Benefits of the Records of Processing Activities
A well-maintained records of processing activities allows:
- to understand and control what data is being processed in the organization and why, regardless of who the data controller is,
- to consolidate in one document an overview of all activities involving personal data in your organization,
- to easily assign responsible individuals for specific areas (so-called process owners),
- to easily gather data for the preparation of privacy notices and ensure their consistency,
- to conduct audits and Data Protection Impact Assessments (DPIA) much more efficiently and accurately.
And finally - the records of processing activities is one of the fundamental documents requested by inspectors from the Polish Data Protection Authority. The reason is the same as described in the first point.
Overview of All Activities Involving Personal Data
Receive a package of free GDPR guides and micro-trainings
A process consists of all activities aimed at achieving a specific purpose of data processing, e.g., employee recruitment, execution of contracts with clients, sending newsletters, or controlling access to buildings and video surveillance. Our organization may have both processes that it implements:
- In its own name – then as a data controller, it maintains the records of processing activities (Article 30(1) GDPR).
- On behalf of other organizations – then as a data processor, it maintains the records of all categories of processing activities (Article 30(2) GDPR).
- Together with others – as one of the joint controllers – then as a data controller, it maintains the records of processing activities (Article 30(1) GDPR), but should correctly indicate the name and contact details of all joint controllers.
Below we present a possible format for the records for example processes. In addition to data concerning all processes, the records should include information about the identity and contact details of your organization and its Data Protection Officer, if appointed.
Example entry in the records for a data controller:
Question | Process: Recruitment |
Process owner | Jan Kowalski |
Purpose of data processing | Hiring new employees. |
Categories of individuals whose data is processed | Job candidates; individuals indicated by candidates as providing references. |
Categories of personal data processed | Job candidates: first name and surname; contact details; information about education; information about employment history. In the case of candidates who successfully passed the recruitment process - also PESEL and date of birth (for the purpose of issuing a referral for medical examinations); Health data regarding work capacity (resulting from a medical certificate). Individuals providing references: first name, surname, position, email address. |
Categories of recipients | Individuals indicated by the candidate providing references (in case of contact for recommendations); medical facilities (recipients of referrals for occupational medicine examinations); document destruction companies. |
Planned deadlines for the deletion of individual categories of data or criteria for their determination | Data in paper form is removed immediately after the recruitment process is completed, unless the candidate consents to the processing of application documents for future recruitment purposes (in which case the data is retained for 9 months). |
The scope of personal data transferred to a third country or international organization and the name of that third country or international organization. | None. |
In the case of transfers referred to in Article 49(1) second paragraph of the GDPR, please indicate the appropriate safeguards. | Not applicable. |
General description of technical and organizational security measures | Data in electronic form stored in a network folder with restricted access; disk encryption and strong passwords for computers. Data in paper form printed in a follow-me printing system, locked in cabinets, and removed immediately after the recruitment process using a shredder or in cooperation with a document destruction company. |
In the case of joint administration: names and contact details of all co-administrators | Recruitment Agency ABC, ul. Przykładowa 1, 12 - 345 Warsaw, email: [email protected] |
Sample register for a data processor:
Question | Process: Archiving |
Name and contact details of each data controller on behalf of whom the data processor operates | Abrakadabra sp. z o.o., ul. Wzorcowa 2, 54-321 Warsaw. XYZ sp. z o.o., ul. Szablonowa 3, 53 - 376 Gdańsk. |
Process owner on the processor's side | Archiving Department, Zofia Nowak |
Scope of data processed on behalf of the data controller and the purpose of their processing | Data contained in the entrusted employee personal files (the files are sealed and as a data processor, we do not have access to them). The purpose of processing is to provide personal data storage services. |
The scope of personal data transferred to a third country or international organization and the name of that third country or international organization. | None. |
What technical and organizational measures are taken to ensure an appropriate level of security for processing? | Video surveillance of the area around the building where personal data is stored, constant presence of a security company employee on site, alarm in the room where personal data is stored. |
In the case of transfers outside the EEA, as referred to in Article 49(1) second paragraph of the GDPR, please indicate the appropriate safeguards. | Not applicable. |
Assignment of Responsible Persons
The management and ongoing updating of the records of processing activities should be coordinated by one person, the Data Protection Officer (DPO), or another person responsible for data protection in the organization or designated to manage them.
In the above examples of the content of the records, in addition to the information required by Article 30 of the GDPR, we recommend indicating the process owner. This person should be formally obligated to inform the person maintaining the records of any planned changes to the information regarding their process.
Regardless, the record keepers should regularly ask individuals to review the records and potentially update them.
Example: The head of the HR department should promptly inform the person maintaining the records of processing activities about the shortening of the statutory retention period for employee personal files or about planned cooperation with an archiving company.
Benefit: By engaging process owners, the records will remain current, and informing the data protection officer about planned changes will also provide them with an opportunity to fulfill the requirement of data protection by design.
Preparation and Standardization of Privacy Notices
The records of processing activities maintained by the data controller serve as an excellent starting point for preparing and updating the content of privacy notices directed at individuals whose data we process.
Do you also prefer prevention over treatment?
Benefit: The content of the privacy notices and privacy policy will be continuously updated and internally consistent.
A properly constructed records of processing activities is essentially the first step in conducting a Data Protection Impact Assessment, as it provides a description of processing operations. It serves as a good starting point for further analysis – namely, compliance assessment with the GDPR, as well as Data Protection Impact Assessment (DPIA), thus analyzing the likelihood and severity of risks to individuals whose data we process.
Example: The person conducting the audit or performing the DPIA may compare the information from the records of processing activities with that obtained during the audit – and clarify any discrepancies if necessary.
Benefit: The audit and DPIA do not begin with the collection of basic information, but rather focus on its verification and making more detailed determinations. This saves time while simultaneously enhancing quality.
Summary
A well-maintained records of processing activities serves as the center for GDPR compliance – it provides an overview of all data operations, indicates responsible individuals, and also contains information useful for preparing other documents, such as privacy notices, audit reports, or Data Protection Impact Assessments. If your organization can achieve these benefits, it will be a significant asset in the event of an inspection by the Polish Data Protection Authority.


