Record of processing activities: how to build one

What a record of processing activities is, what goes into it, and how to build it and keep it current in four steps.

The record of processing activities is the list of all the ways your organization uses personal data. It is usually the first document requested in an inspection and the basis for almost every other obligation: without knowing what you process, you cannot protect it or answer people's requests.

What is recorded for each activity

  • Who the controller is and how to contact them.
  • The purpose of the processing.
  • The categories of people and of data.
  • Who the data is disclosed to.
  • Transfers abroad, if any.
  • How long the data is kept.
  • A general description of the security measures.

How to build it in four steps

  • Talk to every department. HR, sales, marketing, finance and IT use personal data in ways management often does not know about.
  • Write one line per purpose, not per system. Payroll is one activity even if it uses three applications.
  • Record the legal basis for each activity as well. You need it anyway, and this is the most natural place to keep it.
  • Assign an owner and a review date.

How to keep it current

The record goes out of date quickly. Tie it to the processes that bring change: buying a new system, a new marketing campaign or a new supplier should automatically trigger an update. A full review once a year catches what slipped through.

Related serviceLaw 124 and GDPR ComplianceData mapping, record of processing activities, policies, DPIAs and readiness for an inspection by the Commissioner.Learn more

Let's talk about your next engagement.

Tell us about your engagement — we typically respond within one business day.

WhatsApp +355 69 522 4573