Unbenanntes Dokument

Records of Processing Activities




Intro: What is meant by creating records of processing activities, what function does it have and what must be taken into account when implementing it?

To-Dos: What is the specific procedure for fulfilling the documentation obligation and related duties?

Statements: What have the data protection supervisory authorities published on the subject of creating records of processing activities?



Create legally compliant records of processing activities





What is meant by creating records of processing activities, what function does it have and what must be taken into account when implementing it?

The obligation to document processing activities is intended to encourage the company to become aware of its own data processing activities. The records of processing activities also serve as orientation point for data protection supervisory authorities when they review the lawfulness of the handling of personal data.

When defining and subsequently documenting processing activities, the purpose is decisive: What is the purpose of the respective processing and how does it differ from other processing activities? In contrast, the type and method of processing (paper, electronic) is not decisive. Nor should a distinction be made between individual processing steps, but rather between the overriding purpose.

Both so-called "controllers" (the ones who define purposes and means of a processing activity) as well as so-called "processors" (the ones who act as service providers and act based on instructions from the controllers) have to draft records of processing activities. However, the scope of documentation is much broader for controllers. Processors must support controllers with the fulfillment of the controller’s extended documentation duties.

The law does not specify the means by which processing activities must be documented. While documentation using a data protection management system is recommended in larger companies, it is sufficient for companies with few data processing activities to use an Excel or Word template.



What is the specific procedure for fulfilling the documentation obligation and related duties?

1

Process for documentation of processing activities
The process should at least inform about (1) who is responsible for the documentation, (2) by which means the documentation should take place and (3) in which way data processing activities are to be documented. This might be accomplished by a documentation directive.


2

Definition of individual processing activities in the company
Differentiation based on the purpose of processing


3

Documentation of processing activities
The documentation should be realized either by manual or technical means such as a data protection management system.




What have the data protection supervisory authorities published on the subject of creating records of processing activities?


>> Find out which other data protection obligations have to be considered with respect to European data protection law.



Unbenanntes Dokument

Appoint a professional data protection officer now!


Do you need support with the implementation of data protection requirements? about our services.
Unbenanntes Dokument

We are
familiar with the characteristics of small and large companies
experienced in communicating with authorities
active in data protection for over 10 years.