General Data Protection Regulation, Records of Processing Activities (Article 30)
Regulation (EU) 2016/679, Art. 30
In force since .
A comprehensive regime rule binding public and private bodies.
- Obligation class
- Governance
As of .
What it requires
- If you are a controller, a processor or the representative of either, keep the records of processing activities that Article 30(1) and (2) require, unless you are an enterprise or organization employing fewer than 250 persons and none of the three conditions in Article 30(5) is met: the processing you carry out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10 (Article 30(5)).
- If you are a controller or the controller's representative, maintain a record of processing activities under your responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients, and, where applicable, transfers to a third country or international organization with the documentation of suitable safeguards for the transfers referred to in the second subparagraph of Article 49(1) (Article 30(1), points (a) to (e)).
- In the controller's record, include where possible the envisaged time limits for erasure of the different categories of data and a general description of the technical and organizational security measures referred to in Article 32(1) (Article 30(1), points (f) and (g)).
- If you are a processor or the processor's representative, maintain a record of all categories of processing activities carried out on behalf of a controller, containing the name and contact details of the processor and of each controller, the categories of processing carried out on behalf of each controller, where applicable the transfers to a third country or international organization, and where possible a general description of the technical and organizational security measures referred to in Article 32(1) (Article 30(2)).
- Keep the records in writing, including in electronic form (Article 30(3)).
- Make the record available to the supervisory authority on request (Article 30(4)).
If you get it wrong
Private right of actionYes
Penalty structure
Article 83(4)(a) names the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43, a range that includes Article 30, among the provisions carrying the lower administrative-fine tier, up to EUR 10,000,000 or 2 percent of total worldwide annual turnover of the preceding financial year, whichever is higher.
- Rule
- Higher of
- As of
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The data protection supervisory authority designated by each EU Member State under Article 51, coordinated on cross-border cases through the one stop shop mechanism, which does not apply to processing by public authorities or by private bodies acting under Article 6(1)(c) or (e) (Article 55(2)), and through the European Data Protection Board (Articles 68-76).
What this law does
Article 30(1) requires each controller and, where applicable, the controller's representative to maintain a record of processing activities under its responsibility.
Article 30(1) provides that the record shall contain the name and contact details of the controller, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients, transfers to a third country or international organization where applicable, and, where possible, the envisaged time limits for erasure and a general description of the technical and organizational security measures.
Article 30(2) requires each processor and, where applicable, the processor's representative to maintain a record of all categories of processing activities carried out on behalf of a controller. Article 30(3) provides that the records shall be in writing, including in electronic form. Article 30(4) provides that the controller or the processor and, where applicable, their representative shall make the record available to the supervisory authority on request.
Article 30(5) provides that the record-keeping obligations do not apply to an enterprise or an organization employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.
Article 83(4), point (a), subjects infringements of the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43, a range that includes Article 30, to administrative fines up to EUR 10,000,000 or, in the case of an undertaking, up to 2 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher.
Article 82(1) gives any person who has suffered material or non-material damage as a result of an infringement of the Regulation the right to receive compensation from the controller or processor for the damage suffered. Article 79(1) gives each data subject the right to an effective judicial remedy where he or she considers that his or her rights under the Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with the Regulation. Article 99(2) provides that the Regulation applies from .
When LexLint raises it
When your app profile says your app crawls the web, trains models, generates content with AI, deploys a chatbot, sends automated outreach, makes high-risk automated decisions, processes voice recordings or processes biometric data.