Records of Processing Activities Templates and Examples for different Industries

To help you start creating your records of processing activities we have prepared GDPR compliant records of processing activities templates with predefined categories of data that you need to keep track of, for three different industries:

BANKING
TELECOMMUNICATION
RETAIL

However, this article should be helpful, regardless the industry.

What is the Record of Processing Activities?

Art. 30 of the General Data Protection Regulation (GDPR) requires written documentation of procedures concerning personal data you process within your company. It demands that the records need to be in writing, including in the electronic form.

Records of processing activities (ROPA) should answer questions like:

• how are you processing data?
• why are you processing data?
• what kind of data you are processing?
• where is the processing taking place?
•who are you disclosing the data to?

We need to remind you that these records of processing activities templates are just a starting point to get you going. We talked about why an Excel sheet is not a perfect way to keep the records of processing activities.

However, just to be sure you know what are the disadvantages, we refer you to read
Excel vs. GDPR software

Does Your Company Need to Keep Records of Processing Activities?

First things first. Let’s answer the qualification question.  Are you even obligated to keep the Records?

You have to keep records of processing activities if your company has 250 or more employees. 

There is an exception for small and medium-sized companies with fewer than 250 employees, they will be obligated to keep the records if:

• processing is not occasional (processing is not a one-time occurrence)
• the processing is likely to pose a risk to the rights and freedoms of the data subject
• processing involves a special category data or criminal conviction data

Get 14-days Free Data Privacy Manager Trial

Special Categories of Data according to the GDPR

Article 9 of the GDPR states that:

“Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.”

Sensitive personal data - special category under the GDPR

However, since most of the companies are under some national obligation that makes personal data processing mandatory, your company is most likely obligated to keep records of processing activities. Keep in mind, Records of processing activities will be a starting point for audit by the supervisory authority so make sure you keep your records meticulously. GDPR tools can help you in that process by automatization of the entire process.

How to Start with the Records of Processing Activities?

First, you need to discover personal data processing within your organization and document data categories and systems where they are processed. we have discussed this in our blog:

Why is Data Discovery important for compliance? [Infographic]

To do it properly, you should engage other departments. Specifically engage with colleagues from data-driven departments like marketing, HR and legal and your IT. Also, include core business (products, services) departments whose business model relies on data processing.

Determining your role in processing activity

Determine and document your role for each processing activity. You can be a processor in some activities and a controller in others, so make sure you are aware of your responsibilities in each role.

The deciding factor will be the control of the data, rather than possession. So if you are determining how and why you are collecting data you are a controller and your obligations under the GDPR will be greater.

Controller means the natural or legal person, public authority, agency or other bodies which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Data Controller is held accountable for data processing done by the processor and needs to ensure there are agreements, contracts and other measures to ensure the GDPR compliant personal data processing done by the data processor.

Processor means a natural or legal person, public authority, agency or other bodies which processes personal data on behalf of the controller.” (Article 4, definitions). Data Processor is responsible for creating and implementing processes that enable the data controller to gather data, store the data, and transfer it if necessary.

A joint data controller means that your organization, together with one or more organizations, jointly determines ‘why‘ and ‘how’ personal data should be processed. Difference between data controller and data processor

Difference between Data Controller and Data Processor

✅ Data Controller determines the purpose and the meaning of data processing, not the Processor
✅ Data Processor acts on Data Controller instructions, and although can make a certain decision about the way the processing will be done, he has limited control over data
✅ Data Processor has no reason to process that particular set of data on his own
✅ Data Processor and Data Controller have a different set of responsibilities

Information You Should Include in Your Records

•Processing activity name

Data subjects’ categories

•Data categories

Lawful basis

•Purpose of processing

Data retention period

Data controller

•Processing activity details

Data processor

•Data receiver

•Security measures

•External systems

•Owner name

Required form of Records of processing activities

The Records of processing activities have to be in writingincluding in electronic form, and remember, it holds value only if you keep it up to date.

There are a few more things you should take into account. Departments need to be able to cooperate, and there needs to be usability for the departments, as well as availability and integrity of procedural information.

Records of Processing Activities example

The following information is the legally required minimum requirements, which need to be available to the supervisory authority on request. (Article 30(4) of the GDPR).

Document the required information about your company.

 

Data Controller

 

 

Name and contact details

 

 

Data Protection Officer (if applicable)

 

Representative (if applicable)

NameNameName
AddressAddressAddress
EmailEmailEmail
TelephoneTelephoneTelephone

If you are looking for a template to start keeping your Records of Processing Activities, any of the following ones should be sufficient as your starting point.

Records of processing activities template for banking industry

Records of processing activities: Credit example in a bank

Processing activity nameCredit approval
Data subjects categoriesClients
Data categoriesIdentification data; Ownership data
Lawful basisContract
PurposeA loan collateral
Data retention period11 years
Data controllerCompany A
Processing activity detailsWe collect information from the client into the insurance application depending on the type of insurance policy. After that, we print out the client’s offer after the signature is scanned and placed as an integral part of the loan file. These documents are sent for processing to Risk.
Data processor
Data receiverFINA (HR)
Security measuresPseudonymization, Access control, Encryption od data
External systemsCore banking system
Owner nameJohn Williams, Head of Finance

Download Records of processing activities template for the Banking industry

BANKING template

 

Records of processing activities template for telecommunications

Records of processing activities: Marketing example in a Telecommunications company

Processing activity nameNewsletter
Data subjects categoriesMarketing contacts, Clients
Data categoriesContact data, Personal contact data
Lawful basisConsent
PurposeNotifying customers about products and services
Data retention period1 year
Data controllerCompany A
Processing activity detailsRecords of Processing Activities for Marketing activities

to existing and potential customers

Data processorMarketing cloud service provider (HU)
Data receiverFINA (HR)
Security measuresPseudonymization, Access control
External systemsAnalytics system, CRM, Data Warehouse, Salesforce, ERP
Owner nameJoanna Smith, Head of Marketing

Download Records of processing activities template for the Telecommunication industry

TELCO template

Records of processing activities template for retail

Records of processing activities: HR example in a Retail company

Processing activity nameWorking hours record
Data subjects categoriesEmployees
Data categoriesSAP ID
Time and stay information
Lawful basisLegal obligations
PurposeRecording the time an employee spends in a particular workplace space
Data retention periodUntil work contract is no longer valid, expired, or an employee stopped working for the company
Data controllerCompany A
Processing activity detailsEmployees use access cards with which they can enter the premises in accordance with the assigned access rights. Cards also record passing/retention times and are used to record employee attendance and time spent at work. This information is later used in the calculation of salary.
Data processorSAP
EXOR
Data receiverData Link
Security measuresPseudonymization, Access control
External systemsERP
Owner nameMarie Johnson, Head of HR

 

Download Records of processing activities template for Retail

RETAIL template

Software for Managing the GDPR-compliant Processing Records

There are more than a few things you need to take into consideration when deciding on the criteria for suitable software to support your GDPR activities and the Records of processing activities.

The software must provide:

Central management
• Connectivity with other systems
• Proper collaboration through all organizational units
• DPO control panel and segregation of ownership of activities
• Tracking changes on data and demonstrating history
• Automated data removal

Once you have linked your Records of Processing activities to the software, you are ready to start working on this living document and keeping the personal data your company/organization holds/stores/processes. Make sure it stays accurate and up to date.