Governance and inventory

Generate and maintain the record of processing

Compile the approved activities into a controller or processor record of processing, and reflect changes to source records through controlled regeneration rather than manual editing.

By the time a supervisory authority asks for the Article 30 record, an organisation should not be assembling it from scratch. The register compiles itself from the activities already brought to In use, so the document reflects what the workspace holds, not what someone remembers to copy across.

This is exercised whenever an activity changes state or its context changes: the compiled register regenerates rather than being hand edited, so it can never drift from its sources.

The proof is an export that a reader can hand to an authority unmodified, with the scope it was read in stated on its face.

Regulation
Article 30
Registers
Record of processing · Processing activity · Entity · Retention schedule
The record of processing activities, compiled from the activities in use.
The record of processing activities, compiled from the activities in use.

The steps

  1. 01Open the Record of processing view from the Processing section of the left menu.
  2. 02Read the inclusion rule stated at the head of the register: only activities In use are compiled.
  3. 03Check the outstanding gaps panel for any exclusion still awaiting a reason.
  4. 04Use the context band to switch to the controller or processor view as required.
  5. 05Use the export control to produce the register for the supervisory authority.
  6. 06Open the exported file and confirm the context it was read in is stated on the cover.
The outstanding gaps panel, listing exclusions still awaiting a reason.
The outstanding gaps panel, listing exclusions still awaiting a reason.

Accepted when

  • Only activities in use appear, and the reason for every exclusion is stated.
  • The export carries the context it was read in.