Article 30 of GDPR, in force since 2018, firm obligation: any company processing personal data must maintain a <strong>register of processing activities</strong>. According to the APD's latest survey, 60% of Belgian SMEs still don't have one. Here's how to leave that statistic in two hours.
Who must maintain a register?
Officially, the obligation applies to companies with more than 250 employees — but with three exceptions that bring it, in practice, to all companies: as soon as there's non-occasional processing, as soon as it concerns sensitive data (health, opinions, etc.), or as soon as it presents a risk to data subjects.
Payroll, application management, video surveillance, a website with a contact form: all of these apply. In practice, as soon as a company has one employee, it must maintain a register.
What must the register contain
Article 30 lists six mandatory items per processing operation:
The name of the processing and its purpose (payroll, recruitment, prospecting, video surveillance…). The categories of data subjects (employees, candidates, clients, prospects). The categories of data processed (identity, contact, banking data, health data). The recipients (internal, processors, authorities). The retention periods (justified by the purpose or a legal obligation). The technical and organisational security measures.
The five minimum processing operations of an SME
Except for very specific activities, we always find the same basic processing operations:
HR management — contracts, payroll, leave. Legal basis: employment contract and legal obligations. Retention: 5 years after end of contract (10 years for payroll).
Recruitment — CVs, interviews, tests. Legal basis: pre-contractual measures. Retention: 2 years maximum for rejected candidates, with prior information.
Client management — invoicing, commercial relationship, follow-up. Legal basis: contract performance. Retention: 10 years for accounting data, 3 years after end of relationship for the rest.
Commercial prospecting — CRM, newsletters. Legal basis: legitimate interest or consent. Retention: 3 years after last active contact.
Website and cookies — logs, statistics, forms. Legal basis varies by type. Retention: 13 months maximum for statistical cookies.
Mistakes to avoid
The first: drafting a register that's too detailed, unreadable, and never updated. The register is a living tool, not an annual report. Two pages per processing, clear, updatable.
The second: forgetting sub-contracted processing. Your payroll software, your cloud CRM, your emailing platform: these are your processing operations, and it's up to you to list them.
The third: not dating and signing. The register must be dated, signed by the data controller, and presentable to the APD upon simple request.
The format
No format obligation: spreadsheet, database, Word document — all accepted as long as it's readable and up-to-date. The APD recommends a spreadsheet for maintenance. We provide our clients with an Excel template with the five basic processing operations pre-filled — it just remains to adjust the durations, recipients, and security measures specific to the company.
Two hours of well-structured work. It's the best effort-risk ratio in GDPR compliance.