← back to the act's dossier

GDPR — Article 30

The article's text

Article 30 Records of processing activities 1. Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information: (a) the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the data protection officer; (b) the purposes of the processing; (c) a description of the categories of data subjects and of the categories of personal data; (d) the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations; (e) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards; (f) where possible, the envisaged time limits for erasure of the different categories of data; (g) where possible, a general description of the technical and organisational se
full text
curity measures referred to in Article 32(1). possible, a general description of the technical and organisational security measures referred to in Article 32(1). 2. Each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing: (a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's representative, and the data protection officer; (b) the categories of processing carried out on behalf of each controller; (c) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards; (d) where possible, a general description of the technical and organisational security measures referred to in Article 32(1). possible, a general description of the technical and organisational security measures referred to in Article 32(1). 3. The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form. 4. The controller or the processor and, where applicable, the controller's or the processor's representative, shall make the record available to the supervisory authority on request. 5. The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.

Who wrote about this article in the consultations

Filers who named this exact article number in their own text. It is their sentence, not our reading — and not a causal claim.

9
business association
5
NGO
5
company
3
other
2
ACADEMIC_RESEARCH_INSTITTUTION
WhoCountryWhat they wrote
Confederation of Swedish EnterpriseSEwith the level of information required under Art. 30 GDPR, including the IMY's high standard for transparency? In Art. 30 (5) GDPR there is a limitation to the obligation to maintain a record of processing for an enterprise or an organisation with fewer than 2
Deutsche Industrie- und Handelskammer (DIHK) / German Chamber of Commerce and IndustryDE, wann für KMU die Pflicht entfällt, ein Verzeichnis über die Verarbeitungstätigkeit zu führen. Die für KMU geregelte Ausnahme in Art. 30 Absatz 5 DSGVO findet in der Praxis kaum Anwendung Die Vorgaben für Auftragsverarbeitungsverträge sollten dem Risiko entsp
Centre for European PolicyDEuced for sensible and necessary documentation and reporting obligations which the GDPR imposes on companies (using the example of Art. 30 and 33 of the GDPR), and, secondly, B. comment on the interaction between the GDPR and new initiatives (using the example
Selbstregulierung Informationswirtschaft e.V. (SRIW)DEGDPR. The record of processing requires in any case only categories of some information, Art. 30.1 lit c and lit d. Thus, information within external transparency information shall not exceed the required information for internal documentation. Acknowledging t
Shoosmiths LLPGBpresents an opportunity to better balance privacy protection with the operational realities of SMEs. The current exemption under Article 30(5) does not significantly reduce the compliance burden, as SMEs still need to document their data processing activities
Bundesvereinigung der Deutschen ArbeitgeberverbändeDEahrung des jeweiligen Auskunftsrechts muss eine Übersicht, die die verarbeiteten Daten in verständlicher Form auflistet, genügen. Art. 30 Gemäß Art. 30 DS-GVO muss ein Verzeichnis über Verarbeitungstätigkeiten lediglich in Unternehmen ab 250 Mitarbeitern gefüh
MyData-TRUSTBEcomplementing the requirements of the GDPR Art. 30, giving national flavour to the records of processing activities. These variations highlight the complexity of harmonizing data protection practices across the EU, as national DPAs may interpret and implement
Oplysningsforbundet May DayDKaa-overblikket-4-centrale-begreber-der-faar-det-offentlige-Ɵl-rime-paa-cloud 74 art. 5, stk. 1, litra f, jf. art. 5, stk. 2, og Ɵl art. 30, stk.
VNO-NCW / MKB NederlandNLlaw, because it has to prevent other controllers from reading too much leeway in its interpretations). We also recommend amending article 30 paragraph 5 as follows: to not restrict the derogation of keeping a record to occasional processing activities; and to
Xamit Bewertungsgesellschaft mbHDEwie sie in anderen Berufsfeldern selbstverständlich ist. Die Pflicht zum Führen eines "Verzeichnis von Verarbeitungstätigkeiten" (Art. 30 DS-GVO) bringt in der Praxis keinen Mehrwert. Die Verarbeitungen müssen im Wesentlichen in der (im Vergleich zum "Verzeich
Berufsverband der Datenschutzbeauftragten Deutschlands (BvD) e.V.DEsgrundlage nach Artt. 13, 14 DSGVO sowie der Pflicht zur Erfassung im Rahmen des Verzeichnisses von Verarbeitungstätigkeiten nach Art. 30 DSGVO. Damit löst selbst eine einfache Zulässigkeitsprüfung (z.B.
Alliance DigitaleFRrecords of processing activities and remove the term "occasional" from paragraph 5 of Article 30 of the GDPR. As specified in the same Article 30, this exemption would not apply if the processing they carry out is likely to result in a risk to the rights and f
AUSTRIAN FEDERAL ECONOMIC CHAMBERAT(e.g. from trade and craft, engineering offices) must be considered. A proper formulation of the SME exception in accordance with Article 30 Paragraph 5 GDPR for companies that also process data regularly (such as any company that looks after customers or empl
Finnish EnergyFIther a data breach should be reported or not. In addition, more clarification and detailed examples have been requested regarding Article 30 'Records of processing activities,' especially concerning the level at which the information mentioned in the article s
Délégué à la Protection des Données (ancien et formateur)FRles finalités du traitement et leur condition de licéité respective, conformément à l’article 6 du présent règlement ; 7) Article 30.2 RGPD : ajouter l’existence d’une sous-traitance de niveau inférieur dans un registre Sous-traitant Au titre de l’article 30.2
theinfosecvault.comITconsent art. 6 (only when other forms of consent could not be achieved by the Controller) 2) The Record of Processing Activities (art. 30) should be mandatory for every company and periodically archived with digital signature Thank you !
Border Violence Monitoring NetworkDE40 EURODAC Regulation, Article 30 39 Heinrich Böll Stiftung & BVMN. 2023. In defence of defenders: a practical guide to legal means and advocacy tools for criminalised Human Rights Defenders in Europe. Available at: https://gr.boell.org/sites/default/files/202
noybATlaw and Article 78(3) GDPR, any supervisory authority concerned may be joined to a national procedure in another Member State.87 Article 30 - Additional remedies before national courts Without prejudice to the rights under Article 78 GDPR and national laws,
David ErdosGBrelations in article 28 and record keeping which is “not occasional” in article 30 are similarly acontextual. It is also concerning how many of these and indeed other provisions in the GDPR focus on mandating process rather ensuring concrete results which dire
Ecommerce EuropeBEin the GDPR. For example, how detailed must the documentation be, in particular the record of processing activities according to Art. 30 GDPR? Which circumstances fall under Art. 28 GDPR (processing is carried out on behalf of a controller)? What is the corre
Internet Corporation for Assigned Names and NumbersUSbe important to specify under what conditions interested parties should be consulted (Art. 70 (4) of the GDPR). The provision of Art. 30 of the EDPB Rules of Procedure should therefore be supplemented in order to clarify this important issue. The provision sh
Digitale Gesellschaft e.V.DEn authorities. To promote transparency, the legislator must oblige controllers to publish their records of processing activities (Article 30) in a machine- readable form. To strengthen data protection in practice, the legislator must support the development an
BVPA Bundesverband professioneller Bildanbieter e.V.DEe sich aus Art. 28 DSGVO (AVV) i.V. m. Art. 32 DSGVO (TOM) und ggf. zusätzlich aus Art. 44ff DSGVO (Driostaatentransfer) sowie aus Art. 30 DSGVO (Verarbeitungsverzeichnis) und Art. 13 DSGVO (Infopflichten) ergebenden Pflichten für Verantwortliche und AuRraggeber
Deutsche Telekom AGDEe, if not directly accessible, at least retrievable without effort." 7) Record of categories of processing activities pursuant to Article 30 (2) GDPR Request: Where the same category of processing activities is performed on behalf of a large number of controll
Centre for Information Policy Leadership (CIPL)GBthe GDPR. For instance, some controllers are obliging processors contractually to keep 9 records of processing in accordance with Article 30 of the GDPR and requesting access to such records, or are trying contractually to position privacy by design and privac
Zentralverband der deutschen Werbewirtschaft ZAWDEchtspunkten orientieren und stärker an die Gegebenheiten in der Praxis angepasst werden. So ist der Auftragsverarbeiter z.B. nach Artikel 30 Abs. 2 DSGVO zur Führung von Verarbeitungsverzeichnissen verpflichtet, wobei kein Raum für eine Differenzierung zwische
GDPR Article 30(5) - clarifying the record keeping obligation Article 30(5) is clearly aimed at creating a general exception to the record-keeping obligation for smaller companies. What isn't clear, based on the current wording, is when such a small company

Source: public consultation submissions and position papers. n = 27 mentions; counted as a literal reference to the article number.

Ask about this article →