MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
The processing register (Art. 30 GDPR) is an overview of all personal data processing activities within your company — which data, for what purpose, on what legal basis, how long retained, and with whom shared. It is legally mandatory for companies with 250+ employees or in the case of high-risk processing. For smaller SMEs, it is often still advisable — without a register, it is difficult to be GDPR-compliant. Below are details on content, exemptions, and how Tessa builds her register.
The short answer
- Mandatory: for 250+ employees, high-risk processing, or regular processing of sensitive data.
- Smaller SMEs: often exempt, but wise.
- Content: per processing — data, purpose, legal basis, retention period, recipients.
- Format: spreadsheet or HR tool, available internally.
- Sanctions: AP fine for lack of register up to 2% of global turnover.
What is a processing register?
Internal overview of all activities involving the processing of personal data. For each processing activity:
- Processing name (e.g. “payroll administration”).
- Responsible person within the organization.
- Categories of personal data (name, address, financial, health).
- Categories of stakeholders (customers, employees, suppliers).
- Purpose of processing.
- Legal basis.
- Recipients (internal and external).
- Retention period.
- Security measures.
- International transfer (within/outside the EU).
When is it mandatory?
Art. 30 GDPR: register mandatory unless exempt. Exemption only in the case of:
- Company with fewer than 250 employees, AND
- Processing is not structural (incidental), AND
- No sensitive data (no race, religion, health, sexual life, etc.), AND
- No high-risk processing for data subjects.
In practice: virtually every SME with customer or employee data is subject to the obligation.
What needs to be included? — per processing
| Field | Example |
|---|---|
| Processing name | Customer administration |
| Responsible | Sales manager |
| Data categories | Name, address, contact details, purchase history |
| Categories of stakeholders | Private customers |
| Goal | Customer management, marketing |
| Basis | Contract + legitimate interest |
| Recipients | Sales team, email provider |
| Retention period | 7 years after last contact |
| Security | Access rolled, encryption |
| Outside the EU | No (or: yes, with SCC) |
Standard processing for SMEs
- Customer administration.
- Supplier administration.
- Payroll and HR administration.
- Marketing database (newsletter).
- Customer support / helpdesk.
- Website cookies and analytics.
- Application procedures.
- Camera surveillance.
- Bookkeeping.
- Customer or supplier portal.
Separate line in register for each category.
Practical setup
- Simple: spreadsheet: Excel template with columns per field.
- Better: privacy tool: OneTrust, Trust-Hub, or HR tool with privacy modules.
- For SMEs: their own spreadsheet is usually sufficient.
Update upon new processing or changes — the register must be up-to-date.
GDPR Impact Assessment (DPIA)
For high-risk processing: additional impact assessment (DPIA) mandatory. For example:
- Large-scale profiling.
- Camera surveillance in public spaces.
- Automated decision-making.
- Combination of sensitive data.
The DPIA goes deeper than the register — risk analysis and mitigation measures.
Tessa's register
Tessa builds register:
- Spreadsheet with 12 operations.
- Quarterly update.
- With a new partner (e.g., email provider): new rule.
- For a GDPR question from an employee or customer: consult the register for the answer.
Investment: 4 hours setup, 2 hours quarterly update. Upon AP audit: immediately available.
Honest recommendation
For every SME with customers and employees: a processing register is almost always wise, and often mandatory. Start simply with a spreadsheet. Update with every new processing activity. For structural compliance: combine with a privacy statement, data processing agreements, and a data breach procedure. Invest a one-time 4-8 hours in setup — it prevents DPA fines and provides a basis for GDPR inquiries from data subjects.
For other topics: processor agreement,, privacy statement, and en data breach ..
Frequently Asked Questions
Internal overview (Art. 30 GDPR) of all personal data processing operations — which data, purpose, legal basis, recipients, retention period. Mandatory or highly recommended for SMEs holding customer or employee data.
For 250+ employees, or structural processing, or sensitive data, or high-risk processing. Exemption only for small enterprises with incidental processing without sensitivities. In practice: virtually every SME with customers is required.
Per processing: name, controller, categories of personal data, categories of data subjects, purpose, legal basis, recipients (internal/external), retention period, security measures, international transfer.
Customer and supplier administration, payroll/HR, marketing, customer support, website analytics, job applications, camera surveillance, accounting, customer portal. For SMEs, 8-15 processing steps are typical.
Simple: Excel spreadsheet with columns per field. More advanced: privacy tool (OneTrust, Trust-Hub) or HR tool with a privacy module. For SMEs: spreadsheet usually sufficient. Update when changes occur.
Data Protection Impact Assessment — supplementary to the register for high-risk processing: large-scale profiling, camera surveillance in public spaces, automated decision-making, sensitive data. Risk analysis and mitigation measures.
AP fine of up to 2% of global turnover or €10 million in the absence of a register. In the event of a GDPR question from a data subject or an incident: it is difficult to respond adequately without a register. The investment in setting it up (4-8 hours) pays for itself immediately.