the record to be made available to it on request. The prior notification regime disappeared on 25 May 2018.
It is not a prescribed form. Article 30(3) requires writing, “including in electronic form”. A spreadsheet will do, and so will a dedicated tool; what is not accepted is the absence of any trace.
It is not a document you fill in once. Since it must be available on request, it must describe the real processing activities as at the day of the request — not as at the date it was last reviewed. What triggers an update is not the calendar but the event: a new tool, a new provider, a new purpose, a transfer outside the Union.
Lastly, it is not a document without consequences. Failure to keep a record falls under article 83(4)(a), which caps the administrative fine at 10 million euros or, for an undertaking, 2 % of total worldwide annual turnover, whichever is higher. That ceiling is not the sanction to expect for an SME. What matters in practice is more prosaic: a record missing on the first day of an inspection colours everything that follows.
What may change, and what has not changed yet
A point of timing, because it circulates widely and is often presented as settled. On 19 November 2025 the European Commission proposed, in the package known as the “Digital Omnibus” (COM(2025) 837), to amend article 30(5): the threshold raised from 250 to 750 persons, the occasional-processing criterion removed, and the obligation refocused on processing likely to result in a high risk within the meaning of article 35.
That proposal has not been adopted. As at 6 August 2026, the date this article was published, it remains under negotiation between the Parliament and the Council, and the applicable law is unchanged. A business with 400 employees that suspended its record on the strength of a text still under discussion would today be in breach.
What we do on a matter of this kind
We build the record from interviews with the people running each function rather than from written procedures. The gap between the two is what an inspection reveals: real processing activities are almost always more numerous than the organisation believes it operates.
In matters of this kind the difficulty almost never moves onto filling in the columns, but onto classifying each party and onto handing the record over to whoever will have to maintain it afterwards. A record nobody knows how to update is out of date within six months.
The firm applies that standard to its own website, whose original visit logging and consent collection are described in its privacy policy. Our engagements are billed as a fixed fee, and the amount is announced and accepted before we start. If your record is to be built or taken over, a first conversation is enough to gauge the work involved.
Frequent questions
Yes, and for all organisations, public and private, whatever their size. Article 30 of the GDPR requires the controller to maintain a record of the activities carried out under its responsibility, and the processor to maintain its own. Article 30(5) provides a derogation for enterprises employing fewer than 250 persons, but it falls away as soon as the processing is likely to result in a risk to people's rights, as soon as it is not occasional, or as soon as it involves special category or criminal offence data. Payroll and a customer database are not occasional: the record is still required.
Seven headings for the controller, listed at points (a) to (g) of article 30(1): the identity and contact details of the controller, of any joint controllers, of the representative and of the data protection officer; the purposes of the processing; the categories of data subjects and of data; the categories of recipients; transfers outside the Union and the safeguards covering them; where possible, the time limits for erasure; where possible, a general description of the security measures. The processor's record has four, listed in paragraph 2.
The record is kept by the controller itself, that is, by the organisation, and not by a designated individual: article 30(1) refers to the controller and, where applicable, its representative. Where a data protection officer has been appointed, that officer generally steers the exercise, but the obligation is not transferred to them — article 39 gives them an advisory and monitoring role, not responsibility for the document. In practice, updating it means each business function reporting its new processing activities, which is a matter for an internal procedure, not an annual reminder.
Yes. The CNIL makes a basic record template available, in spreadsheet form, intended for small organisations — micro-businesses, SMEs, associations, small local authorities. It is a public resource, available directly on its website, and our firm does not distribute another. One point to know before opening it: that template contains more columns than article 30 requires, because the CNIL recommends enriching the record. The added columns, the lawful basis first among them, are useful but do not arise from the same obligation.
Article 30(1)(f) calls for, where possible, the envisaged time limits for erasure of the different categories of data. The wording is more flexible than the rest of the article, but it excuses nothing: the storage limitation principle in article 5(1)(e) requires a period to be fixed for each purpose, and the record is where it is written down. The period is not freely chosen — it follows from the purpose pursued and from the statutory retention obligations attached to it, whether accounting, employment or tax obligations depending on the case.
The Regulation fixes no frequency, and that is what misleads people. Article 30(4) requires the record to be made available to the supervisory authority on request: it must therefore describe the real processing activities as at the day the request arrives, not as at the date it was last reviewed. The right rule is not a rhythm but a trigger — a new tool, a new provider, a new purpose, a transfer outside the Union, a change of retention period. A record reviewed once a year and never touched in between is wrong eleven months out of twelve.
Yes, and it does not take the same form. Article 30(2) requires the processor to keep a record of the categories of processing activities carried out on behalf of each controller — the distinction is real: it does not record purposes, which it does not determine, but categories of services, client by client. Four headings: the contact details of the parties, of the representative and of the data protection officer; the categories of processing per controller; transfers outside the Union and their safeguards; where possible, the security measures. Most businesses keep both records, being controllers for their payroll and processors for the data their clients entrust to them.
Jérôme Pujol, avocat, partner, barreau de Paris et barreau des Pyrénées-Orientales.
All newsFirst conversation
Tell us your situation and we will tell you what is possible
At our offices in Paris, Perpignan, Barcelona, or by video call.



