The record of processing activities is the list of all the ways your organization uses personal data. It is usually the first document requested in an inspection and the basis for almost every other obligation: without knowing what you process, you cannot protect it or answer people's requests.
What is recorded for each activity
- Who the controller is and how to contact them.
- The purpose of the processing.
- The categories of people and of data.
- Who the data is disclosed to.
- Transfers abroad, if any.
- How long the data is kept.
- A general description of the security measures.
How to build it in four steps
- Talk to every department. HR, sales, marketing, finance and IT use personal data in ways management often does not know about.
- Write one line per purpose, not per system. Payroll is one activity even if it uses three applications.
- Record the legal basis for each activity as well. You need it anyway, and this is the most natural place to keep it.
- Assign an owner and a review date.
How to keep it current
The record goes out of date quickly. Tie it to the processes that bring change: buying a new system, a new marketing campaign or a new supplier should automatically trigger an update. A full review once a year catches what slipped through.
