Article 30 of the GDPR requires your company to provide a list of the personal data it holds. It takes 30 minutes to prepare, and it’s one of the first documents requested during an audit.
It’s called the record of processing activities. In everyday language, it’s referred to as the processing register, and small companies usually don’t have one because they believe it isn’t required. It’s an inventory, not a legal document: like a list of the company’s laptops and chairs, except that instead of objects, you enter data about people—employees, customers, and job applicants.
The most common source of confusion is the 250-employee threshold. Article 30, paragraph 5, does indeed exempt organizations with fewer than 250 employees, but the exemption does not apply in three situations, and any one of them is sufficient: the processing may pose a risk to individuals’ rights, the processing is not occasional, or special categories of data (health, biometric data, union membership) or data relating to criminal convictions are involved.
The second scenario applies to nearly every company with employees. Salaries, contracts, and personnel files are processed month after month, so this processing is not occasional. The position paper from the European data protection authorities states exactly this: data about a company’s own employees is processed on an ongoing basis, so it must be included in the records. The correct nuance is that records are kept for processing activities that fall outside the exemption, not necessarily for all of them.
In short, according to Article 30, paragraph 1, the notice must include: who you are as a data controller and who you are contacting, the purposes for which you process the data, the categories of individuals and data, who else receives the data, whether it is transferred outside the European Union, how long you retain it, and what security measures you have taken. Seven columns in a table cover everything.
Here’s how to do it in practice. Open a spreadsheet and create a row for each real-world situation in your company: employees and payroll, customers and invoices, resumes received in response to job postings, the contact form on your website, the newsletter, security cameras, and the accounting provider who has access to the data. For each row, fill in the seven columns, then note the date of the last update.
There is no required format. Neither the Romanian authority nor the European Data Protection Board publishes a mandatory template; the regulation only requires that the records be in writing—including in electronic format—and that they be made available to the authority upon request. An Excel file saved wherever you keep it is sufficient.
The stakes. Failure to comply with Article 30 falls under the lower tier of penalties provided for in Article 83, paragraph 4: up to 10 million euros or 2% of global annual turnover, whichever is higher. For a small company, the actual amount is much lower than the cap, but an audit that starts with “we don’t have anything like that” is bound to go badly. Thirty minutes now means a document you can calmly present.
This article was generated with AI assistance.