Article 30
Records of Processing Activities
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Maintain current records describing processing purposes, data and subject categories, recipients, transfers, retention, safeguards, and processor activities as applicable.
Points of focus
- Cover actual processing across products, teams, and legal entities
- Record transfers, retention, recipients, and security measures
- Keep records available and current for supervisory authorities
Implementation notes
Seed records from service catalogs, event schemas, data stores, vendors, and infrastructure ownership; require record updates in launch and architecture review workflows. Operationalize cover actual processing across products, teams, and legal entities in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain approved processing inventory with owners and review dates with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the record lists the core application but omits observability and support processing Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample approved processing inventory with owners and review dates with dates and named reviewers. Be ready to walk through how you detect and correct: the record lists the core application but omits observability and support processing
Evidence auditors typically request:
- Approved processing inventory with owners and review dates
- Data-flow diagrams and subprocessor links
- Change-management evidence updating records after launches
Common gaps
- The record lists the core application but omits observability and support processing
- Entries are updated annually even though product data flows change weekly
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 30 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 30: Regulation (EU) 2016/679, Article 30 — Records of Processing Activities