Answers to the questions practitioners most commonly ask about Article 30.
Does every organization have to maintain Article 30 records, or is there an exemption for small businesses?
There is no blanket exemption based solely on organization size. Article 30(5) provides a limited derogation for enterprises employing fewer than 250 persons, but that derogation does not apply where the processing is likely to result in a risk to the rights and freedoms of data subjects, where the processing is not occasional, or where it includes special categories of data (Article 9) or personal data relating to criminal convictions and offences (Article 10). Because most ongoing business processing is not occasional, many smaller organizations still need to maintain records in practice. You should assess your specific processing rather than assume an exemption applies.
Are Article 30 records the same thing as a Data Protection Impact Assessment?
No. Records of processing activities under Article 30 and a Data Protection Impact Assessment under Article 35 are distinct instruments serving different purposes. Article 30 records are a descriptive inventory documenting what processing occurs and its key characteristics, maintained on an ongoing basis. A DPIA under Article 35 is a risk-focused assessment carried out where a type of processing is likely to result in a high risk to individuals. The two can inform each other, but maintaining Article 30 records does not satisfy the DPIA obligation, and vice versa.
What categories of information does Article 30 typically require the records to contain?
Article 30 distinguishes between records kept by a controller and those kept by a processor. For controllers, the record generally includes matters such as the name and contact details of the controller (and, where applicable, the joint controller, representative, and data protection officer), the purposes of processing, a description of the categories of data subjects and categories of personal data, the categories of recipients, information on transfers to third countries, envisaged retention periods where possible, and a general description of technical and organizational security measures where possible. Processors maintain a comparable but narrower record oriented around processing carried out on behalf of controllers. Confirm the exact required fields against the current text of Article 30, as your specific role affects what applies.
In what form should Article 30 records be kept, and do they have to be shared with the supervisory authority?
Article 30 requires the records to be maintained in writing, including in electronic form. There is no mandated template, so organizations commonly use structured spreadsheets, dedicated tools, or governance platforms. The records must be made available to the supervisory authority on request. This is generally an on-request obligation rather than a routine filing requirement, but you should verify current expectations, as regulator guidance and national practice can vary.
How should responsibility for Article 30 records be allocated when acting as both controller and processor?
An organization may act as a controller for some processing and as a processor for other processing, and the records obligations differ for each role. In practice this typically means maintaining distinct records that reflect the applicable role for each processing activity, since the required content is not identical for controllers and processors. Mapping each activity to the correct role first is generally advisable so that the record captures the appropriate fields. Where roles are unclear or shared, the allocation should be assessed on the facts.
How often should Article 30 records be reviewed and updated?
Article 30 records are intended to reflect processing as it actually occurs, so they are generally treated as living documents rather than a one-time exercise. In most cases organizations update them when processing activities change, for example when new purposes, recipients, transfers, or data categories are introduced, and many also conduct periodic reviews as a matter of good governance. There is no single prescribed review interval in the Regulation text, so the cadence is typically set through internal policy and should be proportionate to how frequently your processing changes.