Contents
- What is a GDPR record of processing activities?
- What must a record of processing activities contain?
- Do small businesses with fewer than 250 employees need a record of processing?
- Is the 250-employee threshold going up to 750?
- Is there a free CNIL record of processing template?
- What does a record of processing look like for an online shop?
- What does a record of processing look like for a freelance consultant or coach?
- What does a record of processing look like for a small agency with 3 employees?
- How does the record of processing relate to the privacy policy?
- What is the fine for not keeping a record of processing?
- How do I keep my record of processing up to date?
On 8 October 2024, the CNIL (the French data protection authority) announced that it had sanctioned two companies with fewer than 250 employees for having no record of processing activities (in French). Being small did not protect them: their processing was not occasional, and once that is the case, the exemption for small organisations no longer applies.
Most founders assume the « registre des traitements » (record of processing activities, often shortened to RoPA) is for large groups. For an online shop or a consultant, it fits on three or four entries. The obligation comes from the GDPR, so it is the same across the EU; what is French-specific is the enforcer (the CNIL), its simplified sanction procedure and the statutory retention periods in the examples below, which come from French law. Here are three filled-in examples, ready to adapt.
What is a GDPR record of processing activities?
The record of processing activities is the written inventory of everything your business does with personal data, with, for each activity, its purpose, the data used, who receives it and how long it is kept. It is required by Article 30 of the GDPR and must be shown to the CNIL if it asks.
A “processing activity” is a use of data organised around one goal: handling orders, sending a newsletter, paying staff. A single customer file used both to deliver orders and to market to people gives you two entries, because the legal bases and retention periods differ.
The record does three concrete jobs:
- proving your compliance during an inspection, without rebuilding everything in a panic;
- feeding your privacy policy, which repeats much of its content;
- exposing blind spots: a US tool nobody had flagged, data kept forever, a provider with no contract.
What must a record of processing activities contain?
For each processing activity, the controller’s record states the purposes, the categories of people and data, the recipients, transfers outside the European Union, time limits for erasure and a general description of security measures, plus the business’s contact details. A processor keeps a shorter record, organised by client.
| Heading (Art. 30) | Controller’s record (30(1)) | Processor’s record (30(2)) |
|---|---|---|
| Identity | Name and contact details of the controller, any joint controller, the representative and the data protection officer (DPO) where applicable | Name and contact details of the processor and of each client it acts for, and of the DPO where applicable |
| Purposes | Mandatory, activity by activity | Categories of processing carried out for each client |
| People and data | Categories of data subjects and of personal data | Not required |
| Recipients | Categories of recipients, including outside the EU | Not required |
| Transfers outside the EU | Recipient country or organisation, and safeguards in some cases | Same |
| Retention periods | “Where possible”, time limits for erasure | Not required |
| Security | “Where possible”, a general description of the measures | Same |
The record is kept in writing, including in electronic form (Art. 30(3)), and made available to the supervisory authority on request (Art. 30(4)): nothing requires you to publish it, and the format is up to you.
Do not read “where possible” as optional. For retention, an entry with no period is the first sign that you keep everything indefinitely, which Article 5 of the GDPR prohibits under the storage limitation principle.
Do small businesses with fewer than 250 employees need a record of processing?
Yes, almost always. Article 30(5) exempts organisations with fewer than 250 employees, but the exemption falls away as soon as processing is not occasional, poses a risk to individuals or involves sensitive or criminal data: managing customers, prospects or payroll is enough to lose it.
What the law says
The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.
The three exceptions are alternatives: one is enough. And the first, “not occasional”, on its own rules out most of what a business does. The CNIL says so plainly on its page on the record (in French): the record must include “non-occasional processing (for example: payroll management, management of customers/prospects and suppliers, etc.)” (our translation). It adds that the exemption “is therefore limited to very specific cases of processing” and recommends, when in doubt, putting the processing in the record.
So what stays occasional? A one-off prize draw, a trade fair where you picked up a few business cards and never followed up. Your Shopify store taking orders every week, your appointment calendar, your invoice file: no.
flowchart TD
A["You process personal data"] --> B{"250 employees or more?"}
B -->|Yes| R["Record mandatory"]
B -->|No| C{"Regular processing?"}
C -->|Yes| R
C -->|No| D{"Sensitive or criminal data?"}
D -->|Yes| R
D -->|No| E{"Risk to individuals?"}
E -->|Yes| R
E -->|No| F["Exemption possible for this activity"]Is the 250-employee threshold going up to 750?
Perhaps, but not yet. In May 2025 the European Commission proposed extending the exemption to organisations with fewer than 750 employees, except for high-risk processing; as of 7 October 2026, the text has not been adopted and Article 30(5) applies as currently worded.
According to the joint opinion of the EDPB and the EDPS of 8 July 2025, this “Omnibus IV” proposal would make the record mandatory, below that threshold, only for processing “likely to result in a high risk” within the meaning of Article 35 of the GDPR. According to the European Parliament’s Legislative Observatory, the parliamentary committee approved the text negotiated with the Council on 2 July 2026; the plenary vote is listed for 23 November 2026, and no publication in the Official Journal is reported there.
Do not wait. The final text may differ, and even if you end up exempt, you will still have to inform people, set retention periods and put contracts in place with your providers. The EDPB and the EDPS also describe the record as “a very useful means to support compliance with several GDPR requirements”.
Is there a free CNIL record of processing template?
Yes. The CNIL offers a simplified record template as an ODS spreadsheet (in French), free to download from its page « Le registre des activités de traitement » (the record of processing activities). It opens in LibreOffice, Excel or Google Sheets.
The file is organised in tabs: a tutorial, the list of processing activities headed by the controller’s and DPO’s details, a blank form to copy for each activity, a completed example (payroll) and the drop-down lists. One thing to watch: the list of transfer safeguards still offers “Privacy shield”, which the Court of Justice of the European Union invalidated on 16 July 2020 (in French); do not pick it. The older RTF and PDF templates, still online, are no longer updated according to the CNIL: start from the ODS file.
To fill in retention periods without making them up, rely on the CNIL’s « référentiels » (reference standards): the one on managing commercial activities (decision no. 2021-131 of 23 September 2021) for customers and prospects, and the standard on retention periods for HR data, published on 2 April 2026 and updated on 20 May 2026, for employees (both in French). The periods they recommend are not binding, but departing from them means being able to justify your choice; periods set by statute, such as those in the « Code du travail » (Labour Code) or the « Code de commerce » (Commercial Code), are binding. For security, the CNIL’s practice guide for the security of personal data sets out the basic measures.
What does a record of processing look like for an online shop?
Take a Shopify store selling solid cosmetics, two co-founders, no employees. Three processing activities cover the essentials: orders, the newsletter, audience measurement.
| Heading | Order management | Newsletter | Audience measurement |
|---|---|---|---|
| Purpose | Process orders, delivery, after-sales service and invoicing | Send offers and new products by email | Measure traffic and site performance |
| Legal basis | Performance of the contract (Art. 6(1)(b)); legal obligation for invoicing (Art. 6(1)(c)) | Consent; legitimate interest for an existing customer and similar products (CNIL standard) | Consent to trackers, unless the tool is exempt and configured according to the CNIL’s recommendations |
| People | Customers | Subscribers: customers and prospects | Site visitors |
| Data | Identity, delivery and billing addresses, email, phone, order details, payment status | Email, first name, sign-up date, opens and clicks | Tracker ID, pages viewed, referrer, browser and device |
| Recipients | Co-founders, e-commerce platform, payment provider, carrier, accountant | Email marketing tool | Analytics tool provider |
| Transfers outside the EU | For each provider outside the EU: country and safeguard (adequacy decision, standard contractual clauses) | Same, depending on the tool | Same, depending on the tool |
| Retention | Length of the customer relationship, then archiving within the limitation period (CNIL standard); invoices and accounting records: 10 years (Commercial Code, art. L123-22); card number and expiry date: 13 months after the debit date (15 months for deferred debit), archived, for disputes; security code deleted as soon as payment is complete (CNIL recommendation no. 2018-303) | Until consent is withdrawn, or 3 years after the last contact (CNIL standard) | Trackers: 13 months; information collected: 25 months (CNIL) |
| Security | Named accounts on the back office, two-factor authentication, HTTPS | Access limited to the co-founders, two-factor authentication | Limited dashboard access, minimal configuration |
The CNIL sources in this table are in French.
The detail that matters: if payments go through a provider that stores card data itself, say so in the entry rather than implying that you store card numbers. And the audience measurement entry must match your cookie banner: if the tool is not exempt, nothing is placed before consent.
What does a record of processing look like for a freelance consultant or coach?
An organisational consultant trading as a « micro-entrepreneur » (France’s simplified sole-trader status) who prospects SMEs on LinkedIn and by email, invoices her assignments and books sessions through an online scheduling tool.
| Heading | Prospecting | Invoicing | Appointment booking |
|---|---|---|---|
| Purpose | Approach businesses and follow up on exchanges | Issue and keep invoices, track payments | Schedule discovery calls and sessions, send reminders |
| Legal basis | Legitimate interest for business-to-business prospecting (CNIL standard) | Legal obligation (Art. 6(1)(c)) | Pre-contractual steps or performance of the contract (Art. 6(1)(b)) |
| People | Managers and employees of prospected businesses | Clients | Clients and prospects |
| Data | Name, job title, company, work email and phone, history of exchanges | Identity, address, services, amounts, payments | Name, email, phone, time slot, purpose of the appointment |
| Recipients | The consultant, CRM | Accountant, invoicing software, tax authorities in an audit | Scheduling tool, video-call tool |
| Transfers outside the EU | Depending on where the CRM is hosted | Depending on the software | Depending on the tools |
| Retention | 3 years from collection or from the prospect’s last contact (CNIL standard) | 6 years (« Livre des procédures fiscales » (Tax Procedures Code), art. L102 B); 10 years for a trader or a commercial company (Commercial Code, art. L123-22) | Length of the relationship; for a prospect who did not follow up, 3 years after their last contact (CNIL standard) |
| Security | Strong password and two-factor authentication on the CRM | Regular backups, limited access | Named accounts, reminders with no detail on the purpose of the session |
For a solo consultant, this record fits on one page. The real work: listing your tools, checking where each one hosts the data and that a data processing agreement covers it.
What does a record of processing look like for a small agency with 3 employees?
A communications agency set up as a « SARL » (private limited company), with a manager and three employees. On top of the commercial processing come the staff-related activities, which are more sensitive and subject to precise statutory periods.
| Heading | HR management | Payroll | Clients and prospects |
|---|---|---|---|
| Purpose | Manage personnel files, contracts, leave and training | Calculate and pay salaries, declare contributions (« DSN », France’s monthly payroll filing) | Manage projects, quotes, invoices and B2B prospecting |
| Legal basis | Performance of the employment contract (Art. 6(1)(b)) and legal obligations (Art. 6(1)(c)) | Legal obligation (Art. 6(1)(c)) | Performance of the contract (Art. 6(1)(b)); legitimate interest for B2B prospecting (CNIL standard) |
| People | Employees, interns | Employees | Contacts at clients and prospects |
| Data | Identity, contact details, contract, qualifications, leave, performance reviews | Identity, social security number, bank details, salary, working time, absences | Name, job title, work contact details, exchanges, quotes, invoices |
| Recipients | Manager, HR software | Accountant or payroll provider, social security bodies via the DSN, tax authorities | Team, CRM, invoicing software, accountant |
| Transfers outside the EU | Depending on the tools | Depending on the tools | Depending on the tools |
| Retention | Length of employment, then archiving within the applicable limitation period (CNIL HR standard) | During employment, then a rolling 6 years after the DSN (CNIL HR standard, Tax Procedures Code, art. L102 B); copies of payslips: 5 years (Labour Code, art. L3243-4) | Prospecting: customer relationship then 3 years (CNIL standard); invoices: 10 years (Commercial Code, art. L123-22) |
| Security | Files accessible to the manager only, locked cabinet for paper, encrypted computers | Sent to the accountant over a secure channel, restricted access | Named accounts, two-factor authentication, backups |
One point specific to agencies: if you run your clients’ website, email marketing or CRM, you process their data on their behalf. That makes you a processor, and Article 30(2) requires a second record, organised by client. In December 2025 the CNIL sanctioned a processor that did not keep this record (see below).
How does the record of processing relate to the privacy policy?
The record is the internal, exhaustive version; the privacy policy is the public one. Article 13 of the GDPR requires you to tell people the purposes, legal basis, recipients, transfers and retention period: exactly the columns of your record.
| In the record (Art. 30) | In the privacy policy (Art. 13) |
|---|---|
| Purposes | Purposes and legal basis |
| Categories of recipients | Recipients or categories of recipients |
| Transfers outside the EU | Transfers, adequacy decision or safeguards |
| Time limits for erasure | Retention period or the criteria used to set it |
| Security measures | Not required |
| Not required | Data subjects’ rights, right to complain to the CNIL |
The safest method is to fill in the record first, then write the policy from it. A retention period that differs from one document to the other is an inconsistency anyone spots on first reading. Our guide to the privacy policy in France details what it must contain.
What is the fine for not keeping a record of processing?
A breach of Article 30 can lead to a fine of up to €10 million or 2% of worldwide annual turnover, whichever is higher (Article 83(4) of the GDPR). For a small business, the CNIL can use its simplified procedure, where the fine is capped at €20,000.
The GDPR ceiling is the same across the EU; the simplified procedure (in French) is specific to France. Its €20,000 ceiling applies when worldwide annual turnover does not exceed €50 million; above that, it rises to €100,000 (« loi Informatique et Libertés » (French Data Protection Act), art. 22-1). Three decisions where the record is among the breaches:
| Date | Organisation | What was wrong with the record | Outcome |
|---|---|---|---|
| 29 December 2023 | Tagadamedia, data broker (SAN-2023-025) | Record shared with another company, without stating which one was the controller | €75,000 for all breaches combined, cut to €50,000 by the Conseil d’État (France’s highest administrative court) on 20 May 2026 on procedural grounds (CNIL) |
| October 2024 (announcement) | Two unnamed companies with fewer than 250 employees | No record, although their processing was not occasional | Sanctions under the simplified procedure (CNIL) |
| 11 December 2025 | Mobius Solutions, processor | No record kept as a processor | €1,000,000 for all breaches combined, including a data breach (CNIL) |
All three CNIL sources in this table are in French. In the two detailed decisions, the record is not the only breach: it comes on top of others and makes the case heavier. Our guide to CNIL fines covers the amounts and procedures.
How do I keep my record of processing up to date?
Update the record whenever a processing activity appears, changes or ends: a new tool, a new provider, a new way of collecting data. An annual review catches whatever slipped through during the year.
The record sits alongside other internal documents, such as your providers’ contracts and your data breach procedure. For the full list for your business, see our guide to mandatory legal documents in France, or run the free obligations check from your SIREN (French company registration number). And to see where your website stands in two minutes, take the website compliance quiz.
Sources
- CNIL GDPR, Chapter IV: controller and processor (art. 30: records of processing activities, in French)
- EUR-Lex Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation)
- CNIL GDPR, Chapter II: principles (art. 5, in French)
- CNIL GDPR, Chapter III: rights of the data subject (art. 13, in French)
- CNIL GDPR, Chapter VIII: remedies, liability and penalties (art. 83, in French)
- CNIL Le registre des activités de traitement (the record of processing activities, in French)
- CNIL Modèle de registre simplifié (simplified record template, ODS spreadsheet, in French)
- Légifrance Délibération n° 2021-131 du 23 septembre 2021 portant adoption d’un référentiel relatif aux traitements de données à caractère personnel mis en œuvre aux fins de gestion des activités commerciales (CNIL decision adopting its standard on managing commercial activities, in French)
- CNIL Référentiel relatif aux traitements de données à caractère personnel mis en œuvre aux fins de gestion des activités commerciales (CNIL standard on personal data processing for managing commercial activities, in French)
- CNIL Référentiel : les durées de conservation des données à caractère personnel, gestion des ressources humaines (CNIL standard on retention periods for HR data, 2 April 2026, updated 20 May 2026, in French)
- CNIL Délibération n° 2018-303 du 6 septembre 2018 (CNIL recommendation on processing payment card data for distance selling of goods and services, in French)
- CNIL Invalidation du Privacy shield : les suites de l’arrêt de la CJUE (invalidation of the Privacy Shield: what follows from the CJEU ruling, in French)
- CNIL Cookies : solutions pour les outils de mesure d’audience (cookies: solutions for audience measurement tools, in French)
- Légifrance Code de commerce (Commercial Code), art. L123-22
- Légifrance Livre des procédures fiscales (Tax Procedures Code), art. L102 B
- Légifrance Code du travail (Labour Code), art. L3243-4
- Légifrance Loi n° 78-17 du 6 janvier 1978 (French Data Protection Act, « loi Informatique et Libertés »), art. 22-1
- CNIL La procédure de sanction simplifiée (the simplified sanction procedure, in French)
- CNIL La CNIL a prononcé ces trois derniers mois onze nouvelles sanctions dans le cadre de la procédure simplifiée (the CNIL issued eleven new sanctions under the simplified procedure in the last three months, in French)
- Légifrance Délibération SAN-2023-025 du 29 décembre 2023 (CNIL restricted committee decision against Tagadamedia, in French)
- CNIL Courtiers en données : sanction de 75 000 euros à l’encontre de la société TAGADAMEDIA (data brokers: €75,000 fine against TAGADAMEDIA, in French)
- CNIL Violation de données : sanction d’un million d’euros à l’encontre de la société MOBIUS SOLUTIONS LTD (data breach: €1 million fine against MOBIUS SOLUTIONS LTD, in French)
- EDPB EDPB-EDPS Joint Opinion 01/2025 on the Proposal for a Regulation on simplification measures for SMEs and SMCs, in particular the record-keeping obligation under Art. 30(5) GDPR
- Parlement européen, Observatoire législatif Procedure 2025/0130(COD): Omnibus IV, extending to small mid-caps certain measures available to SMEs
- CNIL Practice guide for the security of personal data: 2024 edition
General information, not legal advice. This guide describes the rules that apply in France as of 7 October 2026. For a specific situation, consult a lawyer. Spotted a mistake or a change in the law? Write to us.

