Skip to content
compliancebase
GDPRChapter IV — Records of Processing Activities

Article 30

Records of Processing Activities

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Maintain current records describing processing purposes, data and subject categories, recipients, transfers, retention, safeguards, and processor activities as applicable.

Points of focus

  • Cover actual processing across products, teams, and legal entities
  • Record transfers, retention, recipients, and security measures
  • Keep records available and current for supervisory authorities

Implementation notes

Seed records from service catalogs, event schemas, data stores, vendors, and infrastructure ownership; require record updates in launch and architecture review workflows. Operationalize cover actual processing across products, teams, and legal entities in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain approved processing inventory with owners and review dates with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the record lists the core application but omits observability and support processing Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample approved processing inventory with owners and review dates with dates and named reviewers. Be ready to walk through how you detect and correct: the record lists the core application but omits observability and support processing

Evidence auditors typically request:

  • Approved processing inventory with owners and review dates
  • Data-flow diagrams and subprocessor links
  • Change-management evidence updating records after launches

Common gaps

  • The record lists the core application but omits observability and support processing
  • Entries are updated annually even though product data flows change weekly

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 30This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Records of Processing Activities applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — cover actual processing across products, teams, and legal entities — with evidence stored where auditors and customers can sample it.

Lead with approved processing inventory with owners and review dates and pair it with data-flow diagrams and subprocessor links. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because the record lists the core application but omits observability and support processing Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above