The record of processing activities: what it is and how to build it in an afternoon

The record of processing activities: what it is and how to build it in an afternoon

It is the document data protection authorities ask for first and the one almost no small business has. What it must contain, who is obliged and how to do it without buying anything.

· AI and data compliance

There is one document that a data protection inspection asks for before any other, and that most small businesses do not have: the record of processing activities.

It is not a filing you submit anywhere. It is an internal inventory you have to hold and be able to show. And the good news is that it takes an afternoon and costs nothing.

Who is obliged

In Spain, the GDPR requires it of controllers and processors. There is an exception for organisations with fewer than 250 employees, but it falls away as soon as any of these three things happens: that the processing may pose a risk to the rights and freedoms of data subjects, that it is not occasional, or that it includes special categories of data.

The practical consequence: almost no business escapes. Running payroll is non-occasional processing. Keeping a customer base is too.

In Chile, Ley 21.719 also brings in the duty to maintain a record of processing activities, within the accountability principle. Its enforceability is tied to the law's entry-into-force calendar and to the supervisory authority being stood up, so the specific position is checked at the official source. The sensible move for a business operating in both countries is to keep a single record that serves both.

What it has to contain

For each processing activity:

  1. Name and contact details of the controller, and of the data protection officer where there is one.
  2. Purposes of the processing: what you use that data for.
  3. Categories of data subjects (customers, workers, suppliers, applicants) and categories of data (identifying, financial, health…).
  4. Recipients the data is disclosed to, including those in other countries.
  5. International transfers, where there are any, with their safeguard.
  6. Erasure deadlines envisaged for each category.
  7. General description of the technical and organisational security measures.

The activities every business has

Here is the short cut: nearly every small business has the same six or seven. Start from this list and add your own.

  • Customer management: contracting, invoicing, support.
  • People management: contracts, payroll, social security, health and safety.
  • Recruitment: CVs received. Watch the retention period — keeping applications indefinitely is one of the most frequent breaches.
  • Supplier management.
  • Video surveillance, if there are cameras.
  • Marketing communications, if you send newsletters or promotions.
  • Website contacts: forms, incoming email.

How to do it in an afternoon

  1. List where personal data lives. Walk mentally through the day: email, invoicing system, shared folder, payroll software, online shop, WhatsApp, cameras. Everything holding people's names.
  2. Group by purpose, not by tool. The purpose «customer management» can live in four different places; in the record it is a single activity.
  3. Fill in the seven columns above for each one. A spreadsheet does the job perfectly.
  4. Note the legal basis for each processing: contract, legal obligation, consent or legitimate interest. It is the box most often left blank and the first one anybody looks at.
  5. Date and owner of the document, and an annual review in the calendar.

What you discover along the way

And this is the real reason to do it, beyond compliance. Filling it in always turns up the same things:

  • Data kept with no defined retention period at all, for years.
  • Third-party tools processing your customers' data with no processor agreement signed.
  • Applicant CVs from five years ago.
  • Copies of identity documents kept «just in case», with no legal basis.
  • People on the team with access to data they no longer need for their job.

Each of those findings is a risk that closes with a five-minute decision. The record is not the goal: it is the exercise that brings them to light.

What goes with it and is worth doing at once

While you are in the inventory, close these three at the same time:

  • Information notices on forms and contracts, consistent with what the record says.
  • Processor agreements with anybody handling data on your behalf: your adviser, your IT provider, your email supplier, your invoicing tool.
  • A breach procedure: who gets told and within what deadline. Both the GDPR and the Chilean rules work with 72-hour deadlines for notifying the authority in the cases provided for, and that deadline is not improvised on the day of the incident.

If this sounds like you

The record, the information notices and the processor agreements are AI and data compliance. If you also use AI with customer data, the specific part is in using AI with customer data within the law and in the AI use policy.

And the technical side that holds all of this up — accesses, backups, incident response — is in the security minimum.

We are Mindset & Code: automation, data and development for small businesses. You can see what we do and what it costs.

Sources: Regulation (EU) 2016/679, arts. 30 (records of processing activities) and 33 (breach notification); AEPD, guidance and templates for controllers; Ley 21.719 on personal data protection in Chile. The specific enforceability in Chile depends on the entry-into-force calendar and is checked at the official source. General guidance; it does not replace legal advice.