MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Did you know that the exemption for the processing register for small businesses almost never applies in practice? Although the law refers to a threshold of 250 employees, the rule regarding non-incidental processing makes drawing up a register of processing activities mandatory for virtually every SME entrepreneur. Whether you manage payroll or send a simple newsletter, the law requires you to know exactly how data flows within your organization.
It is perfectly understandable that you view the GDPR as a time-consuming puzzle, with the fear of hefty fines from the Data Protection Authority always playing a role in the background. You want to do business, not drown in complex legal documentation. In this guide, you will learn how to set up a GDPR-compliant register that not only complies with the law but also gives you back control over your own privacy administration. We discuss the exact steps to efficiently get your affairs in order so that you can focus on growing your business with peace of mind.
Key Points
- Discover why the processing register forms the indispensable basis of your accountability obligation and how it helps you with questions from the supervisor.
- Learn why compiling a register of processing activities is mandatory for almost every SME entrepreneur, even if you have fewer than 250 employees.
- Get a clear overview of the mandatory components under Article 30 of the GDPR so that your administration complies with all legal requirements.
- Follow a concrete step-by-step plan to inventory data flows within your organization and accurately define the goals of each processing activity.
- Understand the risks of using standard templates and how customization ensures true legal certainty and peace of mind in your business operations.
What is a register of processing activities and why is it mandatory?
A register of processing activities is essentially your organization's internal logbook regarding privacy. It is a central document in which you precisely record which personal data you process, for what purpose you do so, and with whom you share this information. Since the introduction of the General Data Protection Regulation (GDPR) , this document is no longer a luxury, but a strict requirement for almost every entrepreneur. It provides you with the necessary overview to maintain control over the data flows within your company. Think of it as a blueprint of your entire information management system.
When the Dutch Data Protection Authority (AP) comes knocking for an inspection or a corrective discussion, this register is often the first document they ask for. The AP's 2025 annual report shows that the regulator is increasingly opting for guidance and corrective discussions rather than issuing fines immediately. Drawing up a good register of processing activities immediately demonstrates that you take your privacy matters seriously and are transparent about your working methods. Without this document, you are left legally empty-handed during such an inspection. The sober reality is that by doing so, you demonstrate that you are 'in control'.
Accountability under the GDPR
The core of current privacy legislation revolves around accountability. This means that you no longer only have to comply with the law, but must also be able to prove this to the outside world at any time. The processing register serves as your primary evidence to the supervisory authority in this regard. It demonstrates that you have actively considered the necessity of each data processing activity and the associated security measures. Transparency within your business operations is essential in this respect. By clearly mapping out your processes, you create peace of mind for yourself and certainty for your customers and employees. It is the foundation upon which your entire privacy policy rests, ensuring that legal challenges remain manageable for every SME entrepreneur.
The difference between a register and a privacy statement
Many entrepreneurs confuse the processing register and the privacy statement, but there is an essential difference between the two documents. The privacy statement is your calling card to the outside world. It tells your website visitors and customers in plain language what you do with their data. The processing register, on the other hand, is an internal document that goes much deeper and contains technical details regarding retention periods, recipients, and specific security methods. You need both documents for full compliance. Having a privacy statement drafted is crucial for your external communication, but internally, establishing a register of processing activities the only way to meet your legal burden of proof. One cannot exist without the other if you truly want to get your privacy administration in order and avoid fines.
Who must draw up a register of processing activities?
There is a persistent misconception that only large multinationals need to concern themselves with privacy administration. Many entrepreneurs point to the provision in the GDPR stating that organizations with fewer than 250 employees are exempt. In practice, however, this exception is so narrow that hardly any company can truly claim it. The question is not only how large your team is, but above all what you do with data on a daily basis.
The law states that the exemption lapses as soon as the processing is 'not incidental'. Consider, for example, your monthly payroll administration, maintaining a customer database, or the periodic sending of newsletters. Because these activities are a structural part of your business operations, compiling a register of processing activities a legal obligation for virtually every SME entrepreneur. Unjustifiably claiming an exemption can lead to unpleasant discussions with the supervisor, especially now that the Dutch Data Protection Authority (AP) is emphasizing transparency and personal responsibility in 2026.
The myth of the 250 employees
Even if you are a sole proprietor, you usually cannot avoid it. By law, the legislator defines structural processing as any action that recurs regularly to achieve your business objectives. Do you have a CRM system? Do you process customer payments? Then the processing is not incidental. The point is to get a grip on your processes before they pose a risk. The recommendations of the Dutch Data Protection Authority make it clear that the focus lies on the risk to the data subjects, not on the size of the office building. It is therefore wise to immediately ensure a solid foundation with the appropriate GDPR/privacy documentation.
When you, as an SME entrepreneur, really cannot do without it
There are situations where there is simply no room for discussion regarding the registration obligation. Does your company process special categories of personal data? This includes information about a person's health, religious beliefs, or biometric data. In sectors such as healthcare or financial services, the register is therefore always mandatory, regardless of whether you work alone or with a team. Furthermore, when your processing activities pose a potentially high risk to the rights of individuals, establishing a register of processing activities essential for your legal protection.
It offers you the necessary certainty to grow safely without having to fear legal pitfalls with every new customer. Compliance is not a brake on your business, but rather proof of professionalism towards your business partners. It shows that you treat other people's data with respect and in accordance with the rules, which is a crucial competitive advantage in today's market. If you would like a complete overview of all obligations applicable to your company, read our practical guide on GDPR compliance for SMEs in 2026.

The contents of the processing register: what do you need to record?
An empty Excel file can be quite intimidating when you start your privacy administration. What exactly do you put in it to comply with the law? Article 30 of the GDPR is very clear on this. It requires you to maintain a detailed record of all processes involving personal data. This starts with the basics: your own contact details and, where applicable, those of your Data Protection Officer (DPO).
A crucial part is describing the purposes. Here, many entrepreneurs make a mistake by remaining too vague. 'Marketing', for example, is too broad. Be specific by referring to 'sending weekly offers to active customers'. At the same time, you must be careful not to make the description so narrow that every minor change in your working method immediately requires an update to the register. A good balance ensures that compiling a register of processing activities remains a workable process rather than a daily administrative burden.
In addition, you record who the data subjects are, such as employees, website visitors, or suppliers, and which categories of data you retain about them. This includes name and address details, but also more sensitive information such as social security numbers or bank account numbers. Do not forget the retention periods and technical security measures either. The supervisory authority wants to see that you not only know what you hold, but also how you protect it and when you delete it.
Mandatory fields under privacy law
You must indicate for each processing activity whether data is shared outside the European Union. Do you use an American cloud service, for example? Then this must be recorded in your register. Group your data logically; put all personnel-related data together and do the same for your customer data. This keeps the structure clear for yourself and for any potential inspectors. Do not forget to also state the legal basis for the processing, such as the performance of a contract or a statutory obligation.
The distinction between controller and processor
Who is ultimately responsible for what is recorded in the register? That is you, as the data controller. You must also include your processors, such as the party handling your payroll or your software supplier, in the overview. There is a direct link between your register and the contracts you enter into with these parties. Would you like to know how to ensure this is legally watertight? Then read our guide on drafting a data processing agreement. After all, compiling a complete register of processing activities also means clearly mapping out your external relationships.
Step-by-step plan for compiling your processing register
a register of processing activities does not have to be a job for months if you approach the process methodically. It starts with creating an overview of daily operations. Follow these five steps to structure your privacy administration:
- Step 1: Inventory your departments. Look beyond just the IT department. Personal data is used everywhere; from recruitment by HR to invoicing by administration.
- Step 2: Determine the goals. For each process, ask yourself: why are we retaining this? Is it for a legal obligation, such as that of the tax authorities, or for a commercial interest?
- Step 3: Identify external recipients. Make a list of all parties that have access to your data. Think of your cloud provider, the external accountant, or a marketing agency.
- Step 4: Establish security. Describe how you protect the data. This concerns password policies and encryption, but also the physical security of your office building.
- Step 5: Schedule the review. The GDPR states that your register must be up to date. Schedule a check at least once a year to see if your processes have changed.
Inventory of data flows within your company
Creating a so-called 'data map' is the most effective way to get started. Begin with short interviews with key figures in each department. Simply ask them what information they receive, where they store it, and with whom they share it. This often reveals hidden processing activities that you would otherwise overlook. Consider, for example, camera surveillance at the entrance or license plate registration in the parking lot. This practical approach ensures that your register reflects reality and does not become a paper tiger. This gives you immediate insight into the risks your company faces.
Software versus Excel: how do you maintain an overview?
For many SME entrepreneurs, a manual register in Excel is an excellent starting point. It is accessible and costs nothing extra. However, there are downsides; version control becomes difficult as your business grows. Specialized GDPR software can offer a solution by sending automatic reminders for the annual review. Regardless of your choice, the most important thing is that the document 'comes to life'. During an audit by the Dutch Data Protection Authority, an outdated register is almost as damaging as having no register at all. Do you want to get started immediately with a professional foundation? View our services for GDPR/privacy documentation to set up your register legally correctly right away.
Legal certainty for your GDPR documentation
The internet is full of free templates for privacy registers. While this may seem like a tempting quick fix, it poses a significant risk for the SME entrepreneur. A standard format fails to take into account the specific data flows within your unique organization. Drafting a register of processing activities is not a simple tick-box exercise, but a process to mitigate your actual legal risks. Customization ensures that your documentation stands up during an audit and that you are not caught off guard by gaps in your records.
Moreover, there is a direct, inextricable link between your register and your other GDPR documents. If you indicate in your register that you share data with an external party, a comprehensive data processing agreement must be in place. When these documents do not align, a legal grey area arises. This makes you vulnerable in the event of data breaches or disputes with customers. By opting for an integrated approach, you create a watertight system in which all contracts and registers reinforce each other rather than contradict one another.
The risks of an incomplete register
The consequences of inadequate privacy administration are severe. The Dutch Data Protection Authority can impose fines of up to €10,000,000 or 2% of global annual turnover. Although the regulator will increasingly opt for a corrective dialogue in 2026, the power to impose fines remains a real leverage tool in cases of serious negligence. In addition to the financial risk, there is reputational damage. Nowadays, customers and business partners demand full transparency. An incomplete register weakens your position in legal disputes and can severely damage the trust of your key stakeholders. Do you know what to do if something goes wrong despite your precautions? Read on to learn how to legal advice regarding data breaches to effectively limit the damage in the event of a security incident.
How MKB Juristen supports you with GDPR compliance
We believe in a pragmatic approach where legal complexity is translated into workable solutions. Our advisors not only help you draw up a register of processing activities, but also look at the bigger picture of your business operations. This ensures that your internal processes align seamlessly with your external contracts. Do you already have agreements in place but have doubts about their content? With our ContractCheck™, we have an experienced legal expert screen your documents for privacy risks.
The goal is always to unburden you, so that you can focus on what you do best: running your business. We offer the peace of mind and predictability needed in a complex landscape of rules and obligations. Do you want to get your privacy matters in order immediately without being overwhelmed by legal jargon? Then contact us via mkbjuristen.nl for clear, tailored advice that suits your practice.
Take the step towards comprehensive privacy administration today
Privacy legislation is more than just a legal obligation; it is an opportunity to make your business operations more transparent and secure. You have seen that the 250-employee threshold almost never offers an exemption and that an up-to-date overview is essential to avoid hefty fines. Establishing a register of processing activities forms the indispensable basis for your legal protection and strengthens the trust of your business partners.
Do you want the assurance that your entire administration is GDPR-compliant without having to dive into complex legal details yourself? As a specialist for SMEs since 2009, MKB Juristen offers you pragmatic advice without unnecessary jargon. In recent years, we have helped more than 5,000 entrepreneurs get their legal affairs in order efficiently. Have your GDPR documentation professionally set up by MKB Juristen and immediately create peace of mind in your business operations. This allows you to continue focusing on the growth of your company with peace of mind.
Frequently asked questions about the processing register
Is a processing register mandatory for a self-employed professional?
Yes, in almost all cases, a self-employed professional must maintain a register. Although an exemption exists for organizations with fewer than 250 employees, this lapses as soon as processing is not incidental. Because matters such as invoicing, customer management, or sending newsletters recur structurally, you, as a self-employed professional, are legally obliged to map out your data flows. After all, it concerns the nature of your activities, not the size of your office.
What happens if I do not have a processing register during an inspection?
Without a register, you cannot comply with the accountability obligation, which immediately leads to problems during an audit by the Dutch Data Protection Authority. The supervisory authority can issue an official warning or schedule a corrective meeting to compel you to take action. In serious cases or in the event of repeated negligence, you risk an administrative fine that can amount to up to 2% of your annual turnover. The document is your only proof that you take privacy seriously.
Do I need to deposit or send my processing register somewhere?
No, you do not need to deposit the document anywhere or proactively send it to an authority. You keep the register internally within your organization, for example on a secure drive or in a protected cloud environment. The only situation in which you must hand it over is when the supervisory authority specifically requests it during an inspection or following a notification of a data breach. It is therefore purely an internal control tool.
How often do I need to update the register of processing activities?
You must update the register of processing activities as soon as a structural change occurs in your business processes. Examples include switching to a new CRM system or engaging a different marketing partner. Additionally, we recommend conducting a full review at least once a year. This ensures that the retention periods and security measures you have documented still align with daily practice in your company.
What is the difference between a processor and a controller?
The data controller is the party that decides why and how data is processed; this is usually your own company. A data processor is an external party that processes data on your behalf without having control over it. Examples of data processors include your hosting provider, cloud services, or an external administration office. In your register, you must clearly indicate which data processors you engage for specific processes to legally define your responsibility.
Do I also need to include paper files in the register?
Yes, paper files must be included in the register if they are part of a structured archive. The GDPR makes no distinction between digital and physical data. For example, if you keep personnel files in physical folders organized according to a specific system, this is a processing activity that you must document. You must then also describe the physical security, such as storing these folders in a locked cabinet in a secure room.
Can I use a standard template for my processing register?
You can use a template as a starting point, but compiling a register of processing activities always requires adaptation to your specific situation. Every company uses different software combinations and employs its own work processes. A standard template that is not adapted to your specific reality offers a false sense of security. The regulator will see right through this during an inspection. Customization is essential to demonstrate that you truly have control over your own data flows.
Are the names of my customers part of the processing register?
No, you do not need to include the names of individual customers in the register. The register is an overview of processes, not a copy of your database. You only list the categories of stakeholders, such as 'customers' or 'prospects'. In doing so, you indicate which types of data you process from them, such as name and address details or payment information. The goal is to provide insight into the existing flows, not to maintain a list of individuals.