Blog

Processing register mandatory or advisable: is it really necessary?

Processing register under the GDPR (Art. 30): when mandatory, content, and how to draft it. For SMEs holding customer or employee data.

Published on July 16, 2026 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

The processing register (Art. 30 GDPR) is an overview of all personal data processing activities within your company — which data, for what purpose, on what legal basis, how long retained, and with whom shared. It is legally mandatory for companies with 250+ employees or in the case of high-risk processing. For smaller SMEs, it is often still advisable — without a register, it is difficult to be GDPR-compliant. Below are details on content, exemptions, and how Tessa builds her register.

The short answer

  • Mandatory: for 250+ employees, high-risk processing, or regular processing of sensitive data.
  • Smaller SMEs: often exempt, but wise.
  • Content: per processing — data, purpose, legal basis, retention period, recipients.
  • Format: spreadsheet or HR tool, available internally.
  • Sanctions: AP fine for lack of register up to 2% of global turnover.

What is a processing register?

Processing register document

Internal overview of all activities involving the processing of personal data. For each processing activity:

  • Processing name (e.g. “payroll administration”).
  • Responsible person within the organization.
  • Categories of personal data (name, address, financial, health).
  • Categories of stakeholders (customers, employees, suppliers).
  • Purpose of processing.
  • Legal basis.
  • Recipients (internal and external).
  • Retention period.
  • Security measures.
  • International transfer (within/outside the EU).

When is it mandatory?

GDPR Register Checklist

Art. 30 GDPR: register mandatory unless exempt. Exemption only in the case of:

  • Company with fewer than 250 employees, AND
  • Processing is not structural (incidental), AND
  • No sensitive data (no race, religion, health, sexual life, etc.), AND
  • No high-risk processing for data subjects.

In practice: virtually every SME with customer or employee data is subject to the obligation.

What needs to be included? — per processing

FieldExample
Processing nameCustomer administration
ResponsibleSales manager
Data categoriesName, address, contact details, purchase history
Categories of stakeholdersPrivate customers
GoalCustomer management, marketing
BasisContract + legitimate interest
RecipientsSales team, email provider
Retention period7 years after last contact
SecurityAccess rolled, encryption
Outside the EUNo (or: yes, with SCC)

Standard processing for SMEs

  1. Customer administration.
  2. Supplier administration.
  3. Payroll and HR administration.
  4. Marketing database (newsletter).
  5. Customer support / helpdesk.
  6. Website cookies and analytics.
  7. Application procedures.
  8. Camera surveillance.
  9. Bookkeeping.
  10. Customer or supplier portal.

Separate line in register for each category.

Practical setup

  • Simple: spreadsheet: Excel template with columns per field.
  • Better: privacy tool: OneTrust, Trust-Hub, or HR tool with privacy modules.
  • For SMEs: their own spreadsheet is usually sufficient.

Update upon new processing or changes — the register must be up-to-date.

GDPR Impact Assessment (DPIA)

For high-risk processing: additional impact assessment (DPIA) mandatory. For example:

  • Large-scale profiling.
  • Camera surveillance in public spaces.
  • Automated decision-making.
  • Combination of sensitive data.

The DPIA goes deeper than the register — risk analysis and mitigation measures.

Tessa's register

Tessa builds register:

  • Spreadsheet with 12 operations.
  • Quarterly update.
  • With a new partner (e.g., email provider): new rule.
  • For a GDPR question from an employee or customer: consult the register for the answer.

Investment: 4 hours setup, 2 hours quarterly update. Upon AP audit: immediately available.

Honest recommendation

Privacy lawyer reviews register

For every SME with customers and employees: a processing register is almost always wise, and often mandatory. Start simply with a spreadsheet. Update with every new processing activity. For structural compliance: combine with a privacy statement, data processing agreements, and a data breach procedure. Invest a one-time 4-8 hours in setup — it prevents DPA fines and provides a basis for GDPR inquiries from data subjects.

For other topics: processor agreement,, privacy statement, and en data breach ..

Frequently Asked Questions

What is a processing register?

Internal overview (Art. 30 GDPR) of all personal data processing operations — which data, purpose, legal basis, recipients, retention period. Mandatory or highly recommended for SMEs holding customer or employee data.

When is it mandatory?

For 250+ employees, or structural processing, or sensitive data, or high-risk processing. Exemption only for small enterprises with incidental processing without sensitivities. In practice: virtually every SME with customers is required.

What needs to go in it?

Per processing: name, controller, categories of personal data, categories of data subjects, purpose, legal basis, recipients (internal/external), retention period, security measures, international transfer.

Which processing methods are typical?

Customer and supplier administration, payroll/HR, marketing, customer support, website analytics, job applications, camera surveillance, accounting, customer portal. For SMEs, 8-15 processing steps are typical.

How to build up?

Simple: Excel spreadsheet with columns per field. More advanced: privacy tool (OneTrust, Trust-Hub) or HR tool with a privacy module. For SMEs: spreadsheet usually sufficient. Update when changes occur.

What is a DPIA?

Data Protection Impact Assessment — supplementary to the register for high-risk processing: large-scale profiling, camera surveillance in public spaces, automated decision-making, sensitive data. Risk analysis and mitigation measures.

Sanctions for absence?

AP fine of up to 2% of global turnover or €10 million in the absence of a register. In the event of a GDPR question from a data subject or an incident: it is difficult to respond adequately without a register. The investment in setting it up (4-8 hours) pays for itself immediately.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

September 9, 2026

Having a statute of limitations interruption drafted: costs and process

Having a legal expert draft the interruption of the statute of limitations: what does it cost, how does the process work, and when should you choose custom work over a...

September 9, 2026

Drafting an agreement for hiring and leasing self-employed professionals: this is what should be included

Drafting an agreement for hiring and leasing freelancers? Read about the components that should be included, common mistakes, and when to consult a lawyer.

September 8, 2026

What are the general terms and conditions for companies that sell training and courses? Function and legal status

What are general terms and conditions for companies that sell education and courses? Explanation of the function, when you need it and where...

September 8, 2026

What is an order confirmation? Explanation and use

What is an order confirmation? Explanation of its function, when you need it, and what to look out for in the SME sector.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation