It is widely believed that the record of processing activities is an obligation reserved for larger organisations, because of the 250-employee threshold. This is a misunderstanding as common as it is treacherous: read in full, the rules lead to the opposite conclusion. For the generality of those who process personal data, the record is in fact the very precondition of compliance with Regulation (EU) 2016/679. It is therefore worth clarifying what it is, who is subject to the obligation, what its required content is and in what form it must be kept and updated.
What the record of processing activities is
The record of processing activities is founded on Article 30 of Regulation (EU) 2016/679 (GDPR). It consists, in short, of a documentary mapping of all the personal-data processing carried out by an organisation: for each activity it sets out the purposes pursued, the categories of data subjects and of data, the recipients, the retention periods and the security measures adopted.
It is not a mere formality. The record is one of the defining tools of the accountability principle: anyone who processes data must be able to demonstrate that they do so in compliance with the rules. Without an up-to-date picture of the processing carried out, it becomes hard to assess risks, respond to data subjects’ requests or manage a personal-data breach. It is no coincidence that the record is among the first documents the Authority requests during an inspection.
Who is required to keep the record
It is on this point that the most common uncertainty in application arises. Article 30(5) of the Regulation introduces, on the face of it, a favourable threshold: the obligation does not apply to organisations with fewer than 250 employees. The same provision, however, immediately follows with three exceptions that bring almost all controllers back within the obligation.
Even below the threshold, the record must be kept by anyone who:
- carries out processing likely to result in a risk — even if not a high one — to the rights and freedoms of data subjects;
- carries out non-occasional processing;
- processes special categories of data (the data that Article 9 GDPR classifies as sensitive: health, biometric and genetic data, religious or political beliefs and the like) or data relating to criminal convictions and offences (Article 10 GDPR).
The decisive exception is the second. “Occasional processing” means a sporadic, unplanned activity; conversely, the ordinary management of customer, supplier and employee data is by its nature systematic and continuous. Anyone with even a single employee processes their data on a stable basis for payroll and statutory purposes. It follows that the 250-employee threshold, in practice, is relevant only in entirely residual cases — as the Authority itself acknowledges in its official FAQs on the subject.
The cases indicated by the Authority
To convey how broad the pool of obliged parties is, the Authority lists, among others:
- shops and tradespeople with at least one employee — bars, restaurants, workshops, stores — or who process customers’ health data, such as beauticians, hairdressers and opticians;
- self-employed professionals with at least one employee, or who process health data or data relating to criminal convictions and offences: think of accountants, physiotherapists, pharmacists and, in general, healthcare practitioners;
- associations, foundations and committees that process special categories of data (sports clubs managing medical certificates, bodies protecting vulnerable people and the like);
- even condominiums, where they process special categories of data, as in the case of resolutions on removing architectural barriers.
Given the scope of these exceptions, the Authority nonetheless recommends that all controllers and processors keep the record, even outside the cases where it is mandatory, in line with recital 82 of the Regulation: it is a handy tool, suited to governing the processing and to establishing a cooperative dialogue with the Authority.
The simplification for SMEs
Organisations with fewer than 250 employees that are subject to the obligation can take advantage of a simplification: the record may be limited to the processing activities that trigger the obligation, without having to map the entire operation. To this end the Authority provides two “simplified record” templates for SMEs — one for the controller, one for the processor — in editable format. They are a useful starting point, provided they are adapted to the organisation’s actual situation: a template filled in generically is of little use.
What the record must contain
The minimum content is precisely set by Article 30(1) of the Regulation. The controller’s record must contain, for each processing operation:
- the name and contact details of the controller and, where appointed, of any joint controller, the representative and the data protection officer (DPO);
- the purposes of the processing, broken down by type (for example: managing the employment relationship of staff; managing orders to suppliers). It is advisable also to set out the legal basis under Article 6;
- the categories of data subjects and of personal data: the people involved (customers, suppliers, employees) and the type of data processed (identifying, health, biometric and so on);
- the categories of recipients to whom the data are or will be disclosed, including external parties appointed as processors;
- any transfers to third countries or international organisations, indicating the country and the safeguards provided;
- the retention periods, that is the time set for erasing the various categories of data; where no term can be fixed, the criteria for determining it must be indicated;
- a general description of the technical and organisational security measures adopted under Article 32. The list in Article 32 is open-ended: it is for the controller to assess, in practice, the level of security appropriate to the risks.
There is nothing to prevent the inclusion of further useful information, such as the impact assessments (DPIAs) carried out or the internal contacts identified for certain processing.
The controller’s record and the processor’s record
Article 30 distinguishes two documents. The controller’s record (paragraph 1) describes the processing decided on and carried out by the organisation for its own purposes. The processor’s record (paragraph 2), by contrast, concerns those who process data on behalf of others — an IT service provider, a payroll company, a software house — and lists the categories of activities carried out for each client controller.
Anyone acting as a processor for several clients will have to organise their record into separate sections, one for each controller, and may, in describing the processing, refer to what is already set out in the appointment act, which under Article 28 must specify the nature, purposes, types of data, categories of data subjects and duration of the processing. It should be added that the same party may be a controller for some processing and a processor for others: in such cases both records are needed.
In what form it is kept and how it is updated
The record must be in writing, including electronic form. No set format is prescribed: a suitably structured spreadsheet or a text document will do, provided the content meets the requirements of Article 30. On request, it must be shown to the Authority.
The most delicate aspect concerns updating. The record is a “living” document: it must correspond, at all times, to the processing actually carried out. Any significant change — a new purpose, a new category of data or of data subjects, a new external supplier — must be incorporated promptly. It is therefore good practice to note, in a verifiable way, both the date of first creation (or of creation of each entry) and that of the last update. A record that is not up to date is equivalent, in an inspection, to a missing record.
The most common mistakes
A few mistakes recur regularly in practice:
- Believing oneself exempt because of the 250 employees. This is the most widespread misunderstanding: as seen, the exceptions in Article 30(5) involve almost everyone.
- Adopting a generic template and failing to update it. A record reproduced in a standardised way and never revised does not reflect reality and will not withstand an inspection.
- Confusing purposes and legal bases, or neglecting the latter. Indicating the legal basis of each processing operation is what makes the record genuinely useful.
- Describing security measures vaguely, or, conversely, declaring there are none. The measures must be stated in summary, but consistently with what is actually in place.
- Omitting the processor’s record. Those who process data on behalf of others are often unaware that it even exists.
- Not dating creation and updates. Without such notes it is impossible to demonstrate that the record was kept over time.
What you risk: the penalty framework
On the penalty side, breaching the obligations on the record falls within the band set by Article 83(4)(a) of the Regulation: up to 10 million euros or, for undertakings, up to 2% of the total worldwide annual turnover of the preceding year, whichever is higher. It is the “lower” band compared with that reserved for the most serious breaches (Article 83(5)), but anything but symbolic.
It should be noted, moreover, that the Authority very rarely penalises the mere absence of the record. In practice, the failure to keep it, or its inadequacy, emerges in the context of broader investigations and contributes, together with other shortcomings, to defining the seriousness of the conduct and the size of the penalty.
This is confirmed by the Authority’s measure no. 278 of 17 December 2020, which imposed a penalty of 100,000 euros on Azienda USL Toscana Sud Est. Among the various breaches found, at the time of the investigation the body had not yet adopted the record of processing activities under Article 30; to this were added an act appointing a processor without the instructions required by Article 28, inadequate security measures and the failure to carry out the impact assessment.
The timing aspect is particularly instructive. The body had subsequently adopted the record, but late. The Authority observed that the Regulation had been applicable since 25 May 2018 and that the earlier period was intended precisely for getting into compliance: the late fulfilment, therefore, did not serve to avoid the penalty. It confirms a principle as elementary as it is binding: the record must be set up and kept up to date in good time, not reconstructed after the fact, once the investigation is already under way.
The record is not a document to draw up and file away, but a mirror of how an organisation governs personal data. Keeping it carefully today means moving with confidence tomorrow — in responding to a data subject, managing an incident or facing an inspection. Drawing it up correctly, or bringing an existing one into compliance, is a key part of the GDPR compliance of businesses and professionals. On the same theme, the article on the cookie banner may also be useful.
Frequently asked questions
Does the 250-employee threshold exempt you from the record? Almost never: the three exceptions in Article 30(5) — processing that poses a risk to rights, non-occasional processing, special categories of data — bring almost every controller back within the obligation. The ordinary handling of customer, supplier and employee data is, by its nature, non-occasional.
In what form must the record be kept? In writing, including electronic form: a properly structured spreadsheet or text document is adequate, provided its content meets the Article 30 requirements and it can be produced to the Authority on request.
Must someone who processes data on behalf of others keep one too? Yes: the processor keeps the record under Article 30(2), organised per client controller. Since the same entity may be a controller for some processing and a processor for others, both records may be needed.
This article is for information purposes and does not replace an assessment of the specific case.
This article is for general information only and is not legal advice on any specific case. Content reviewed by Giuseppe Foti, legal consultant — last checked on June 16, 2026.