The short answer: if your business has customers or employees, it keeps a record of processing activities, even with three people on the payroll. The exemption for organisations under 250 employees exists, but it is much narrower than the usual one-line summary suggests. Here is the text, a three-question test, and a method for getting it done in an afternoon without a law firm.
Disclaimer: this article is provided for information only and does not constitute legal advice. For a specific situation, consult a qualified legal professional or your data protection officer.
Article 30 of the GDPR requires the controller to maintain a record of processing activities. Paragraph 5 states that this obligation "shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10".
Three exceptions, any one of which removes the exemption on its own:
The word that changes everything is "occasional". A customer file, invoicing, payroll, a newsletter, a contact form handled every week: none of these is occasional. The European data protection authorities said so in 2018 (Article 29 Working Party position paper on the derogations from the obligation to maintain records, 19 April 2018): the exemption is assessed processing activity by processing activity. A small company records its regular activities and may leave out the ones that are genuinely one-off.
| Question | If yes |
|---|---|
| 1. Do you have at least one regular processing activity? Customers, employees, prospects, suppliers, website visitors with audience measurement. | Keep a record for those activities. This covers almost every business. |
| 2. Do you process special-category data or data on criminal convictions? Health data (a practice, a gym, a pharmacy), opinions, biometric data, a candidate's criminal record. | Keep a record, and pay particular attention to the legal basis for those activities. |
| 3. Does any activity carry a particular risk? Profiling, geolocation, employee monitoring, children's data, large scale. | Keep a record, and probably carry out an impact assessment (article 35) as well. |
In practice, the exemption is there so that you do not have to document the anecdotal: the attendee list for a single event, for instance. It does not exempt the business as such.
Article 30(1) sets out the content, for each processing activity:
The record is kept in writing, including in electronic form (paragraph 3), and made available to the supervisory authority on request (paragraph 4). It is not published: it is an internal document.
The record is built by purpose. For a small services or retail business, the list often fits in seven lines:
The CNIL publishes a simplified record template in spreadsheet form, designed for small organisations. One row per activity, the seven columns above. There is no need to buy software.
Hosting provider, emailing tool, CRM, payment provider, accountant, analytics tool, appointment-booking service. What your website loads is a good starting point: the third-party services called by your pages are, almost always, recipients of data that belong in the record.
One period per activity, based on the reference periods published by the CNIL and on statutory retention duties. Two common examples: prospect data is generally kept for three years after the last contact; accounting records and invoices are kept for ten years under the Code de commerce. Check each period against your own sector.
Note the date of the last update and the name of the person keeping the record. Add a row for every new tool or activity. A record from 2019 that has never been reopened is barely better than no record at all.
The work described above produces an inventory: activities, data, recipients, retention periods. That inventory feeds the record, an internal document, and the privacy policy, a public document required by articles 13 and 14 of the GDPR. Doing one without the other means doing the same work twice. We recommend starting from the record and deriving the policy from it.
The free Sitetals check reviews your home page and lists the third-party services it loads, along with whether an accessible privacy policy is present. It is a useful starting point for the "recipients" column of your record. It does not replace the internal inventory described above.
Also worth reading:
Sources: Regulation (EU) 2016/679, articles 9, 10, 13, 14, 30 and 35 · CNIL, "Le registre des activités de traitement" and simplified record template · Article 29 Working Party, position paper on the derogations from the obligation to maintain records (19 April 2018) · Sitetals methodology.
Sitetals editorial team