Processing activities
A processing activity recorded under Article 30.
- States
- Draft → Legal review → Approved → In use → Suspended → Retired
- Opens at
- Draft
- Answers
- 30 fields, of which 8 are required
Reference · 4.1
This page is generated from the schema the application runs on, so it cannot fall out of step with the screens. For each record type it states what the record is for, the states it passes through in order, and how many answers it holds.
Processing
The Article 30 register of processing activities.
A processing activity recorded under Article 30.
Governance
Who is accountable, and the documents that evidence it.
A controller, joint controller, processor, subprocessor, recipient, Data Protection Officer, representative or authority.
A data protection document such as a DPIA, LIA, TIA, privacy notice, agreement, policy or retention schedule.
Evidence that consent was given, for what wording, and how it can be withdrawn.
A transfer of personal data to a third country or international organisation.
Operations
Open matters with a statutory or internal deadline.
A planned or completed audit, review or supervisory engagement.
A data subject rights request under Chapter III.
A personal data breach record with the seventy-two hour notification clock.
An owned, dated remediation task raised from a finding or a review.
Risk and security
Identified risks and the measures that address them.
One uncertain event, assessed for its consequence for data subjects and for the organisation, treated by measures and monitored or accepted with authority.
A technical or organisational measure and its tested effectiveness.
Resources
The reference records that other registers cite.
A system, application, database, location, device or third-party service that processing depends on.
A named population of people whose personal data is processed, held once and referred to by every activity that concerns it.