What is the processing register?
The processing register is an overview of all personal data processing activities within your organisation. Art. 30 of the GDPR requires both controllers and processors to maintain such a register.
The register is not intended as a public document, but must be available for inspection by the supervisory authority upon request.
Who must maintain one?
In principle, the processing register is mandatory for all organisations. Art. 30(5) GDPR contains an exception for organisations with fewer than 250 employees, but this exception does not apply when:
- The processing is likely to result in a risk to the rights and freedoms of data subjects
- The processing is not occasional (i.e. it takes place regularly)
- Special categories of data are processed (health data, criminal records, etc.)
In practice, this means that virtually every organisation must maintain a processing register. Any organisation with employees or a customer database regularly processes personal data.
What must it contain? (controller)
The controller's register must contain at minimum per Art. 30(1) GDPR:
- Name and contact details of the controller (and DPO if applicable)
- Purposes of processing — why do you process the data?
- Categories of data subjects — whose data? (employees, customers, applicants, etc.)
- Categories of personal data — which data? (name, address, national ID, health data, etc.)
- Categories of recipients — with whom is the data shared? (vendors, government bodies, etc.)
- Transfers outside the EEA — any transfers to third countries and safeguards
- Retention periods — how long is data retained?
- Security measures — general description of technical and organisational measures
What must it contain? (processor)
If you act as a processor, your register per Art. 30(2) GDPR must contain:
- Name and contact details of the processor and each controller on whose behalf you process
- The categories of processing carried out on behalf of each controller
- Any transfers outside the EEA
- General description of security measures
Example: payroll processing activity
An example entry in the processing register:
- Processing activity: Payroll administration
- Purpose: Calculation and payment of employee salaries
- Legal basis: Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
- Categories of data subjects: Employees
- Categories of data: Name, address, national ID number, bank account, salary data
- Recipients: Payroll provider (processor), tax authority, pension fund
- Retention period: 7 years after end of employment (statutory retention)
- Security: Encrypted storage, role-based access control, two-factor authentication
Example: newsletter processing activity
- Processing activity: Sending newsletters
- Purpose: Informing customers about products and services
- Legal basis: Consent (Art. 6(1)(a))
- Categories of data subjects: Customers and prospects
- Categories of data: Email address, first name
- Recipients: Email service provider (processor)
- Retention period: Until withdrawal of consent
- Security: Encrypted connection, processor ISO 27001 certified
Practical tips
- Start with the processing activities that carry the most risk
- Involve all departments — HR, marketing, IT, finance all process personal data
- Keep the register up to date: schedule quarterly reviews
- Link the register to your DPAs for a complete overview
- Use a tool like DPAkit to automatically generate your processing register based on your vendors
Summary
The processing register is a mandatory element of GDPR compliance for virtually every organisation. It provides you with oversight, demonstrates to the supervisory authority that you take privacy seriously, and forms the basis for other compliance activities such as DPIAs and breach procedures.