Skip to main content
Category: Impact Assessments & Documentation

Article 30

Simply put

The evidence packet provided does not contain any source addressing GDPR Article 30. The five supplied sources concern unrelated legal instruments: the Massachusetts Declaration of Rights, the Universal Declaration of Human Rights, and the Constitution of India. Because none of these describe the General Data Protection Regulation, a sourced definition of GDPR Article 30 cannot be generated from this evidence.

Formal definition

No definition can be produced on the basis of the supplied evidence. In the context of Privacy Track, 'Article 30' would ordinarily refer to the GDPR provision on records of processing activities, but none of the provided sources (Massachusetts Declaration of Rights Article 30, UDHR Article 30, or Article 30 of the Constitution of India) relate to the GDPR or data protection law. Drafting a technical definition here would require either citing GDPR source material not present in this packet or inventing content, both of which are prohibited. The reader should supply GDPR-specific authoritative sources (for example, the official Regulation text or supervisory authority guidance) so that an accurate, cited entry can be prepared.

Why it matters

The evidence digest supplied for this entry does not contain any source that addresses GDPR Article 30 or data protection law. The five items provided concern the Massachusetts Declaration of Rights (separation of legislative, executive, and judicial powers), Article 30 of the Universal Declaration of Human Rights, and Article 30 of the Constitution of India (minority rights to establish and administer educational institutions). None of these describe the General Data Protection Regulation.

Who it's relevant to

Evidence insufficient to determine relevance
The supplied sources do not concern the GDPR, so the audiences typically affected by an Article 30 obligation cannot be identified from this evidence without inventing content. Please provide GDPR-specific authoritative sources so that the relevant roles, such as controllers, processors, and their compliance functions, can be described accurately and with proper provenance.

Inside Article 30

Controller records
Records maintained by the controller documenting, among other things, the identity and contact details of the controller and any DPO, the purposes of processing, categories of data subjects and personal data, categories of recipients, relevant third-country transfers and safeguards, envisaged erasure time limits where possible, and a general description of security measures where possible.
Processor records
A narrower set of records maintained by the processor, including its contact details and those of each controller it acts for, the categories of processing carried out on behalf of each controller, relevant third-country transfers and safeguards, and a general description of security measures where possible.
Form and availability
The records must be kept in writing, which includes electronic form, and must generally be made available to the supervisory authority on request. They are an internal accountability instrument and are not typically published.
Small-organisation condition
Article 30 contains a limited exemption from the record-keeping obligation for organisations with fewer than 250 employees, but it applies only subject to specified conditions. The precise conditions should be checked against the current official text.
Link to accountability
Records of processing support the broader accountability principle, helping an organisation demonstrate what it processes and why, and connecting to related obligations such as the security measures referenced under Article 32.

Common questions

Answers to the questions practitioners most commonly ask about Article 30.

Does every organization have to maintain Article 30 records, or is there an exemption for small businesses?
There is no blanket exemption based solely on organization size. Article 30(5) provides a limited derogation for enterprises employing fewer than 250 persons, but that derogation does not apply where the processing is likely to result in a risk to the rights and freedoms of data subjects, where the processing is not occasional, or where it includes special categories of data (Article 9) or personal data relating to criminal convictions and offences (Article 10). Because most ongoing business processing is not occasional, many smaller organizations still need to maintain records in practice. You should assess your specific processing rather than assume an exemption applies.
Are Article 30 records the same thing as a Data Protection Impact Assessment?
No. Records of processing activities under Article 30 and a Data Protection Impact Assessment under Article 35 are distinct instruments serving different purposes. Article 30 records are a descriptive inventory documenting what processing occurs and its key characteristics, maintained on an ongoing basis. A DPIA under Article 35 is a risk-focused assessment carried out where a type of processing is likely to result in a high risk to individuals. The two can inform each other, but maintaining Article 30 records does not satisfy the DPIA obligation, and vice versa.
What categories of information does Article 30 typically require the records to contain?
Article 30 distinguishes between records kept by a controller and those kept by a processor. For controllers, the record generally includes matters such as the name and contact details of the controller (and, where applicable, the joint controller, representative, and data protection officer), the purposes of processing, a description of the categories of data subjects and categories of personal data, the categories of recipients, information on transfers to third countries, envisaged retention periods where possible, and a general description of technical and organizational security measures where possible. Processors maintain a comparable but narrower record oriented around processing carried out on behalf of controllers. Confirm the exact required fields against the current text of Article 30, as your specific role affects what applies.
In what form should Article 30 records be kept, and do they have to be shared with the supervisory authority?
Article 30 requires the records to be maintained in writing, including in electronic form. There is no mandated template, so organizations commonly use structured spreadsheets, dedicated tools, or governance platforms. The records must be made available to the supervisory authority on request. This is generally an on-request obligation rather than a routine filing requirement, but you should verify current expectations, as regulator guidance and national practice can vary.
How should responsibility for Article 30 records be allocated when acting as both controller and processor?
An organization may act as a controller for some processing and as a processor for other processing, and the records obligations differ for each role. In practice this typically means maintaining distinct records that reflect the applicable role for each processing activity, since the required content is not identical for controllers and processors. Mapping each activity to the correct role first is generally advisable so that the record captures the appropriate fields. Where roles are unclear or shared, the allocation should be assessed on the facts.
How often should Article 30 records be reviewed and updated?
Article 30 records are intended to reflect processing as it actually occurs, so they are generally treated as living documents rather than a one-time exercise. In most cases organizations update them when processing activities change, for example when new purposes, recipients, transfers, or data categories are introduced, and many also conduct periodic reviews as a matter of good governance. There is no single prescribed review interval in the Regulation text, so the cadence is typically set through internal policy and should be proportionate to how frequently your processing changes.

Common misconceptions

Organisations with fewer than 250 employees are automatically exempt from keeping records under Article 30.
The exemption is not automatic or absolute. It is subject to conditions set out in Article 30, and in many common situations the obligation still applies. Practitioners should verify the exact conditions against the current text before relying on the exemption.
Article 30 records are the same as, or a substitute for, a Data Protection Impact Assessment.
Article 30 records are an inventory of processing activities and a distinct instrument from a Data Protection Impact Assessment. The two serve different purposes and should not be conflated; each addresses different accountability requirements.
Only controllers need to maintain records under Article 30.
Both controllers and processors have record-keeping obligations, though the required content differs. Processors maintain a narrower record focused on the processing they carry out on behalf of each controller.

Best practices

Maintain the records in electronic form so they can be readily updated and made available to a supervisory authority on request.
Distinguish clearly between records kept in your capacity as a controller and any kept in your capacity as a processor, since the required content differs.
Review and update the records periodically and whenever processing purposes, categories of data, recipients, or transfer arrangements change, rather than treating them as a one-off exercise.
Document third-country transfers and the applicable safeguards within the records, and revisit them as transfer mechanisms and safeguards evolve.
Do not rely on the small-organisation exemption without confirming that its specific conditions in the current Article 30 text are met.
Use the records to connect with related obligations, such as the general description of technical and organisational security measures referenced in Article 32, to support overall accountability.