Article 30 GDPR

From GDPRhub
Article 30 - Records of processing activities
Gdpricon.png
Chapter 10: Delegated and implementing acts

Legal Text


Article 30 - Records of processing activities


1. Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information:

(a) the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the data protection officer;
(b) the purposes of the processing;
(c) a description of the categories of data subjects and of the categories of personal data;
(d) the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations;
(e) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;
(f) where possible, the envisaged time limits for erasure of the different categories of data;
(g) where possible, a general description of the technical and organisational security measures referred to in Article 32(1).

2. Each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing:

(a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's representative, and the data protection officer;
(b) the categories of processing carried out on behalf of each controller;
(c) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;
(d) where possible, a general description of the technical and organisational security measures referred to in Article 32(1).

3. The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.

4. The controller or the processor and, where applicable, the controller's or the processor's representative, shall make the record available to the supervisory authority on request.

5. The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.

Relevant Recitals

Recital 13: Harmonisation of Protection and Advantages for Small and Medium-Sized Enterprises
In order to ensure a consistent level of protection for natural persons throughout the Union and to prevent divergences hampering the free movement of personal data within the internal market, a Regulation is necessary to provide legal certainty and transparency for economic operators, including micro, small and medium-sized enterprises, and to provide natural persons in all Member States with the same level of legally enforceable rights and obligations and responsibilities for controllers and processors, to ensure consistent monitoring of the processing of personal data, and equivalent sanctions in all Member States as well as effective cooperation between the supervisory authorities of different Member States. The proper functioning of the internal market requires that the free movement of personal data within the Union is not restricted or prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data. To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping. In addition, the Union institutions and bodies, and Member States and their supervisory authorities, are encouraged to take account of the specific needs of micro, small and medium-sized enterprises in the application of this Regulation. The notion of micro, small and medium-sized enterprises should draw from Article 2 of the Annex to Commission Recommendation 2003/361/EC.

Recital 82: Maintenance and Availability of Records
In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of processing activities under its responsibility. Each controller and processor should be obliged to cooperate with the supervisory authority and make those records, on request, available to it, so that it might serve for monitoring those processing operations.

Recital 89: Abolishment of Indiscriminate General Notification
Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it did not in all cases contribute to improving the protection of personal data. Such indiscriminate general notification obligations should therefore be abolished, and replaced by effective procedures and mechanisms which focus instead on those types of processing operations which are likely to result in a high risk to the rights and freedoms of natural persons by virtue of their nature, scope, context and purposes. Such types of processing operations may be those which in, particular, involve using new technologies, or are of a new kind and where no data protection impact assessment has been carried out before by the controller, or where they become necessary in the light of the time that has elapsed since the initial processing.

Commentary on Article 30

Article 30 GDPR describes the obligation to maintain a record of processing activities. This means that each controller and processor has to establish a record of each processing activity that concerns personal data. The definition of processing activities corresponds with the definition of processing in Article 4(2) GDPR. The stipulation systematically goes hand in hand with the principles and obligations stated in Articles 5, 6, 12 GDPR.[1] Only when a record of processing activities exists, principles such as transparency, purpose, data minimization, accuracy, storage limitation and accountability etc., can be realized. It serves as a self-control mechanism to assess what kind of processing activities are at stake.[2] Moreover, Data Protection Impact Assessments (“DPIA”) are included in these records to legitimize the respective processing activity, in particular if there is a high risk for personal data. Therefore, technical and organizational measures also have to be mentioned in the record.

Another reason for maintaining records has to do with accountability. When either a data subjects enforces its rights (Article 12 GDPR) or a data protection authority requests information about processing (Articles 13 and 14 GDPR), all activities can easily be explained. A record of data processing activities is useful and eases the process of giving a data subject the information that have been asked for. The record can also help in drafting and keeping the privacy policy up to date. The record of processing activities also supports the controller in assessing its own processing as well as the one carried out by possible external processors.

(1) Record of Processing Activities

The obligation to record processing activities lays with the controller and not with the data protection officer.

Activities which have to be included in the non-exhaustive list are the following: (1) The name and contact details of the controller and related parties; (2) The purposes of the processing; (3) A description of the categories of data subjects and of the categories of personal data; (4) The categories of recipients; (5) Transfers of personal data to a third country or an international organisation and, in the case of the applicability of Article 49(1) GDPR, the documentation of suitable safeguards; (6) A data deletion concept; (7) A general description of the technical and organisational security measures referred to in Article 32(1) GDPR.

(2) Categories of Processing Activities

The processor has the obligations to record (1) the name and contact details of the controller on behalf of which the processor is acting; (2) The categories of processing carried out on behalf of each controller; (3) Transfers of personal data to a third country or an international organisation and, in the case of the applicability of Article 49(1) GDPR, the documentation of suitable safeguards; (4) A general description of the technical and organisational security measures referred to in Article 32(1) GDPR.

(3) Written Form

The records shall be in writing; this includes as well electronic formats. Chambers of Commerce as well as supervisory authorities in the EU provide for templates in PDF and Microsoft Word formats. In general, these records shall include processing activities, applications, responsible persons (“owners of data”) which is connected with the organisational structure of the respective company/organisation.

The obligation to keep the record up to date is not expressly regulated in the GDPR. However, if the record is not kept up to date, it is not possible to comply with the principles of transparency etc. and to provide the data protection authority with such records when requested.[3]

In addition, this leads to the question, whether the record needs to be electronically or has at least to provide for a timestamp, which is easier to trace in an electronic format. This means changes that have been made to the record need to be available to show ongoing compliance. Due to the principle of accountability (Article 5(2) GDPR), changes have to be transparent and traceable, e.g. who has been the controller/processor or data protection officer etc. at a certain point in time. This kind of documentation of changes should be kept for a certain amount of time.[4]

(4) Provision to Supervisory Authority

The supervisory authorities can assess controllers and processor as general control measure, but also in case of data breaches and complaints of data subjects. This is why a records of processing activities needs to be available at any time to provide the supervisory authority with it upon request.

(5) Exceptions

An enterprise or an organisation employing less than 250 persons is not obliged to implement the record of processing. However, the exception is not applicable if such an organisation carries out processing that is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data (Article 9(1) GDPR) or personal data relating to criminal convictions and offences referred to in Article 10 GDPR.

Decisions

→ You can find all related decisions in Category:Article 30 GDPR

References

  1. Hartung, in Kühling, Buchner, DS-GVO BDSG, Article 30 GDPR, margin number 11 (Beck 2020, 3rd ed.) (accessed 19 August 2021).
  2. Cf. Hartung, in Kühling, Buchner, DS-GVO BDSG, Article 30 GDPR, margin number 12 (Beck 2020, 3rd ed.) (accessed 19 August 2021).
  3. Hartung, in Kühling, Buchner, DS-GVO BDSG, Article 30 GDPR, margin number 31 (Beck 2020, 3rd ed.) (accessed 19 August 2021).
  4. DSK, Datenschutzkonferenz, Hinweise zum Verzeichnis von Verarbeitungstätigkeiten, Art. 30 DS-GVO, February 2018, p. 3.