Inventory
Which processing activities exist?
We inventory your personal data processing, build the necessary record sheets and deliver a structured register that you can actually use and keep up to date, based on GDPR Article 30 requirements and CNIL recommendations.
Not a file filled in for the sake of it: a genuine mapping and compliance steering tool. The CNIL itself presents the register as a way not only to document compliance, but also to identify and prioritise risks.
What you get
At the end of the engagement
A complete records of processing, compliant with GDPR Article 30, documenting each processing activity with its regulatory characteristics — ready for a CNIL inspection.
First check during a CNIL inspection: presenting your records of processing
What is a GDPR register?
The records of processing activities list the personal data processing carried out by an organisation. Required by GDPR Article 30, they provide a structured view of the data processed, their purposes, the data subjects, the recipients, retention periods, any transfers and the associated security measures.
Which processing activities exist?
Why and how is the data used?
Which rules and measures apply?
Which gaps or risks need to be corrected?
Is the GDPR register mandatory?
GDPR Article 30 sets a general duty to keep records. The exemption for some organisations with fewer than 250 employees is very limited: it does not mean SMEs are excused.
General principle: keep the register.
The exemption is very limited. It does not apply in particular if the processing:
The CNIL therefore summarises the position by stating that keeping the register concerns most organisations that regularly process personal data.
In practice, a business that regularly manages customers, prospects, employees, suppliers or users generally has an interest in checking precisely whether it can actually rely on the exception.
Controller vs processor
Article 30 distinguishes two registers according to the organisation’s role. A controller’s register and a processor’s register do not document the same activities.
Records of processing carried out under its responsibility.
Records of categories of activities carried out for its clients.
If the same organisation acts both as controller and as processor, the CNIL recommends clearly distinguishing the two categories and, in practice, keeping two registers.
Article 30 mandatory vs useful enrichment
Article 30 sets the legally required entries for a controller’s records of processing. The CNIL recommends going beyond this core so the register becomes a genuine mapping and compliance steering tool.
The legally required entries.
Beyond the legal core, to actually steer compliance.
The legal basis is not a mandatory Article 30 field. We include it, as the CNIL recommends, with the other enrichment fields, so each processing record actually helps you steer compliance.
Register template and example
A fictional, simplified extract to show what structured GDPR records of processing look like — then an opened processing record sheet.
| Processing | Purpose | Data subjects | Data | Retention | Legal basis |
|---|---|---|---|---|---|
| Customer management | Invoicing & follow-up | Customers | identity, contact details, invoices | According to applicable rules | Contract / legal obligation |
| Prospecting | Business development | Prospects | name, email, company | Defined period | To be qualified |
| HR | Staff administration | Employees | identity, payroll, career | By category | To be qualified |
Example GDPR processing record
Fictional and simplified example: the real content of a record sheet depends on the processing activity and the organisation’s context.
Register ≠ list of software
The register lists processing activities defined by their purpose, not the applications that support them. The same tool may serve several processing activities; the same processing activity may use several tools.
These are tools.
They may use those tools.
The CNIL recommends mapping processing activities by main purpose, not by application.
Register vs mapping
The two complement each other. The register is the document expected under Article 30; data mapping provides a broader view, upstream.
A structured document meeting Article 30 requirements in particular.
A broader view of flows, systems and parties.
Mapping often helps build and make the register more reliable.
CNIL template
Yes. The CNIL provides a simplified ODS template, particularly aimed at the day-to-day needs of smaller organisations. It states that this template can meet the core requirements of Article 30 and recommends enriching it when that helps steer compliance more effectively.
Correctly spot the processing that actually takes place, not only what is already documented.
Ask the right teams (HR, sales, IT, marketing…) so the register matches real practice.
Separate purposes, avoid catch-all records and document what is actually processed.
Keep the register alive over time, whenever a new tool, provider or data use appears.
The problem is generally not finding an empty spreadsheet: it is correctly identifying processing activities, interviewing the right teams, distinguishing purposes and then maintaining the document.
AI processing
When an AI system carries out processing of personal data within the scope of the GDPR, the relevant processing activities must be included in the mapping and documented like any other applicable processing. The CNIL also notes that some AI models themselves may fall under the GDPR when they contain or retain personal data.
The register documents these activities under the GDPR. The specific framework for AI systems (risks, governance, AI Act) is covered in a dedicated engagement.
See our AI compliance & AI Act supportConfigurator
Six questions to estimate how complete and current your register is — and to identify update priorities.
State of your GDPR register
Update & enrich the register
Indicative diagnostic that does not constitute a legal validation of compliance.
Mission deliverables
A complete, documented and self-sufficient register — your team can keep it up to date without relying on a consultant.
List of processing activities identified by purpose, not by software — by department (HR, marketing, IT, sales…).
Each sheet covers the Article 30 core, then the fields useful for steering (legal basis, risks, DPIA, contracts, actions…).
A maintainable version so the register can actually live. Excel and ODS for updates (the CNIL’s own base template is ODS).
An overview of flows, applications, recipients and data location — to make the register more reliable.
Missing or inconsistent elements: unclear purposes, missing retention periods, incomplete recipients, undescribed security measures.
Documented procedure to add, modify or remove a processing activity from the register autonomously.
Transfer of the maintenance method to the person in charge of updating the register.
The Complete GDPR register + diagnostic pack also includes an associated compliance roadmap: priorities, owners and a timeline to address the gaps.
See the complete + diagnostic packOur method
Seven steps, from scoping through to maintenance training — for a real register built from your teams’ practices, not a generic spreadsheet.
Identification of the entities, departments and stakeholders involved, to set a register scope that can actually be maintained.
Collection of practices as they actually exist, from the teams that process the data.
By purpose, not merely by software. The CNIL specifically recommends drawing up the list of processing activities according to their main purpose, rather than inventorying applications. See a GDPR processing activity is not a software tool.
Drafting each record: Article 30 information, then relevant complementary information to steer compliance.
Identification of missing or inconsistent elements — unclear purposes, missing retention periods, incomplete recipients, undescribed security measures.
Handover of the final register and associated recommendations, in an editable and usable format.
Transfer of the maintenance method, so your teams can update the register without relying on a consultant.
The register is not a template to fill in: it is built from the business teams, real purposes and identified gaps.
The register must stay alive
The register must reflect the reality of processing activities. The CNIL recommends updating it when processing changes and presents it as a dynamic steering tool.
That is precisely the purpose of our update & maintenance plan.
See update & maintenanceOur pricing
The ranges below are indicative. The quote depends on the reality of your organisation — not a single flat fee. Provided within 24 hours.
GDPR register setup
€900 – 1,800 excl. VAT
Document your processing activities. Micro-business / SME up to 30 processing activities.
Complete GDPR register + diagnostic
€1,500 – 2,800 excl. VAT
Document, analyse inconsistencies and produce recommendations.
Update & maintenance
€600 – 1,200 excl. VAT / year
Keep the register alive as processing activities change.
The first pack documents. The second documents, analyses inconsistencies and produces recommendations.
Indicative pricing — a tailored quote is provided within 24 hours based on the factors above.
The record of processing activities lists the personal data processing carried out by an organisation. Required by GDPR Article 30, it provides a structured view of purposes, data subjects, recipients, retention periods, any transfers and security measures. See what a GDPR register is.
For a controller’s register, Article 30 requires in particular: the controller and contact details, purposes, categories of data subjects and data, recipients, any international transfers, erasure time limits where possible, and a general description of security measures where possible. The legal basis is not a mandatory Article 30 field; the CNIL nevertheless recommends enriching the register. See the Article 30 core.
Yes. GDPR Article 30 requires keeping a register. A very limited exemption exists for some organisations with fewer than 250 employees; it does not mean SMEs are excused. The CNIL states that keeping the register concerns most organisations that regularly process personal data. The register must be capable of being presented to the CNIL. See who must keep a register.
Not systematically. The exception in Article 30(5) is limited and falls away in particular when processing is not occasional or presents certain risk or sensitivity characteristics. See who must keep a GDPR register.
Yes. The CNIL provides in particular a simplified template in ODS format. It states that this can meet the Article 30 core and recommends enriching it to steer compliance. See the CNIL template.
Yes. The GDPR requires a written form, including electronic; it does not require a specific software tool. Excel and ODS are suitable for keeping the register alive. We deliver an editable register in these formats.
The register is a structured document meeting Article 30 requirements in particular. Mapping provides a broader view of flows, applications, people, recipients, providers, systems and data location. Mapping often helps build and make the register more reliable. See register and mapping.
The CNIL states that a person may be specifically tasked with keeping it and that, where a DPO exists, they may in particular monitor it as part of their duties. See our outsourced DPO.
There is no “once a year” obligation. The register must mainly reflect processing actually carried out and evolve when that processing changes (new software, new purpose, new processor, transfer outside the EU, AI system…). See the register must stay alive and update & maintenance.
Yes, when an AI system carries out processing of personal data within the scope of the GDPR. The relevant activities must be included in the mapping and documented like any other processing. The CNIL also notes that some AI models themselves may fall under the GDPR when they contain or retain personal data. See AI processing in the register and our AI compliance & AI Act support.
The controller keeps records of processing carried out under its responsibility. The processor keeps records of categories of activities carried out for its clients. If the same organisation acts in both roles, the CNIL recommends clearly distinguishing the two categories and, in practice, keeping two registers. See controller or processor.
No: mapping logic is based on processing activities and their purposes, not on a simple list of tools. Salesforce, Brevo or Google Drive are tools; prospect, customer, applicant or payroll management are processing activities. See a processing activity is not a software tool.
No. It is an important documentation and steering element, but GDPR obligations go well beyond keeping the register alone. The CNIL states this explicitly. See our GDPR compliance and GDPR audit.
The price depends in particular on the number of entities, departments and processing activities, the maturity of existing documentation, processors, sensitive processing, international transfers, the volume of interviews, whether a register already exists or a full setup is needed, and the need for mapping and maintenance. Indicative ranges: setup €900 – 1,800 excl. VAT, complete register + diagnostic €1,500 – 2,800 excl. VAT, update & maintenance €600 – 1,200 excl. VAT / year. See pricing.
Our GDPR experts build your complete Article 30 register in 2 to 3 weeks. Delivered as an editable version (Excel/ODS) and PDF, with team training. First conversation free.
Quick, free estimate with no commitment — we usually reply within 24 hours.
By submitting this form, you accept our privacy policy.
Choose a day and then a time slot. We will confirm your appointment by email or phone.
Preferred time slot
Request sent successfully
We will get back to you shortly to confirm your time slot.
Availability shown is indicative; final confirmation is provided by our team.