← All postsHow-to

Record of processing activities: the inventory everything else depends on

A record of processing activities lists what personal data you hold, why, where it goes and how long you keep it. It is dull to build and it answers half the questions anyone will ever ask you.

How-toR

A record of processing activities is a structured inventory of what personal data your organisation handles: what you collect, why, on what basis, who you share it with, where it is stored and how long you keep it. Under the GDPR it is a specific obligation with defined content, and comparable requirements appear in other regimes. Even where none applies to you, it is the document that makes every other data question answerable.

It has a reputation as bureaucracy, and the reputation is earned by the way it is usually produced — filled in once from a template to satisfy a customer questionnaire, then never opened. Built as a working inventory instead, it is the thing you reach for when a subject access request arrives, when a supplier is being assessed, or when someone asks whether you can legally send that email.

What a record of processing activities contains

  • Each processing activity, described by purpose rather than by system — recruitment, payroll, customer support, marketing.
  • The categories of individual involved: customers, employees, candidates, website visitors.
  • The categories of data held for each, flagging anything sensitive.
  • Why you process it, and the legal basis where your regime requires one.
  • Who it is shared with — suppliers, processors, authorities — and under what agreement.
  • Where it is stored, including whether it leaves your country or region.
  • The retention period, or the rule that determines it.
  • The security measures relied on, described honestly.
  • An owner for each activity, and the date it was last reviewed.

Organise by purpose, not by tool. A list of software tells you nothing about why data is held, and it goes stale every time you switch a product. Recruitment as an activity survives changing the applicant tracking tool; a row named after the tool does not.

Building one without stopping work for a month

  1. List the activities first — most small companies have between eight and fifteen.
  2. For each, ask who the data is about and what fields you actually hold.
  3. Trace where it goes: which suppliers touch it, and whether any are outside your region.
  4. Write the retention period, or say plainly that it has not been decided — an honest gap is better than an invented number.
  5. Assign each activity to a named owner in the business, not to the person compiling the record.
  6. Check the result against reality by asking each owner whether anything is missing.
  7. Set a review date and attach it to something that already happens, such as onboarding a new supplier.
  8. Update it when a new tool is adopted, which is the moment it usually goes out of date.

What it exposes

Two findings are near-universal. The first is data nobody remembered: an old spreadsheet of leads, a mailbox of applications from three years ago, an analytics tool switched on once. The second is retention — most companies discover they keep everything indefinitely because no one ever decided otherwise, which is both a risk and, in several regimes, a breach in itself.

The register also makes supplier assessment tractable. Once you can see which activities involve which providers, the question of who holds your data has a written answer instead of a guess, and the overlap between them becomes visible.

Who has to keep one

Obligations vary. The GDPR requires records from most organisations, with a limited exemption for very small ones that does not apply as broadly as people assume — it falls away where processing is regular, involves sensitive categories, or poses risk to individuals. Other regimes have their own rules. Check what applies to you rather than relying on a summary, and treat the legal-basis column as something to get right with advice rather than by picking the option that sounds best.

Where to keep it

Ettex Records is built for exactly this shape: one row per processing activity, with fields for purpose, data categories, recipients, storage location, retention, owner and review date, filterable to what is overdue or what involves a given supplier. A living table beats the usual fate of a spreadsheet that forks into four versions.

What it does not do: there is no template pre-filled for any regime, no legal-basis guidance, no data discovery scanning your systems to find personal data, and no compliance reporting. The inventory is compiled by people who know the business, and the legal judgements belong with someone qualified.

Frequently asked

What is a record of processing activities?

A structured inventory of the personal data an organisation processes: purposes, categories of people and data, recipients, storage locations, retention periods and owners.

Should it be organised by system or by purpose?

By purpose. Purposes are stable; tools change, and a register named after tools goes stale immediately.

Does a small company need one?

Often yes. The exemption for small organisations under the GDPR is narrower than assumed, and other regimes have their own rules — check what applies to you.

What does building one usually reveal?

Forgotten data nobody remembered holding, and retention periods that were never actually decided.

How often should it be updated?

On a set review cycle, and whenever a new tool or supplier is adopted — that is when it usually falls out of date.

Is it the same as a data map?

Closely related. A data map often focuses on flows and locations; the record adds purposes, legal bases and retention.

One row per purpose, an owner per row, an honest retention column, and an update triggered by adopting anything new.

EP
Written by Elena P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.