GDPR Article 30 documentation Records of processing — CNIL-compliant setup and maintenance

We inventory your personal data processing, build the necessary record sheets and deliver a structured register that you can actually use and keep up to date, based on GDPR Article 30 requirements and CNIL recommendations.

Not a file filled in for the sake of it: a genuine mapping and compliance steering tool. The CNIL itself presents the register as a way not only to document compliance, but also to identify and prioritise risks.

Register delivered in 2 to 3 weeks
Editable register, Excel/ODS and PDF exports
Internal owner training

What you get

At the end of the engagement

A complete records of processing, compliant with GDPR Article 30, documenting each processing activity with its regulatory characteristics — ready for a CNIL inspection.

2–3 weeks
Art. 30 compliant
5 deliverables

First check during a CNIL inspection: presenting your records of processing

Register delivered in 2 to 3 weeks CNIL format, editable Excel/ODS and PDF Training and maintenance procedure included

+150 registers created

0 non-compliance reported

4.9/5 client satisfaction

What are GDPR records of processing?

The records of processing activities list the personal data processing carried out by an organisation. Required by GDPR Article 30, they provide a structured view of the data processed, their purposes, the data subjects, the recipients, retention periods, any transfers and the associated security measures.

Inventory

Which processing activities exist?

Understand

Why and how is the data used?

Document

Which rules and measures apply?

Steer

Which gaps or risks need to be corrected?

Who must keep a GDPR register?

GDPR Article 30 sets a general duty to keep records. The exemption for some organisations with fewer than 250 employees is very limited: it does not mean SMEs are excused.

250 employees or more

General principle: keep the register.

  • Article 30 requires records of processing activities
  • No size-based exemption
  • The register must be available to the CNIL

Fewer than 250 employees

The exemption is very limited. It does not apply in particular if the processing:

  • is not occasional
  • presents a risk to rights and freedoms
  • involves certain special categories of data
  • or data relating to criminal convictions and offences

The CNIL therefore summarises the position by stating that keeping the register concerns most organisations that regularly process personal data.

In practice, a business that regularly manages customers, prospects, employees, suppliers or users generally has an interest in checking precisely whether it can actually rely on the exception.

Controller or processor: which register must you keep?

Article 30 distinguishes two registers according to the organisation’s role. A controller’s register and a processor’s register do not document the same activities.

Controller

Records of processing carried out under its responsibility.

  • Determines the purposes and means of the processing
  • Documents its own processing (customers, HR, prospects…)
  • Article 30(1) core

Processor

Records of categories of activities carried out for its clients.

  • Processes data on behalf of a controller
  • Documents the categories of activities carried out for each client
  • Article 30(2) core

If the same organisation acts both as controller and as processor, the CNIL recommends clearly distinguishing the two categories and, in practice, keeping two registers.

Article 30 core and Complianz enriched register

Article 30 sets the legally required entries for a controller’s records of processing. The CNIL recommends going beyond this core so the register becomes a genuine mapping and compliance steering tool.

Article 30 core

The legally required entries.

  • Controller and contact details
  • Purposes
  • Categories of data subjects
  • Categories of data
  • Recipients
  • Any international transfers
  • Erasure time limits, where possible
  • General description of security measures, where possible

Complianz enriched register

Beyond the legal core, to actually steer compliance.

  • Legal basis
  • Data source
  • Retention criteria
  • Associated documentation
  • Risks
  • Possible DPIA
  • Processor contracts
  • Compliance status
  • Internal owner
  • Actions to take

The legal basis is not a mandatory Article 30 field. We include it, as the CNIL recommends, with the other enrichment fields, so each processing record actually helps you steer compliance.

Filled GDPR register example

A fictional, simplified extract to show what structured GDPR records of processing look like — then an opened processing record sheet.

Processing Purpose Data subjects Data Retention Legal basis
Customer management Invoicing & follow-up Customers identity, contact details, invoices According to applicable rules Contract / legal obligation
Prospecting Business development Prospects name, email, company Defined period To be qualified
HR Staff administration Employees identity, payroll, career By category To be qualified

Example GDPR processing record

Processing: Customer relationship management

Purpose
Order management and commercial relationship.
Data subjects
Customers and customer contacts.
Data
Identity, contact details, contractual information.
Recipients
Relevant teams and identified providers.
Retention
Documented rules according to the data concerned.
Security
Restricted access, authentication, backups, etc.

Fictional and simplified example: the real content of a record sheet depends on the processing activity and the organisation’s context.

A GDPR processing activity is not a software tool

The register lists processing activities defined by their purpose, not the applications that support them. The same tool may serve several processing activities; the same processing activity may use several tools.

These are not processing activities

These are tools.

  • Salesforce
  • Brevo
  • Google Drive

These are processing activities

They may use those tools.

  • Prospect management
  • Customer management
  • Application management
  • Payroll management

The CNIL recommends mapping processing activities by main purpose, not by application.

Records of processing and data mapping: what is the difference?

The two complement each other. The register is the document expected under Article 30; data mapping provides a broader view, upstream.

Register

A structured document meeting Article 30 requirements in particular.

  • Records by processing activity
  • Regulatory entries and steering
  • Document to present to the CNIL

Mapping

A broader view of flows, systems and parties.

  • flows
  • applications
  • people
  • recipients
  • providers
  • systems
  • data location

Mapping often helps build and make the register more reliable.

Is there a CNIL GDPR register template?

Yes. The CNIL provides a simplified ODS template, particularly aimed at the day-to-day needs of smaller organisations. It states that this template can meet the core requirements of Article 30 and recommends enriching it when that helps steer compliance more effectively.

Identify

Correctly spot the processing that actually takes place, not only what is already documented.

Interview

Ask the right teams (HR, sales, IT, marketing…) so the register matches real practice.

Distinguish

Separate purposes, avoid catch-all records and document what is actually processed.

Maintain

Keep the register alive over time, whenever a new tool, provider or data use appears.

The problem is generally not finding an empty spreadsheet: it is correctly identifying processing activities, interviewing the right teams, distinguishing purposes and then maintaining the document.

Must AI processing activities appear in the GDPR register?

When an AI system carries out processing of personal data within the scope of the GDPR, the relevant processing activities must be included in the mapping and documented like any other applicable processing. The CNIL also notes that some AI models themselves may fall under the GDPR when they contain or retain personal data.

  • chatbot using customer data
  • scoring
  • HR tool
  • transcription
  • AI agent connected to the CRM
  • generation using personal data
  • automatic case analysis

The register documents these activities under the GDPR. The specific framework for AI systems (risks, governance, AI Act) is covered in a dedicated engagement.

See our AI compliance & AI Act support

Is your GDPR register actually up to date?

Six questions to estimate how complete and current your register is — and to identify update priorities.

State of your GDPR register

Completeness 53%
Freshness Needs review
Priorities 4
  • Processing52%
  • Retention40%
  • Processors60%
  • Security58%
  • Documentation58%

Recommended priorities

  • complete retention periods
  • inventory new processing activities
  • identify processors
  • set up a periodic review

Recommended need

Update & enrich the register

Have my register reviewed

Indicative diagnostic that does not constitute a legal validation of compliance.

What you receive at the end of setup

A complete, documented and self-sufficient register — your team can keep it up to date without relying on a consultant.

Inventory of processing activities

List of processing activities identified by purpose, not by software — by department (HR, marketing, IT, sales…).

Detailed record sheets

Each sheet covers the Article 30 core, then the fields useful for steering (legal basis, risks, DPIA, contracts, actions…).

Editable Excel / ODS register

A maintainable version so the register can actually live. Excel and ODS for updates (the CNIL’s own base template is ODS).

Summary mapping

An overview of flows, applications, recipients and data location — to make the register more reliable.

List of identified gaps

Missing or inconsistent elements: unclear purposes, missing retention periods, incomplete recipients, undescribed security measures.

Update procedure

Documented procedure to add, modify or remove a processing activity from the register autonomously.

Internal owner training

Transfer of the maintenance method to the person in charge of updating the register.

The Complete GDPR register + diagnostic pack also includes an associated compliance roadmap: priorities, owners and a timeline to address the gaps.

See the complete + diagnostic pack

How do we build your records of processing?

Seven steps, from scoping through to maintenance training — for a real register built from your teams’ practices, not a generic spreadsheet.

01

Scoping

Identification of the entities, departments and stakeholders involved, to set a register scope that can actually be maintained.

02

Business interviews

Collection of practices as they actually exist, from the teams that process the data.

  • HR
  • sales
  • marketing
  • finance
  • IT
  • support
03

Inventory of processing activities

By purpose, not merely by software. The CNIL specifically recommends drawing up the list of processing activities according to their main purpose, rather than inventorying applications. See a GDPR processing activity is not a software tool.

04

Building the records

Drafting each record: Article 30 information, then relevant complementary information to steer compliance.

05

Gap analysis

Identification of missing or inconsistent elements — unclear purposes, missing retention periods, incomplete recipients, undescribed security measures.

06

Delivery

Handover of the final register and associated recommendations, in an editable and usable format.

07

Training

Transfer of the maintenance method, so your teams can update the register without relying on a consultant.

The register is not a template to fill in: it is built from the business teams, real purposes and identified gaps.

A GDPR register is never really “finished”

The register must reflect the reality of processing activities. The CNIL recommends updating it when processing changes and presents it as a dynamic steering tool.

  • new software
  • new marketing campaign
  • new purpose
  • new processor
  • change of retention period
  • transfer outside the EU
  • new AI system
  • new activity

That is precisely the purpose of our update & maintenance plan.

See update & maintenance

How much does a GDPR register cost and what does the price depend on?

The ranges below are indicative. The quote depends on the reality of your organisation — not a single flat fee. Provided within 24 hours.

  • number of entities
  • number of departments
  • number of processing activities
  • maturity of existing documentation
  • number of processors
  • sensitive processing
  • international transfers
  • volume of interviews
  • existing register or full setup
  • mapping need
  • maintenance need

GDPR register setup

€900 – 1,800 excl. VAT

Document your processing activities. Micro-business / SME up to 30 processing activities.

  • Processing inventory
  • Detailed record sheets
  • Editable Excel / ODS register
  • Update procedure
Request a quote

Update & maintenance

€600 – 1,200 excl. VAT / year

Keep the register alive as processing activities change.

  • Annual register review
  • Integration of new processing activities
  • Updates following CNIL developments
  • Annual compliance report
Request a quote

The first pack documents. The second documents, analyses inconsistencies and produces recommendations.

Indicative pricing — a tailored quote is provided within 24 hours based on the factors above.

Your questions about records of processing

Our GDPR experts respond within 24 hours to any question about your Article 30 register.

Contact us
What is a GDPR register?

The record of processing activities lists the personal data processing carried out by an organisation. Required by GDPR Article 30, it provides a structured view of purposes, data subjects, recipients, retention periods, any transfers and security measures. See what a GDPR register is.

What does a records of processing contain?

For a controller’s register, Article 30 requires in particular: the controller and contact details, purposes, categories of data subjects and data, recipients, any international transfers, erasure time limits where possible, and a general description of security measures where possible. The legal basis is not a mandatory Article 30 field; the CNIL nevertheless recommends enriching the register. See the Article 30 core.

Is the GDPR register mandatory?

Yes. GDPR Article 30 requires keeping a register. A very limited exemption exists for some organisations with fewer than 250 employees; it does not mean SMEs are excused. The CNIL states that keeping the register concerns most organisations that regularly process personal data. The register must be capable of being presented to the CNIL. See who must keep a register.

Is a business with fewer than 250 employees exempt?

Not systematically. The exception in Article 30(5) is limited and falls away in particular when processing is not occasional or presents certain risk or sensitivity characteristics. See who must keep a GDPR register.

Is there a CNIL register template?

Yes. The CNIL provides in particular a simplified template in ODS format. It states that this can meet the Article 30 core and recommends enriching it to steer compliance. See the CNIL template.

Can Excel be used to keep the register?

Yes. The GDPR requires a written form, including electronic; it does not require a specific software tool. Excel and ODS are suitable for keeping the register alive. We deliver an editable register in these formats.

What is the difference between a GDPR register and data mapping?

The register is a structured document meeting Article 30 requirements in particular. Mapping provides a broader view of flows, applications, people, recipients, providers, systems and data location. Mapping often helps build and make the register more reliable. See register and mapping.

Who must keep the register inside the organisation?

The CNIL states that a person may be specifically tasked with keeping it and that, where a DPO exists, they may in particular monitor it as part of their duties. See our outsourced DPO.

How often must the register be updated?

There is no “once a year” obligation. The register must mainly reflect processing actually carried out and evolve when that processing changes (new software, new purpose, new processor, transfer outside the EU, AI system…). See the register must stay alive and update & maintenance.

Must AI processing be entered in the register?

Yes, when an AI system carries out processing of personal data within the scope of the GDPR. The relevant activities must be included in the mapping and documented like any other processing. The CNIL also notes that some AI models themselves may fall under the GDPR when they contain or retain personal data. See AI processing in the register and our AI compliance & AI Act support.

What is the difference between a controller register and a processor register?

The controller keeps records of processing carried out under its responsibility. The processor keeps records of categories of activities carried out for its clients. If the same organisation acts in both roles, the CNIL recommends clearly distinguishing the two categories and, in practice, keeping two registers. See controller or processor.

Must every software tool be entered in the register?

No: mapping logic is based on processing activities and their purposes, not on a simple list of tools. Salesforce, Brevo or Google Drive are tools; prospect, customer, applicant or payroll management are processing activities. See a processing activity is not a software tool.

Is a GDPR register enough to be compliant?

No. It is an important documentation and steering element, but GDPR obligations go well beyond keeping the register alone. The CNIL states this explicitly. See our GDPR compliance and GDPR audit.

How much does a GDPR register cost and what does the price depend on?

The price depends in particular on the number of entities, departments and processing activities, the maturity of existing documentation, processors, sensitive processing, international transfers, the volume of interviews, whether a register already exists or a full setup is needed, and the need for mapping and maintenance. Indicative ranges: setup €900 – 1,800 excl. VAT, complete register + diagnostic €1,500 – 2,800 excl. VAT, update & maintenance €600 – 1,200 excl. VAT / year. See pricing.

Ready to create your GDPR records of processing?

Our GDPR experts build your complete Article 30 register in 2 to 3 weeks. Delivered as an editable version (Excel/ODS) and PDF, with team training. First conversation free.

Create my GDPR register
Delivered in 2 to 3 weeks Editable Excel/ODS + PDF Internal owner training
Innovation hub