Records of Processing Activities
Map all your personal data processing activities and demonstrate your GDPR compliance.
What are the records of processing?
The records of processing activities is a mandatory document under GDPR Article 30. It lists all personal data processing activities carried out by the organisation and is the cornerstone of GDPR compliance.
For each processing activity, the records document the purposes, legal bases, categories of data collected, data subjects, recipients, retention periods, processors involved, transfers outside the EU and security measures in place.
Beyond the legal obligation, the records serve as an essential management tool: they provide a comprehensive view of data flows within the organisation, form the basis for Data Protection Impact Assessments (DPIAs) and enable demonstration of compliance during inspections by the data protection authority.
The records are a living document that must be updated with every change: new processing activity, modification to existing processing, change of processor, regulatory evolution.
GDPR obligation mandatory records
of processing activities mapped
ongoing integration
How do we proceed?
Creating and maintaining the records follows a structured four-phase approach.
Processing inventory
Interviews with department heads and key personnel about their daily activities, with particular focus on the information lifecycle and data protection measures. Review of existing documentation: security policies, procedures, supplier and processor contracts.
Processing documentation
Each processing activity is documented in a structured record containing all elements required by Article 30: purpose, organisation's role, legal basis, data subjects, data categories, retention period, recipients, processors, transfers outside the EU and security measures.
Compliance review
Compliance review of each processing activity: verification of legal bases, adequacy of retention periods, analysis of flows to processors and recipients, identification of processing requiring a DPIA. Gap documentation with remediation recommendations.
Maintenance and updates
The records are a living document updated with every change: new processing, modification to existing processing, change of processor, regulatory evolution. The DPO (internal or outsourced) is involved in all new project initiatives to ensure compliance continuity.
Prerequisites
Access to department heads and key personnel in the organisation. Existing documentation: organisation chart, internal policies, processor contracts. Mapping of information systems and data flows. A dedicated client-side contact for engagement oversight.
Public administration
Complete inventory and ongoing maintenance of the records of processing
As part of a GDPR compliance engagement with a public administration, Tomeris carried out a complete inventory of personal data processing activities. Interviews with department heads enabled mapping of all data flows and creation of records compliant with GDPR Article 30.
Each processing activity was documented, analysed and assigned to an internal owner. The records cover all administration activities: human resources, information systems, data breach management and specific business processes.
Following this engagement, Tomeris is now responsible for maintaining the records over time. Every new project or organisational change triggers a records update, ensuring continuous compliance and always up-to-date documentation.
A living register, continuously maintained, that evolves with the organisation and guarantees lasting GDPR compliance.
Results
Need to bring your records into compliance?
Map your personal data processing activities and keep your records up to date with expert support.