List of processing activities
The processing activities list is a central component of the General Data Protection Regulation (GDPR) and contains information about the processing of personal data by a company. The processing activities list is a document that must be kept by every company organisation that processes personal data in accordance with Article 30 of the General Data Protection Regulation (GDPR)
The list of processing activities should include information on the following aspects:
- Responsible body: The responsible body in the company must be clearly designated. The responsible body in the company is the natural or legal person who decides which personal data is processed and for what purpose. This body is also referred to as the "controller" and is responsible for compliance with data protection regulations.
- Purpose of processing: The purpose for which the personal data is processed should be described. This may, for example, be the processing of business transactions or the fulfilment of contractual obligations.
- Categories of data subjects: The categories of data subjects affected by the processing should be described. These may be customers, employees or suppliers, for example.
- Categories of personal data: The types of personal data that are processed should be described. This may include, for example, name, address, e-mail address, bank details or health data.
- Recipients or categories of recipients: The data subject should be informed to whom the personal data will be disclosed. This may be, for example, partner companies or government agencies.
- Transfer to a country outside the EU or to an international organisation: It should be described whether personal data is transferred to countries outside the EU or to international organisations and which protective measures are taken to adequately protect the data.
- Retention periods: The length of time for which personal data is stored should be described.
- Technical and organisational measures: Technical and organisational measures should be described that are taken to ensure the security of personal data.
The list of processing activities can be kept in electronic or paper form, as long as it meets the requirements of the GDPR and is available or accessible at all times. It should be regularly updated and adapted to changes in processing activities.
In some cases, such as large organisations or complex processing activities, it may also be appropriate to have the register of processing activities managed by an external data protection consultant or service provider who has the necessary expertise and experience to ensure compliance with the GDPR.
A document directory of processing activities must be created for each application or IT system that creates, manages, processes or stores personal data.
Stock-keeping application