Skip to main content
Category: Scope & Exemptions

250-Employee Exemption

Also known as: Article 30(5) exemption, small and medium-sized organisation record-keeping exemption, 250-employee myth
Simply put

The 250-Employee Exemption refers to a limited relief under data protection law that reduces the record-keeping obligations for organisations with fewer than 250 staff. It is commonly misunderstood as a blanket exemption from data protection rules for smaller organisations, but this is not correct, it only narrows one specific documentation duty, and even that relief falls away in certain situations. Organisations under 250 employees still generally have to comply with the rest of their data protection obligations.

Formal definition

The term describes the qualified derogation associated with Article 30(5) of the UK GDPR (and the corresponding EU GDPR provision) concerning the obligation to maintain records of processing activities (ROPA). Per ICO guidance, an organisation employing fewer than 250 people needs only to document processing in more limited circumstances rather than being wholly relieved of the record-keeping duty; the relief is subject to conditions, so that an organisation below the threshold may still be required to keep records where its processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or involves special category or criminal offence data (practitioners should verify the precise conditions against the current text of Article 30(5)). The label '250-employee exemption' is widely characterised as a myth insofar as it does not confer a general exemption from the GDPR as a whole, it addresses only one accountability documentation obligation and does not affect other duties such as lawful basis, transparency, security, or data subject rights. Note that the EU and UK regimes may diverge over time and that member state or national implementing law can affect the position; readers should confirm current requirements against the applicable regulatory text and guidance.

Why it matters

The 250-Employee Exemption is one of the most persistently misunderstood provisions in data protection practice. Many smaller organisations and startups assume that having fewer than 250 employees means they are exempt from the GDPR, or at least from the bulk of its obligations. This is incorrect. As the ICO's guidance and commentary on the so-called '250-employee myth' make clear, the relief attaches only to the duty to maintain records of processing activities (ROPA) under Article 30(5), it is not a general exemption from the Regulation as a whole. Treating it as such can leave an organisation exposed on obligations it never addressed, including lawful basis, transparency, security, and data subject rights.

The practical significance is that the relief is both narrow and conditional. Even the limited documentation relief typically falls away where an organisation's processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or involves special category or criminal offence data. Because many businesses, regardless of headcount, carry out processing that meets one of these triggers, a large number of sub-250 organisations may in practice still need to maintain records. Practitioners should verify the precise conditions against the current text of Article 30(5) rather than relying on the headcount figure alone.

Misreading the exemption also risks distracting from the broader accountability principle. Documentation is only one element of demonstrating compliance, and an organisation that assumes it is off the hook for record-keeping may fail to build the wider governance it still needs. The scope of the relief, and any divergence between the EU and UK regimes over time, should be confirmed against current regulatory guidance and the applicable text.

Who it's relevant to

Startups and small businesses
Smaller organisations are the group most likely to encounter, and misapply, this exemption. The key takeaway is that fewer than 250 employees does not mean exemption from the GDPR generally; it narrows one record-keeping duty and, even then, only in limited circumstances. Because much routine processing may be non-occasional or involve special category data, many small organisations may still need to maintain records and should not assume otherwise.
Data protection officers and compliance leads
Those responsible for accountability need to assess whether their organisation actually qualifies for the narrowed record-keeping duty, testing their processing against the risk, occasional-nature, and special category or criminal offence data conditions. They should also ensure that any reliance on the relief does not undermine the wider accountability principle or divert attention from other obligations.
Legal advisers and outside counsel
Advisers should correct the common client misconception that the '250-employee exemption' is a blanket relief, and should verify the precise conditions of Article 30(5) against the current text. They should also flag potential divergence between the EU and UK regimes over time and the effect of national implementing law when advising on record-keeping obligations.
Engineers and product teams building data systems
Technical teams should recognise that the exemption does not relax obligations around lawful basis, transparency, security, or data subject rights. Even where formal ROPA documentation may be narrowed, systems still need to support these broader compliance requirements regardless of organisation size.

Inside 250-Employee Exemption

Records of Processing Activities (ROPA) baseline obligation
The so-called 250-employee exemption relates to Article 30 GDPR, which generally requires controllers and processors to maintain records of processing activities. The provision includes a carve-out for organisations employing fewer than 250 persons, subject to important conditions.
Employee headcount threshold
The threshold is expressed by reference to the number of persons employed by the organisation, with 250 as the relevant figure. Whether a particular entity falls below the threshold should be assessed against its own workforce; group structures and how headcount is counted may require careful analysis.
Conditional, not absolute, nature of the carve-out
The exemption does not apply where the processing is likely to result in a risk to the rights and freedoms of data subjects, where the processing is not occasional, or where it includes special category data (Article 9) or personal data relating to criminal convictions and offences (Article 10). Because most organisations carry out at least some non-occasional processing (for example, of employee or customer data), the practical benefit of the exemption is often narrow.
Scope limited to Article 30 records
The exemption addresses only the record-keeping duty under Article 30. It does not exempt an organisation from other GDPR obligations, such as identifying a lawful basis under Article 6, meeting transparency requirements, or honouring data subject rights.
Interpretive guidance
Regulatory guidance has generally taken a restrictive view of the exemption, emphasising that the conditions substantially limit its availability. Readers should verify the current position against the official text of Article 30 and applicable supervisory authority guidance, as interpretation may evolve and can vary between EU member states and the UK GDPR regime.

Common questions

Answers to the questions practitioners most commonly ask about 250-Employee Exemption.

Does having fewer than 250 employees mean my organisation is exempt from keeping records of processing activities?
No. This is a common misconception. Under Article 30(5) GDPR, the exemption for organisations with fewer than 250 employees does not apply where the processing is likely to result in a risk to the rights and freedoms of data subjects, where the processing is not occasional, or where the processing includes special category data (Article 9) or personal data relating to criminal convictions and offences (Article 10). Because most organisations engage in some processing that is not occasional (such as routine HR or payroll activity), the practical effect is that many small organisations must still maintain records for at least part of their processing. The threshold should be treated as a limited, conditional relief rather than a blanket exemption.
Is the 250-employee threshold a general small-business exemption from the GDPR as a whole?
No. The threshold in Article 30(5) relates specifically to the obligation to maintain records of processing activities (ROPA) and does not exempt an organisation from the GDPR more broadly. Other obligations, such as identifying a lawful basis under Article 6, honouring data subject rights, ensuring appropriate security, and complying with transparency requirements, continue to apply regardless of headcount. Treating it as a general exemption would misstate the scope of the relief.
How should we assess whether our processing is 'occasional' for the purposes of the exemption?
The GDPR does not define 'occasional' in Article 30, and interpretation typically draws on regulatory guidance rather than the Regulation text itself. In most cases, processing that is carried out on a regular, structured, or ongoing basis (for example, managing employee records or a recurring customer database) is unlikely to be considered occasional. Because this is an area of interpretation, organisations should document their reasoning and verify their approach against current guidance from the relevant supervisory authority, as regulator views can differ.
Which categories of processing typically remove the benefit of the exemption?
Under Article 30(5), the exemption is generally unavailable where processing is likely to result in a risk to data subjects' rights and freedoms, where it is not occasional, or where it involves special category data under Article 9 or criminal offence data under Article 10. If any of these apply to a given processing activity, records should generally be maintained for that activity. Each of these conditions is independent, so meeting even one can be sufficient to require records.
If only some of our processing falls outside the exemption, do we need records for everything?
The conditions in Article 30(5) are typically assessed by reference to the specific processing activity rather than the organisation as a whole. In practice this means an organisation may need to keep records for those activities that are not occasional or that involve higher-risk or special category data, even if other, genuinely occasional activities might fall within the relief. Given the difficulty of neatly separating activities, many organisations choose to maintain comprehensive records as a matter of good practice, though this is an operational judgement rather than a strict legal requirement in every case.
How does the 250-employee threshold apply under the UK GDPR, and are there national variations?
The record-keeping provision is broadly mirrored in the UK GDPR following its incorporation into UK law, but readers should not assume the EU and UK positions are identical in all respects, as divergence can develop over time and through separate guidance. Member state implementing laws and supervisory authority interpretations can also vary within the EU. Because the position is subject to change, organisations should verify the current wording and applicable guidance for the specific jurisdiction in which they operate rather than relying on a single snapshot.

Common misconceptions

Organisations with fewer than 250 employees never have to keep records of processing activities.
The headcount test is only the starting point. The carve-out is disapplied where processing is likely to risk data subjects' rights and freedoms, is not occasional, or involves special category or criminal offence data. Because routine processing of staff and customer data is typically non-occasional, many small organisations remain obliged to maintain records in practice.
The exemption relieves a small organisation of GDPR compliance more broadly.
The provision is confined to the Article 30 record-keeping duty. It does not affect obligations such as establishing a lawful basis, providing transparency information, responding to data subject requests, or securing personal data. Falling under the threshold does not make an organisation exempt from the Regulation generally.
If a small organisation qualifies, it can rely on the exemption permanently.
Eligibility is assessed on an ongoing basis and can change as processing activities change. New processing that is non-occasional or that involves special category data can remove the benefit of the carve-out even if headcount stays below the threshold. The position should be kept under review.

Best practices

Assess each of the disapplying conditions separately, confirming whether processing is occasional, whether it involves special category or criminal offence data, and whether it is likely to risk data subjects' rights, rather than relying on headcount alone.
Given how commonly the conditions apply, consider maintaining records of processing activities regardless of the exemption, as this generally supports accountability and other GDPR obligations.
Document the reasoning behind any reliance on the carve-out, including how the headcount and each condition were evaluated, so the assessment can be evidenced and revisited.
Review eligibility periodically and when processing activities change, since new non-occasional or high-risk processing can remove the benefit of the exemption over time.
Verify the applicable requirements against the current official text of Article 30 and relevant supervisory authority guidance, and check whether the EU GDPR, UK GDPR, or national implementing law governs the organisation, as positions can diverge.
Remember that even where the Article 30 exemption applies, other GDPR duties continue to apply, and address lawful basis, transparency, security, and data subject rights independently.