Compliance

Discover
Legalnest
Language FR EN
Annotated template 15 min read

GDPR record of processing activities: who needs one and 3 filled-in examples for small businesses

Key takeaways

A business that processes personal data on a regular basis (customers, prospects, payroll) must keep a record of processing activities, even with fewer than 250 employees: the exemption in Article 30(5) of the GDPR only covers processing that is occasional, risk-free and involves no sensitive data. The record describes each processing activity: purpose, people concerned, data, recipients, transfers, retention periods and security measures.

  • The Legalnest team
  • Updated on
  • Checked against the law in force on
  • Markdown version
Contents
  1. What is a GDPR record of processing activities?
  2. What must a record of processing activities contain?
  3. Do small businesses with fewer than 250 employees need a record of processing?
  4. Is the 250-employee threshold going up to 750?
  5. Is there a free CNIL record of processing template?
  6. What does a record of processing look like for an online shop?
  7. What does a record of processing look like for a freelance consultant or coach?
  8. What does a record of processing look like for a small agency with 3 employees?
  9. How does the record of processing relate to the privacy policy?
  10. What is the fine for not keeping a record of processing?
  11. How do I keep my record of processing up to date?

On 8 October 2024, the CNIL (the French data protection authority) announced that it had sanctioned two companies with fewer than 250 employees for having no record of processing activities (in French). Being small did not protect them: their processing was not occasional, and once that is the case, the exemption for small organisations no longer applies.

Most founders assume the « registre des traitements » (record of processing activities, often shortened to RoPA) is for large groups. For an online shop or a consultant, it fits on three or four entries. The obligation comes from the GDPR, so it is the same across the EU; what is French-specific is the enforcer (the CNIL), its simplified sanction procedure and the statutory retention periods in the examples below, which come from French law. Here are three filled-in examples, ready to adapt.

What is a GDPR record of processing activities?

The record of processing activities is the written inventory of everything your business does with personal data, with, for each activity, its purpose, the data used, who receives it and how long it is kept. It is required by Article 30 of the GDPR and must be shown to the CNIL if it asks.

A “processing activity” is a use of data organised around one goal: handling orders, sending a newsletter, paying staff. A single customer file used both to deliver orders and to market to people gives you two entries, because the legal bases and retention periods differ.

The record does three concrete jobs:

  • proving your compliance during an inspection, without rebuilding everything in a panic;
  • feeding your privacy policy, which repeats much of its content;
  • exposing blind spots: a US tool nobody had flagged, data kept forever, a provider with no contract.

What must a record of processing activities contain?

For each processing activity, the controller’s record states the purposes, the categories of people and data, the recipients, transfers outside the European Union, time limits for erasure and a general description of security measures, plus the business’s contact details. A processor keeps a shorter record, organised by client.

Heading (Art. 30)Controller’s record (30(1))Processor’s record (30(2))
IdentityName and contact details of the controller, any joint controller, the representative and the data protection officer (DPO) where applicableName and contact details of the processor and of each client it acts for, and of the DPO where applicable
PurposesMandatory, activity by activityCategories of processing carried out for each client
People and dataCategories of data subjects and of personal dataNot required
RecipientsCategories of recipients, including outside the EUNot required
Transfers outside the EURecipient country or organisation, and safeguards in some casesSame
Retention periods“Where possible”, time limits for erasureNot required
Security“Where possible”, a general description of the measuresSame

The record is kept in writing, including in electronic form (Art. 30(3)), and made available to the supervisory authority on request (Art. 30(4)): nothing requires you to publish it, and the format is up to you.

Do not read “where possible” as optional. For retention, an entry with no period is the first sign that you keep everything indefinitely, which Article 5 of the GDPR prohibits under the storage limitation principle.

Do small businesses with fewer than 250 employees need a record of processing?

Yes, almost always. Article 30(5) exempts organisations with fewer than 250 employees, but the exemption falls away as soon as processing is not occasional, poses a risk to individuals or involves sensitive or criminal data: managing customers, prospects or payroll is enough to lose it.

What the law says

The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.

Regulation (EU) 2016/679 (GDPR), Article 30(5)

The three exceptions are alternatives: one is enough. And the first, “not occasional”, on its own rules out most of what a business does. The CNIL says so plainly on its page on the record (in French): the record must include “non-occasional processing (for example: payroll management, management of customers/prospects and suppliers, etc.)” (our translation). It adds that the exemption “is therefore limited to very specific cases of processing” and recommends, when in doubt, putting the processing in the record.

So what stays occasional? A one-off prize draw, a trade fair where you picked up a few business cards and never followed up. Your Shopify store taking orders every week, your appointment calendar, your invoice file: no.

flowchart TD
  A["You process personal data"] --> B{"250 employees or more?"}
  B -->|Yes| R["Record mandatory"]
  B -->|No| C{"Regular processing?"}
  C -->|Yes| R
  C -->|No| D{"Sensitive or criminal data?"}
  D -->|Yes| R
  D -->|No| E{"Risk to individuals?"}
  E -->|Yes| R
  E -->|No| F["Exemption possible for this activity"]

Is the 250-employee threshold going up to 750?

Perhaps, but not yet. In May 2025 the European Commission proposed extending the exemption to organisations with fewer than 750 employees, except for high-risk processing; as of 7 October 2026, the text has not been adopted and Article 30(5) applies as currently worded.

According to the joint opinion of the EDPB and the EDPS of 8 July 2025, this “Omnibus IV” proposal would make the record mandatory, below that threshold, only for processing “likely to result in a high risk” within the meaning of Article 35 of the GDPR. According to the European Parliament’s Legislative Observatory, the parliamentary committee approved the text negotiated with the Council on 2 July 2026; the plenary vote is listed for 23 November 2026, and no publication in the Official Journal is reported there.

Do not wait. The final text may differ, and even if you end up exempt, you will still have to inform people, set retention periods and put contracts in place with your providers. The EDPB and the EDPS also describe the record as “a very useful means to support compliance with several GDPR requirements”.

Is there a free CNIL record of processing template?

Yes. The CNIL offers a simplified record template as an ODS spreadsheet (in French), free to download from its page « Le registre des activités de traitement » (the record of processing activities). It opens in LibreOffice, Excel or Google Sheets.

The file is organised in tabs: a tutorial, the list of processing activities headed by the controller’s and DPO’s details, a blank form to copy for each activity, a completed example (payroll) and the drop-down lists. One thing to watch: the list of transfer safeguards still offers “Privacy shield”, which the Court of Justice of the European Union invalidated on 16 July 2020 (in French); do not pick it. The older RTF and PDF templates, still online, are no longer updated according to the CNIL: start from the ODS file.

To fill in retention periods without making them up, rely on the CNIL’s « référentiels » (reference standards): the one on managing commercial activities (decision no. 2021-131 of 23 September 2021) for customers and prospects, and the standard on retention periods for HR data, published on 2 April 2026 and updated on 20 May 2026, for employees (both in French). The periods they recommend are not binding, but departing from them means being able to justify your choice; periods set by statute, such as those in the « Code du travail » (Labour Code) or the « Code de commerce » (Commercial Code), are binding. For security, the CNIL’s practice guide for the security of personal data sets out the basic measures.

What does a record of processing look like for an online shop?

Take a Shopify store selling solid cosmetics, two co-founders, no employees. Three processing activities cover the essentials: orders, the newsletter, audience measurement.

HeadingOrder managementNewsletterAudience measurement
PurposeProcess orders, delivery, after-sales service and invoicingSend offers and new products by emailMeasure traffic and site performance
Legal basisPerformance of the contract (Art. 6(1)(b)); legal obligation for invoicing (Art. 6(1)(c))Consent; legitimate interest for an existing customer and similar products (CNIL standard)Consent to trackers, unless the tool is exempt and configured according to the CNIL’s recommendations
PeopleCustomersSubscribers: customers and prospectsSite visitors
DataIdentity, delivery and billing addresses, email, phone, order details, payment statusEmail, first name, sign-up date, opens and clicksTracker ID, pages viewed, referrer, browser and device
RecipientsCo-founders, e-commerce platform, payment provider, carrier, accountantEmail marketing toolAnalytics tool provider
Transfers outside the EUFor each provider outside the EU: country and safeguard (adequacy decision, standard contractual clauses)Same, depending on the toolSame, depending on the tool
RetentionLength of the customer relationship, then archiving within the limitation period (CNIL standard); invoices and accounting records: 10 years (Commercial Code, art. L123-22); card number and expiry date: 13 months after the debit date (15 months for deferred debit), archived, for disputes; security code deleted as soon as payment is complete (CNIL recommendation no. 2018-303)Until consent is withdrawn, or 3 years after the last contact (CNIL standard)Trackers: 13 months; information collected: 25 months (CNIL)
SecurityNamed accounts on the back office, two-factor authentication, HTTPSAccess limited to the co-founders, two-factor authenticationLimited dashboard access, minimal configuration

The CNIL sources in this table are in French.

The detail that matters: if payments go through a provider that stores card data itself, say so in the entry rather than implying that you store card numbers. And the audience measurement entry must match your cookie banner: if the tool is not exempt, nothing is placed before consent.

What does a record of processing look like for a freelance consultant or coach?

An organisational consultant trading as a « micro-entrepreneur » (France’s simplified sole-trader status) who prospects SMEs on LinkedIn and by email, invoices her assignments and books sessions through an online scheduling tool.

HeadingProspectingInvoicingAppointment booking
PurposeApproach businesses and follow up on exchangesIssue and keep invoices, track paymentsSchedule discovery calls and sessions, send reminders
Legal basisLegitimate interest for business-to-business prospecting (CNIL standard)Legal obligation (Art. 6(1)(c))Pre-contractual steps or performance of the contract (Art. 6(1)(b))
PeopleManagers and employees of prospected businessesClientsClients and prospects
DataName, job title, company, work email and phone, history of exchangesIdentity, address, services, amounts, paymentsName, email, phone, time slot, purpose of the appointment
RecipientsThe consultant, CRMAccountant, invoicing software, tax authorities in an auditScheduling tool, video-call tool
Transfers outside the EUDepending on where the CRM is hostedDepending on the softwareDepending on the tools
Retention3 years from collection or from the prospect’s last contact (CNIL standard)6 years (« Livre des procédures fiscales » (Tax Procedures Code), art. L102 B); 10 years for a trader or a commercial company (Commercial Code, art. L123-22)Length of the relationship; for a prospect who did not follow up, 3 years after their last contact (CNIL standard)
SecurityStrong password and two-factor authentication on the CRMRegular backups, limited accessNamed accounts, reminders with no detail on the purpose of the session

For a solo consultant, this record fits on one page. The real work: listing your tools, checking where each one hosts the data and that a data processing agreement covers it.

What does a record of processing look like for a small agency with 3 employees?

A communications agency set up as a « SARL » (private limited company), with a manager and three employees. On top of the commercial processing come the staff-related activities, which are more sensitive and subject to precise statutory periods.

HeadingHR managementPayrollClients and prospects
PurposeManage personnel files, contracts, leave and trainingCalculate and pay salaries, declare contributions (« DSN », France’s monthly payroll filing)Manage projects, quotes, invoices and B2B prospecting
Legal basisPerformance of the employment contract (Art. 6(1)(b)) and legal obligations (Art. 6(1)(c))Legal obligation (Art. 6(1)(c))Performance of the contract (Art. 6(1)(b)); legitimate interest for B2B prospecting (CNIL standard)
PeopleEmployees, internsEmployeesContacts at clients and prospects
DataIdentity, contact details, contract, qualifications, leave, performance reviewsIdentity, social security number, bank details, salary, working time, absencesName, job title, work contact details, exchanges, quotes, invoices
RecipientsManager, HR softwareAccountant or payroll provider, social security bodies via the DSN, tax authoritiesTeam, CRM, invoicing software, accountant
Transfers outside the EUDepending on the toolsDepending on the toolsDepending on the tools
RetentionLength of employment, then archiving within the applicable limitation period (CNIL HR standard)During employment, then a rolling 6 years after the DSN (CNIL HR standard, Tax Procedures Code, art. L102 B); copies of payslips: 5 years (Labour Code, art. L3243-4)Prospecting: customer relationship then 3 years (CNIL standard); invoices: 10 years (Commercial Code, art. L123-22)
SecurityFiles accessible to the manager only, locked cabinet for paper, encrypted computersSent to the accountant over a secure channel, restricted accessNamed accounts, two-factor authentication, backups

One point specific to agencies: if you run your clients’ website, email marketing or CRM, you process their data on their behalf. That makes you a processor, and Article 30(2) requires a second record, organised by client. In December 2025 the CNIL sanctioned a processor that did not keep this record (see below).

How does the record of processing relate to the privacy policy?

The record is the internal, exhaustive version; the privacy policy is the public one. Article 13 of the GDPR requires you to tell people the purposes, legal basis, recipients, transfers and retention period: exactly the columns of your record.

In the record (Art. 30)In the privacy policy (Art. 13)
PurposesPurposes and legal basis
Categories of recipientsRecipients or categories of recipients
Transfers outside the EUTransfers, adequacy decision or safeguards
Time limits for erasureRetention period or the criteria used to set it
Security measuresNot required
Not requiredData subjects’ rights, right to complain to the CNIL

The safest method is to fill in the record first, then write the policy from it. A retention period that differs from one document to the other is an inconsistency anyone spots on first reading. Our guide to the privacy policy in France details what it must contain.

What is the fine for not keeping a record of processing?

A breach of Article 30 can lead to a fine of up to €10 million or 2% of worldwide annual turnover, whichever is higher (Article 83(4) of the GDPR). For a small business, the CNIL can use its simplified procedure, where the fine is capped at €20,000.

The GDPR ceiling is the same across the EU; the simplified procedure (in French) is specific to France. Its €20,000 ceiling applies when worldwide annual turnover does not exceed €50 million; above that, it rises to €100,000 (« loi Informatique et Libertés » (French Data Protection Act), art. 22-1). Three decisions where the record is among the breaches:

DateOrganisationWhat was wrong with the recordOutcome
29 December 2023Tagadamedia, data broker (SAN-2023-025)Record shared with another company, without stating which one was the controller€75,000 for all breaches combined, cut to €50,000 by the Conseil d’État (France’s highest administrative court) on 20 May 2026 on procedural grounds (CNIL)
October 2024 (announcement)Two unnamed companies with fewer than 250 employeesNo record, although their processing was not occasionalSanctions under the simplified procedure (CNIL)
11 December 2025Mobius Solutions, processorNo record kept as a processor€1,000,000 for all breaches combined, including a data breach (CNIL)

All three CNIL sources in this table are in French. In the two detailed decisions, the record is not the only breach: it comes on top of others and makes the case heavier. Our guide to CNIL fines covers the amounts and procedures.

How do I keep my record of processing up to date?

Update the record whenever a processing activity appears, changes or ends: a new tool, a new provider, a new way of collecting data. An annual review catches whatever slipped through during the year.

Your record of processing in 10 steps0/10

The record sits alongside other internal documents, such as your providers’ contracts and your data breach procedure. For the full list for your business, see our guide to mandatory legal documents in France, or run the free obligations check from your SIREN (French company registration number). And to see where your website stands in two minutes, take the website compliance quiz.

Sources

  1. CNIL GDPR, Chapter IV: controller and processor (art. 30: records of processing activities, in French)
  2. EUR-Lex Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation)
  3. CNIL GDPR, Chapter II: principles (art. 5, in French)
  4. CNIL GDPR, Chapter III: rights of the data subject (art. 13, in French)
  5. CNIL GDPR, Chapter VIII: remedies, liability and penalties (art. 83, in French)
  6. CNIL Le registre des activités de traitement (the record of processing activities, in French)
  7. CNIL Modèle de registre simplifié (simplified record template, ODS spreadsheet, in French)
  8. Légifrance Délibération n° 2021-131 du 23 septembre 2021 portant adoption d’un référentiel relatif aux traitements de données à caractère personnel mis en œuvre aux fins de gestion des activités commerciales (CNIL decision adopting its standard on managing commercial activities, in French)
  9. CNIL Référentiel relatif aux traitements de données à caractère personnel mis en œuvre aux fins de gestion des activités commerciales (CNIL standard on personal data processing for managing commercial activities, in French)
  10. CNIL Référentiel : les durées de conservation des données à caractère personnel, gestion des ressources humaines (CNIL standard on retention periods for HR data, 2 April 2026, updated 20 May 2026, in French)
  11. CNIL Délibération n° 2018-303 du 6 septembre 2018 (CNIL recommendation on processing payment card data for distance selling of goods and services, in French)
  12. CNIL Invalidation du Privacy shield : les suites de l’arrêt de la CJUE (invalidation of the Privacy Shield: what follows from the CJEU ruling, in French)
  13. CNIL Cookies : solutions pour les outils de mesure d’audience (cookies: solutions for audience measurement tools, in French)
  14. Légifrance Code de commerce (Commercial Code), art. L123-22
  15. Légifrance Livre des procédures fiscales (Tax Procedures Code), art. L102 B
  16. Légifrance Code du travail (Labour Code), art. L3243-4
  17. Légifrance Loi n° 78-17 du 6 janvier 1978 (French Data Protection Act, « loi Informatique et Libertés »), art. 22-1
  18. CNIL La procédure de sanction simplifiée (the simplified sanction procedure, in French)
  19. CNIL La CNIL a prononcé ces trois derniers mois onze nouvelles sanctions dans le cadre de la procédure simplifiée (the CNIL issued eleven new sanctions under the simplified procedure in the last three months, in French)
  20. Légifrance Délibération SAN-2023-025 du 29 décembre 2023 (CNIL restricted committee decision against Tagadamedia, in French)
  21. CNIL Courtiers en données : sanction de 75 000 euros à l’encontre de la société TAGADAMEDIA (data brokers: €75,000 fine against TAGADAMEDIA, in French)
  22. CNIL Violation de données : sanction d’un million d’euros à l’encontre de la société MOBIUS SOLUTIONS LTD (data breach: €1 million fine against MOBIUS SOLUTIONS LTD, in French)
  23. EDPB EDPB-EDPS Joint Opinion 01/2025 on the Proposal for a Regulation on simplification measures for SMEs and SMCs, in particular the record-keeping obligation under Art. 30(5) GDPR
  24. Parlement européen, Observatoire législatif Procedure 2025/0130(COD): Omnibus IV, extending to small mid-caps certain measures available to SMEs
  25. CNIL Practice guide for the security of personal data: 2024 edition

General information, not legal advice. This guide describes the rules that apply in France as of 7 October 2026. For a specific situation, consult a lawyer. Spotted a mistake or a change in the law? Write to us.

FAQ

Frequently asked questions.

Does a micro-business or sole trader need a GDPR record of processing?

Yes, in almost every case. Article 30(5) of the GDPR exempts organisations with fewer than 250 employees only for processing that is occasional, risk-free and involves no sensitive data. Invoicing, a customer file or a newsletter are regular processing activities, and the CNIL (the French data protection authority) itself gives customer and prospect management as an example of non-occasional processing that must go in the record.

Is there a free record of processing template?

Yes. The CNIL provides a simplified record template as an ODS spreadsheet (in French), which you can download from its page on the record of processing activities. The GDPR imposes no format: a spreadsheet, a text document or an online tool will all do, as long as the record is in writing and contains the information listed in Article 30.

Do I have to publish my record of processing on my website?

No. The record is an internal document that you must make available to the supervisory authority (the CNIL in France) on request, under Article 30(4) of the GDPR. What must be public is your privacy policy, which repeats part of the record: purposes, legal bases, recipients, transfers and retention periods.

What is the fine for not keeping a record of processing?

A breach of Article 30 falls under the fines in Article 83(4) of the GDPR: up to €10 million or 2% of worldwide annual turnover, whichever is higher. For a small business, the CNIL can use its simplified procedure, where the fine is capped at €20,000 when turnover is below €50 million. In 2024, it sanctioned two companies with fewer than 250 employees this way for having no record.

Does a processor also need a record of processing?

Yes. Article 30(2) of the GDPR requires a processor to keep a separate record listing the categories of processing carried out for each client, transfers outside the European Union and security measures. A web agency that runs its clients’ newsletter or website therefore keeps two records: its own as a controller, and one for the work it does on behalf of its clients.

Read next

Related guides.