Guide

The record of processing, without the legalese

What a record of processing activities is, who has to keep one, what each entry must contain, and how to keep the register current once the audit is over. Written for the team that has to maintain it, with the regulation itself linked at the end.

Published 2026-09-01 · Last reviewed 2026-09-01 · References verified 2026-08-31

One register, one entry per processing activity

Article 30 of the UK GDPR requires controllers to keep a record of the processing activities under their responsibility, and processors to keep a record of the processing they carry out for each controller. An activity is a unit of business reality: running payroll, operating CCTV, sending marketing email. The register is the set of those entries, each answering the same questions.

It is also the backbone of accountability in practice: the document a supervisory authority asks for first, and the one your own team consults when a subject access request needs the purposes and legal bases behind an answer.

The exemption is narrower than it looks

Article 30(5) exempts organisations employing fewer than 250 people, unless the processing is likely to result in a risk to people's rights and freedoms, is other than occasional, or includes special category or criminal-offence data. Routine processing such as payroll and HR records is not occasional, so in practice most organisations fall back inside the duty.

The ICO's documentation guidance is the authority on where the line sits, and it is linked in the references below. If you are relying on the exemption, write down why: the reasoning is itself the kind of record an authority expects to see.

The Article 30(1) checklist

For a controller, each record covers the items below. Two of them, the erasure time limits and the description of security measures, are qualified with "where possible" in the regulation itself. The register should still attempt both: the qualification is a concession to genuinely unknowable cases, and an inspector will read a blank field accordingly.

  1. a

    Name and contact details of the controller and, where applicable, the joint controller, the controller's representative, and the data protection officer

  2. b

    Purposes of the processing

  3. c

    Categories of data subjects and categories of personal data

  4. d

    Categories of recipients the data has been or will be disclosed to, including recipients in third countries

  5. e

    Transfers to third countries, and for certain transfers the documentation of suitable safeguards

  6. f

    Envisaged time limits for erasure of the different categories of data, where possible

  7. g

    General description of the technical and organisational security measures, where possible

Processor records under Article 30(2) are shorter: the controllers you process for, the categories of processing, the same transfer detail, and the same security description.

Electronic form is expected. Currency is the hard part.

Article 30(3) requires the record in writing, including in electronic form, and Article 30(4) requires you to make it available to the supervisory authority on request. Neither is difficult. The difficult obligation is implicit: a record of processing describes the present tense, so a register that no longer matches your processing has stopped being one.

Give every entry an owner and a next review date, and treat a lapsed review date as a defect to fix.

Building a first register

  1. 1

    List the processing you already know about

    Payroll, recruitment, CCTV, marketing, support, supplier management. Most organisations run the same core activities, which is why worked examples are a faster start than a blank page.

  2. 2

    Put each entry in front of the person who runs the process

    The legal basis, the recipients, and the retention period are facts about how your organisation works. The person running the process knows them; a template can only guess.

  3. 3

    Record what you can't yet answer

    A blank retention period you know about is worth more than a plausible one nobody checked. The gaps are the work list.

  4. 4

    Sign entries off, and schedule the review

    A register describes the present tense. An owner and a next review date per entry are what keep it true after the first pass.

This guide is general information, not legal advice. EmberHound supports the documentation and review work around a record of processing. It does not provide legal advice or guarantee compliance. Organisations should obtain specialist advice where processing presents significant regulatory risk.

Sources & references

  1. Article 30 - Records of processing activities, UK GDPR - legislation.gov.uk
  2. Documentation (records of processing activities) - ICO
  3. Article 6 - Lawfulness of processing, UK GDPR - legislation.gov.uk
  4. Regulation (EU) 2016/679 (General Data Protection Regulation), Official Journal text - EUR-Lex

Doing this properly, rather than in a spreadsheet

The EmberHound ROPA Workspace turns the steps above into a repeatable process: worked examples to start from, review and sign-off per entry, DSAR wiring, and a signed evidence pack.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy