Blog

Processing register mandatory or advisable: is it really necessary?

Processing register under the GDPR (Art. 30): when mandatory, content, and how to draft it. For SMEs holding customer or employee data.

Published on July 16, 2026 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

The processing register (Art. 30 GDPR) is an overview of all personal data processing activities within your company — which data, for what purpose, on what legal basis, how long retained, and with whom shared. It is legally mandatory for companies with 250+ employees or in the case of high-risk processing. For smaller SMEs, it is often still advisable — without a register, it is difficult to be GDPR-compliant. Below are details on content, exemptions, and how Tessa builds her register.

The short answer

  • Mandatory: for 250+ employees, high-risk processing, or regular processing of sensitive data.
  • Smaller SMEs: often exempt, but wise.
  • Content: per processing — data, purpose, legal basis, retention period, recipients.
  • Format: spreadsheet or HR tool, available internally.
  • Sanctions: AP fine for lack of register up to 2% of global turnover.

What is a processing register?

Processing register document

Internal overview of all activities involving the processing of personal data. For each processing activity:

  • Processing name (e.g. “payroll administration”).
  • Responsible person within the organization.
  • Categories of personal data (name, address, financial, health).
  • Categories of stakeholders (customers, employees, suppliers).
  • Purpose of processing.
  • Legal basis.
  • Recipients (internal and external).
  • Retention period.
  • Security measures.
  • International transfer (within/outside the EU).

When is it mandatory?

GDPR Register Checklist

Art. 30 GDPR: register mandatory unless exempt. Exemption only in the case of:

  • Company with fewer than 250 employees, AND
  • Processing is not structural (incidental), AND
  • No sensitive data (no race, religion, health, sexual life, etc.), AND
  • No high-risk processing for data subjects.

In practice: virtually every SME with customer or employee data is subject to the obligation.

What needs to be included? — per processing

FieldExample
Processing nameCustomer administration
ResponsibleSales manager
Data categoriesName, address, contact details, purchase history
Categories of stakeholdersPrivate customers
GoalCustomer management, marketing
BasisContract + legitimate interest
RecipientsSales team, email provider
Retention period7 years after last contact
SecurityAccess rolled, encryption
Outside the EUNo (or: yes, with SCC)

Standard processing for SMEs

  1. Customer administration.
  2. Supplier administration.
  3. Payroll and HR administration.
  4. Marketing database (newsletter).
  5. Customer support / helpdesk.
  6. Website cookies and analytics.
  7. Application procedures.
  8. Camera surveillance.
  9. Bookkeeping.
  10. Customer or supplier portal.

Separate line in register for each category.

Practical setup

  • Simple: spreadsheet: Excel template with columns per field.
  • Better: privacy tool: OneTrust, Trust-Hub, or HR tool with privacy modules.
  • For SMEs: their own spreadsheet is usually sufficient.

Update upon new processing or changes — the register must be up-to-date.

GDPR Impact Assessment (DPIA)

For high-risk processing: additional impact assessment (DPIA) mandatory. For example:

  • Large-scale profiling.
  • Camera surveillance in public spaces.
  • Automated decision-making.
  • Combination of sensitive data.

The DPIA goes deeper than the register — risk analysis and mitigation measures.

Tessa's register

Tessa builds register:

  • Spreadsheet with 12 operations.
  • Quarterly update.
  • With a new partner (e.g., email provider): new rule.
  • For a GDPR question from an employee or customer: consult the register for the answer.

Investment: 4 hours setup, 2 hours quarterly update. Upon AP audit: immediately available.

Honest recommendation

Privacy lawyer reviews register

For every SME with customers and employees: a processing register is almost always wise, and often mandatory. Start simply with a spreadsheet. Update with every new processing activity. For structural compliance: combine with a privacy statement, data processing agreements, and a data breach procedure. Invest a one-time 4-8 hours in setup — it prevents DPA fines and provides a basis for GDPR inquiries from data subjects.

For other topics: processor agreement,, privacy statement, and en data breach ..

Frequently Asked Questions

What is a processing register?

Internal overview (Art. 30 GDPR) of all personal data processing operations — which data, purpose, legal basis, recipients, retention period. Mandatory or highly recommended for SMEs holding customer or employee data.

When is it mandatory?

For 250+ employees, or structural processing, or sensitive data, or high-risk processing. Exemption only for small enterprises with incidental processing without sensitivities. In practice: virtually every SME with customers is required.

What needs to go in it?

Per processing: name, controller, categories of personal data, categories of data subjects, purpose, legal basis, recipients (internal/external), retention period, security measures, international transfer.

Which processing methods are typical?

Customer and supplier administration, payroll/HR, marketing, customer support, website analytics, job applications, camera surveillance, accounting, customer portal. For SMEs, 8-15 processing steps are typical.

How to build up?

Simple: Excel spreadsheet with columns per field. More advanced: privacy tool (OneTrust, Trust-Hub) or HR tool with a privacy module. For SMEs: spreadsheet usually sufficient. Update when changes occur.

What is a DPIA?

Data Protection Impact Assessment — supplementary to the register for high-risk processing: large-scale profiling, camera surveillance in public spaces, automated decision-making, sensitive data. Risk analysis and mitigation measures.

Sanctions for absence?

AP fine of up to 2% of global turnover or €10 million in the absence of a register. In the event of a GDPR question from a data subject or an incident: it is difficult to respond adequately without a register. The investment in setting it up (4-8 hours) pays for itself immediately.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

July 24, 2026

Having a non-compete clause drafted: costs and process

Having a non-compete clause drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom draft over a template.

July 24, 2026

Checking contracts: step-by-step plan for SME entrepreneurs

Checking or reviewing a contract before signing: step-by-step plan, red flags, checklist, and when you need a lawyer.

July 24, 2026

Having general terms and conditions drafted for contractors: costs and process

Having general terms and conditions for contractors drafted by a lawyer: what does it cost, how does the process work, and when do you choose custom work over...

July 23, 2026

Having general terms and conditions drafted: costs and process

Having general terms and conditions drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom-made version over a template.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation