Corrective action: fixing the cause rather than the symptom
A corrective action stops a problem recurring. Most of what gets recorded as one is a repair — the thing you do to the affected item, which changes nothing about the next occurrence.
A record of processing activities lists what personal data you hold, why, where it goes and how long you keep it. It is dull to build and it answers half the questions anyone will ever ask you.
A record of processing activities is a structured inventory of what personal data your organisation handles: what you collect, why, on what basis, who you share it with, where it is stored and how long you keep it. Under the GDPR it is a specific obligation with defined content, and comparable requirements appear in other regimes. Even where none applies to you, it is the document that makes every other data question answerable.
It has a reputation as bureaucracy, and the reputation is earned by the way it is usually produced — filled in once from a template to satisfy a customer questionnaire, then never opened. Built as a working inventory instead, it is the thing you reach for when a subject access request arrives, when a supplier is being assessed, or when someone asks whether you can legally send that email.
Organise by purpose, not by tool. A list of software tells you nothing about why data is held, and it goes stale every time you switch a product. Recruitment as an activity survives changing the applicant tracking tool; a row named after the tool does not.
Two findings are near-universal. The first is data nobody remembered: an old spreadsheet of leads, a mailbox of applications from three years ago, an analytics tool switched on once. The second is retention — most companies discover they keep everything indefinitely because no one ever decided otherwise, which is both a risk and, in several regimes, a breach in itself.
The register also makes supplier assessment tractable. Once you can see which activities involve which providers, the question of who holds your data has a written answer instead of a guess, and the overlap between them becomes visible.
Obligations vary. The GDPR requires records from most organisations, with a limited exemption for very small ones that does not apply as broadly as people assume — it falls away where processing is regular, involves sensitive categories, or poses risk to individuals. Other regimes have their own rules. Check what applies to you rather than relying on a summary, and treat the legal-basis column as something to get right with advice rather than by picking the option that sounds best.
Ettex Records is built for exactly this shape: one row per processing activity, with fields for purpose, data categories, recipients, storage location, retention, owner and review date, filterable to what is overdue or what involves a given supplier. A living table beats the usual fate of a spreadsheet that forks into four versions.
What it does not do: there is no template pre-filled for any regime, no legal-basis guidance, no data discovery scanning your systems to find personal data, and no compliance reporting. The inventory is compiled by people who know the business, and the legal judgements belong with someone qualified.
A structured inventory of the personal data an organisation processes: purposes, categories of people and data, recipients, storage locations, retention periods and owners.
By purpose. Purposes are stable; tools change, and a register named after tools goes stale immediately.
Often yes. The exemption for small organisations under the GDPR is narrower than assumed, and other regimes have their own rules — check what applies to you.
Forgotten data nobody remembered holding, and retention periods that were never actually decided.
On a set review cycle, and whenever a new tool or supplier is adopted — that is when it usually falls out of date.
Closely related. A data map often focuses on flows and locations; the record adds purposes, legal bases and retention.
One row per purpose, an owner per row, an honest retention column, and an update triggered by adopting anything new.
A corrective action stops a problem recurring. Most of what gets recorded as one is a repair — the thing you do to the affected item, which changes nothing about the next occurrence.
A conflict of interest policy is mostly a register and a habit. The point is not to forbid overlapping interests but to have them written down before anyone has reason to ask.
A performance review is a conversation with a written record attached. Most of what makes it useful happens in the eleven months before it, and most of what makes it dreaded is the surprise.