Article 30 GDPR : Maintaining Records of Processing Activities
Article 30 GDPR obliges controllers and processors to maintain comprehensive records of processing activities (purposes, data categories, recipients, transfers, retention periods, security measures), serving as the core cornerstone of accountability.
Mandatory Legal Content of the Register (Arts. 30(1) & 30(2) GDPR)
The records maintained by the controller must mandatorily contain the following information:
- Name and contact details of the controller, joint controllers, representative, and Data Protection Officer (DPO);
- Specific purposes of each processing activity;
- Description of the categories of data subjects and categories of personal data;
- Categories of recipients to whom the personal data have been or will be disclosed;
- Transfers of personal data to a third country or an international organisation and documentation of suitable safeguards (Art. 49(1) second subpara);
- Envisaged time limits for erasure of the different categories of data;
- General description of technical and organisational security measures (Art. 32(1)).
Scope and Narrow Limits of the Fewer Than 250 Employees Derogation (Art. 30(5) GDPR)
Article 30(5) provides an exemption for enterprises or organisations employing fewer than 250 persons, but its practical application is very narrow.
In practice, maintaining records remains mandatory whenever the processing is not occasional (e.g. payroll, customer relationship management), is likely to result in a risk to rights and freedoms, or involves special categories of data (Art. 9) or criminal convictions (Art. 10). Maintaining processing records is the indispensable foundation of demonstrable accountability.
Verified Official Sources
General Data Protection Regulation — EU Reference Legal Framework
Consult official source →Transparence (Art. 12, 13, 14), langage clair, information par couches
Consult official source →See Also in the Legal Framework
Article 5 GDPR: Cardinal Processing Principles & Accountability
Legal analysis of the cardinal principles in Article 5 GDPR: lawfulness, fairness, transparency, purpose limitation, dat...
Article 28 GDPR: Data Processing Agreement & Mandatory Clauses
Comprehensive guide to Article 28 GDPR: mandatory clauses of the Data Processing Agreement (DPA), controller and process...