Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

GDPR Article 30 records of processing for controllers and processors

Records of Processing: Why the 250-Employee Exemption Fails

Records of processing under GDPR Article 30 are the document a supervisory authority asks for first, and the one most organisations under 250 employees believe they do not need.

That belief is usually wrong, and the reason is a single word in Article 30(5).

The records of processing exemption that almost never applies

Article 30(5) does say the obligation does not apply to an enterprise or organisation employing fewer than 250 persons. Then it adds three exceptions, and any one of them removes the exemption.

The obligation applies anyway where:

  • the processing is likely to result in a risk to the rights and freedoms of data subjects;
  • the processing is not occasional; or
  • the processing includes special categories of data under Article 9(1), or criminal conviction and offence data under Article 10.

The second one settles it for nearly everybody. Paying employees is not occasional. Holding a customer database is not occasional. Routine, ongoing processing is the opposite of occasional, and virtually every organisation does some.

Note also that the exception is about risk being likely, not high risk — a lower bar than the DPIA trigger in Article 35.

The practical position: if you have staff and customers, assume records of processing are required and spend your energy on making the record useful rather than on arguing you are exempt.

What the controller records of processing must contain

What GDPR Article 30 requires in records of processing for controllers and processors

Article 30(1) says the record shall contain all of the following — there is no “where appropriate” on the list as a whole:

  • Contact details of the controller, any joint controller, the representative and the data protection officer.
  • The purposes of the processing.
  • Categories of data subjects and categories of personal data.
  • Categories of recipients to whom the data have been or will be disclosed, including recipients in third countries or international organisations.
  • Transfers to a third country or international organisation, identifying it — and for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards.
  • Where possible, the envisaged time limits for erasure of the different categories of data.
  • Where possible, a general description of the technical and organisational security measures referred to in Article 32(1).

Only the last two carry “where possible”. The rest are unqualified — which means a record with blank purposes or unnamed recipient categories is incomplete on the face of it.

Processors keep their own records of processing

This is the part processors routinely miss: Article 30(2) places a separate, independent obligation on the processor. It is not satisfied by appearing in a client’s record.

The processor record covers all categories of processing carried out on behalf of a controller, and contains:

  • Contact details of the processor, and of each controller it acts for, plus any representative and the DPO.
  • The categories of processing carried out on behalf of each controller.
  • Transfers to third countries or international organisations, with the same identification and safeguard documentation.
  • Where possible, a general description of the Article 32(1) security measures.

Notice what is absent: purposes, categories of data subjects, categories of personal data and retention periods are not in the processor list. That is deliberate — those belong to the controller, whose record carries them. A processor that copies the controller template is documenting decisions it does not own.

Form and disclosure of records of processing

Article 30(3) requires records of processing to be in writing, including in electronic form. A spreadsheet is fine. A shared understanding is not.

Article 30(4) requires the controller or processor — and where applicable the representative — to make the record available to the supervisory authority on request.

That last obligation is why this document matters more than its dull name suggests. It is frequently the opening request in an investigation or complaint, and it is read as a proxy for whether the organisation knows what it is doing. A thin or contradictory record shapes everything that follows.

What records of processing unlock

Treated as a compliance chore, records of processing produce a spreadsheet nobody opens. Treated as an inventory, it is the foundation several other obligations quietly assume:

Obligation What it takes from the record
DPIA Article 35(7)(a) requires a systematic description of the processing and purposes. Most DPIA delays are really inventory delays
Data subject rights You cannot answer an access or erasure request across systems you have not listed
Breach notification Under time pressure, the record tells you what categories and whose data are involved
Data governance The same inventory, with ownership and quality added. Build one, not two

The same artefact also does most of the work for India’s DPDP Act and CCPA obligations, which is the strongest argument for maintaining it properly rather than annually.

Where to start with records of processing

  1. Stop testing the 250-person exemption. If your processing is not occasional, it does not apply.
  2. Decide your role per activity — controller, joint controller or processor — because it determines which list you complete.
  3. Complete the unqualified fields fully. Only erasure limits and the security description are softened by “where possible”.
  4. Name recipient categories including those in third countries, and link each transfer to its safeguard.
  5. Keep it current by trigger, not annually — a new system, supplier or purpose should update it.
  6. Build it as the inventory your DPIAs, rights requests and breach response will draw on.

This guide reflects Regulation (EU) 2016/679 as published on EUR-Lex, read at 15 August 2026.

The GDPR Toolkit provides 100+ editable templates including separate controller and processor records of processing, the DPIA template and screening questionnaire, retention schedules and the data subject rights procedures.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.