Record of processing activities template (GDPR Article 30)

Record of processing activities template (GDPR Article 30) for controllers and processors, with the Article 35 screening. Free, nothing stored.

beta Addresses you have already built will keep rendering the same form; what may still change is what the tool can do.

Contact, delivery address, bug report, order tracking...

Pick the service that receives them, then give it the address that service gave you. Left as it is, nothing is sent: the answers stay in the browser.

Pick the record you have to produce, keep the questions that apply to you, and you get a link to a form that asks them — one entry at a time, in your own words. Nothing is stored here: the form lives in its address, and your answers go where you send them. Free, no account.

What it does, and why it is here

Article 30 of the GDPR obliges most organisations to keep a record of processing activities — a written inventory of what personal data they handle, why, for how long and who sees it. It is the first thing a supervisory authority asks for, and it is also the document nobody knows how to start, because the regulation lists what the record must contain without ever showing what a page of it looks like.

The result is a search that ends in a spreadsheet template downloaded from somewhere, with columns whose headings restate the article and no indication of what belongs under them.

So this page turns the obligation into questions. Each record becomes a form asking, one field at a time, exactly what the article requires — and because the questions come from the text, filling the form in is the compliance work rather than a rehearsal of it.

It covers four documents, not one: the controller’s record under Article 30(1), the processor’s record under Article 30(2) — a genuinely different and much shorter list — the screening that says whether you owe an impact assessment under Article 35(3), and the assessment itself under Article 35(7).

What you fill in

  • Which record you are producing — controller’s register, processor’s register, the impact-assessment screening, or the assessment. Choosing one loads the questions that record actually requires; they are not the same set.
  • The questions themselves — keep what applies, drop what does not, add anything your own organisation tracks. The article’s mandatory items are the ones already ticked.
  • Where the answers go — the service that will receive them, and the address it gave you. Left as it is, nothing is sent anywhere: the answers stay in the browser of whoever fills the form in.

What you get back

  • A link to the form — copy it, open it, or make a QR code of it. Send it to the person who actually knows the answers, which for a processing record is rarely the person building the form.
  • The form itself at that address, asking one entry’s worth of questions.
  • How many questions, and how many required, plus an estimate of the time it takes to fill in — useful when you are about to send it to twelve colleagues.
  • Which of your questions carry risk, flagged from the field referential — and on a privacy record this line is more than a courtesy: it names the fields that are themselves personal data, which is exactly the irony a register has to avoid.

What it does not do

It is not a compliance service and not legal advice. It gives you the questions the articles ask; whether your answers satisfy a regulator is between you, your data protection officer and your counsel.

It does not host your register. Nothing is written here — no entries, no answers, no account. A register is a living document you keep and update; this builds the form you fill it in with, and the finished record belongs in a place you control.

It also does not decide for you whether you are a controller or a processor, or whether an assessment is owed. The screening asks the Article 35(3) questions; the answers are yours.

The tool is in beta: an address already built keeps rendering the same form, while what the tool can do may still grow.

What Article 30 actually requires

The mandatory items, which are the questions the controller’s form opens with.

ItemIn practice
Name and contact detailsOf the controller, any joint controller, the representative and the DPO where they exist.
Purposes of the processingWhy you do it — one entry per purpose, not one per system.
Categories of data subjects and of dataWhose data, and what kinds.
Categories of recipientsWho it is disclosed to, processors included.
Transfers outside the EUThe country, and the safeguard relied on.
Retention periodsThe item most registers leave blank, and the one most often asked about.
Security measuresA general description, not an audit.

Two things worth knowing before you start. The register is organised by purpose, not by software — “recruitment” is an entry, “the HR tool” is not. And the lawful basis is not on this list: Article 30 does not require it, though Article 13 makes you tell people anyway, so most organisations record it regardless.

Questions

Is this free?

Yes, and there is no account — nothing is stored here for one to hold.

Who has to keep a record?

Broadly, any organisation over 250 employees, and below that any whose processing is not occasional, is likely to be risky, or touches special categories or criminal-offence data. In practice that catches almost everyone with employees.

Are we a controller or a processor?

You are a controller when you decide why and how the data is processed, and a processor when you do it on somebody else’s instructions. Many organisations are both, for different activities — and then keep both registers, which is why the tool offers both.

How many entries does a register need?

One per purpose. A small organisation usually lands between five and fifteen: payroll, recruitment, customer contracts, the mailing list, video surveillance, and so on.

Is a spreadsheet good enough?

Yes — the regulation asks for writing, including electronic form, not for a product. What matters is that it is complete and current.

How often should it be updated?

When something changes, and on a review at least yearly. A register that has not moved in three years is evidence of nothing.

When do I also owe an impact assessment?

When the processing is likely to result in a high risk — systematic evaluation, large-scale special categories, systematic monitoring of a public area. That is what the screening form asks, question by question.

Does this apply outside the EU?

The GDPR reaches organisations outside the EU that offer goods or services to people in it, or monitor their behaviour. The UK keeps an equivalent regime with the same structure.

Is a record of processing the same as a privacy policy?

No. The register is internal, for you and the regulator. The privacy policy is what you publish to the people whose data you hold. They overlap and they are not interchangeable.

Sources and further reading

Explore

More tools like this one

Picked from the catalog by what this page is about — the closest ones first. Each tag opens its whole family.

Write a landing page as one Markdown document, with features, steps and a FAQ as fenced sections, and see it rendered. Free, no account, nothing stored.

Build a working form and get its link: pick what you ask, drop what you do not need, choose where answers go. Free, no sign-up, nothing stored.