EN Poser une question juridique →

GDPR: How to Maintain Your Record of Processing Activities

Business

The General Data Protection Regulation (GDPR) is no longer a novelty, but its day-to-day application remains a challenge for many businesses, associations, and public administrations in France. At the heart of this compliance lies a document that is often dreaded, yet absolutely indispensable: the record of processing activities. Far from being a mere administrative formality, this document is the cornerstone of your legal accountability and a strategic management tool for your organisation. Whether you are a sole trader, a SME director, or the head of a multinational corporation, understanding how to maintain this record in accordance with the requirements of the CNIL is essential to protect your clients, your employees, and your organisation against heavy financial penalties.

---

What is the record of processing activities and why is it mandatory?

The record of processing activities is an inventory and analysis document that lists all personal data processing activities carried out by an organisation. In other words, as soon as you collect, store, modify, or delete information that makes it possible to directly or indirectly identify a natural person (a name, an email, a telephone number, an IP address), you are carrying out a data processing operation that must appear in this record.

The legal basis: Article 30 of the GDPR

The obligation to maintain a record of processing activities is firmly anchored in European and national law. It is Article 30 of the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016) that establishes this obligation and precisely defines its scope.

This article distinguishes between two situations:

Each must maintain their own record, with slightly different mandatory details. In France, the Commission Nationale de l'Informatique et des Libertés (CNIL - the French data protection authority) is responsible for ensuring compliance with these provisions, in accordance with Law No. 78-17 of 6 January 1978 relating to information technology, files and liberties, as amended.

Who is exempt? The reality of the derogation

Article 30.5 of the GDPR provides for an exemption for companies or organisations employing fewer than 250 employees. However, this exemption is actually very restrictive. It does not apply if:

1. The processing is likely to result in a risk to the rights and freedoms of individuals.

2. The processing is not occasional (processing for payroll, client management, or supplier management is by definition regular and not occasional).

3. The processing includes sensitive data (political opinions, health data, criminal convictions, etc.).

In practice, 99% of organisations with fewer than 250 employees carry out non-occasional processing (payroll management, client invoicing). They must therefore obligatorily maintain a record, at least for these regular processing activities.

---

Substantive rules: what must the record contain?

To comply with the law, your record must be structured rigorously. Each processing sheet (which corresponds to a specific activity, such as "recruitment" or "newsletter management") must obligatorily contain the following information:

---

Practical steps: how to create and maintain your record in 5 steps

Setting up a record can seem like a monumental task. By proceeding methodically, you can transform this legal constraint into an excellent tool for mapping your information flows.

Step 1: Appoint the compliance leader

Before starting, determine who will be responsible for the project. If your organisation has appointed a Data Protection Officer (DPO), they will lead the process. Otherwise, designate an internal GDPR referent (often the legal counsel, the IT manager, or the business owner themselves).

Step 2: Identify all processing activities

For each department of your organisation (Human Resources, Marketing, Sales, Accounting, IT), list the activities that handle personal data.

Step 3: Collect information from operational teams

Interview the heads of each department to fill out the processing sheets. You need to know precisely: what data they collect, why, where it is stored, who has access to it, and when it is deleted. It is often during this step that "rogue" files (Excel spreadsheets on computer desktops) are discovered and must be regularised.

Step 4: Formalise the record

You can use different formats for your record. The CNIL offers a free, simplified record template in spreadsheet format (Excel/Calc) which is very well designed for VSEs/SMEs. You can also use dedicated GDPR governance software. The important thing is that the record must be easily editable and available in electronic format so that it can be presented quickly to the CNIL in the event of an audit.

Step 5: Keep the record alive and updated

The record is not a static document to be filed away in a drawer once completed. It must be updated regularly, as soon as a new processing activity is envisaged (for example, the installation of CCTV cameras or a change in payroll software). A minimum annual review is highly recommended.

---

Deadlines, sanctions, and key figures

Failure to comply with the obligations related to the record of processing activities exposes organisations to major legal and financial risks.

---

Concrete and quantified examples of compliance

To better understand the practical application of these rules, let us study two common scenarios in France.

Example 1: Thomas's physiotherapy practice

Thomas is a self-employed physiotherapist in Lyon. He employs 1 part-time medical secretary and manages a portfolio of 450 active patients. His data processing activities are not occasional and involve health data (sensitive data). He must obligatorily maintain a record.

In his record, Thomas will create three main sheets:

1. Patient file management (health data): The data (pathologies, prescriptions, mutual insurance details) are kept for 10 years from the last contact (ethical recommendation). The recipients are Thomas, his secretary, and health insurance bodies. Security measures include professional software with two-factor authentication and encryption of the practice's computer hard drive.

2. Payroll management for the secretary: Civil status data, RIB (bank account details), hours worked. Retention for 5 years (statute of limitations for wages). Recipient: the chartered accounting firm (processor).

3. CCTV of the practice: Thomas has installed 2 cameras to secure the waiting room and the entrance. The images are kept for a maximum of 30 days. An information sign is visible at the entrance.

Example 2: The e-commerce shop "ModeÉcolo"

The SAS (simplified joint-stock company) "ModeÉcolo" sells clothes online. It generates a turnover of €1,200,000 and employs 8 staff members. It collects the data of 15,000 clients and has a database of 50,000 prospects for its newsletter.

In its record, "ModeÉcolo" must notably detail:

1. Order and delivery management: Collection of names, delivery addresses, credit card numbers (via a secure payment provider, without plain text storage by the shop). Retention of client data for the duration of the contractual relationship, then archiving for 5 years (commercial statute of limitations) and 10 years for invoices (accounting obligation).

2. Commercial prospecting (Newsletter): Collection of the email address based on consent (active opt-in). Retention as long as the person does not unsubscribe, with automatic deletion after 3 years of complete inactivity.

---

Mistakes to avoid

When drafting or updating your record, be sure to avoid these classic pitfalls:

---

FAQ (Frequently Asked Questions)

Must the record of processing activities be sent to the CNIL as soon as it is created?

No. Unlike the old prior declarations that existed before 2018, you do not have to spontaneously send your record to the CNIL. You must keep it carefully internally. The CNIL will only request it in the event of an audit, a user complaint, or an investigation following a data breach.

Can the record be kept in a simple paper notebook?

Yes, the law does not impose a mandatory electronic format; the record can theoretically be kept in writing. However, in practice, the paper format is highly discouraged. It makes updates tedious, complicates information retrieval, and proves difficult to transmit quickly to the CNIL in a structured format in the event of an audit. A spreadsheet format (Excel, PDF) or an online tool is highly preferable.

What is the difference between the record of processing activities and the website's privacy policy?

The record of processing activities is an extremely detailed internal governance document that lists all of the company's processing activities (including human resources or supplier management). The privacy policy (or data protection charter) is an external document, written in simple and clear language, intended to inform the public (clients, internet users) of how their data is processed on a specific platform (such as a website). The privacy policy is derived from the information contained in the record.

What happens if I do not keep my record up to date?

A record that is not up to date is legally equivalent to an absence of a record. In the event of a CNIL audit, if the officers find that recent and significant processing activities (such as the implementation of a new geolocation system for company vehicles) do not appear in the record, you expose yourself to a formal notice, or even a direct financial penalty.

---

Summary

Legal information for guidance only, not personalised legal advice. For your specific situation, ask your question free of charge on AvocatAI — answers based on French law, in your language.

Content reviewed by the AvocatAI legal editorial team

This article is provided for information only and is not legal advice. Consult a lawyer for advice tailored to your situation.