GDPR Article 30: The Record-Keeping Obligation Explained
Article 30 is the single most frequently invoked provision in GDPR compliance. It is the obligation to keep a written record of processing activities — the register that says, in structured form, what personal data you process, why, whose it is, where it goes and how long you keep it. Almost every other compliance task, from answering a data subject access request to running a DPIA to responding to a breach, reads data off this record.
This is the framework page for the Article 30 obligation. It is where the concept is defined once, so the rest of the blog can link here instead of re-explaining the rule each time.
What Article 30 requires
Article 30 requires every controller and most processors to maintain a record of their processing activities, in writing or in electronic form, and to make it available to the supervisory authority on request.
The record is not optional. It is the demonstration mechanism for the accountability principle in Article 5(2): you must be able to show you are complying with the GDPR, and the record of processing activities is the document that does much of the showing.
Controller vs processor records
Controllers keep records under Article 30(1), with the full field list: the purposes of processing, the categories of data subjects and personal data, the recipients, details of any transfers to a third country or international organisation, retention periods, and a description of security measures.
Processors keep a narrower record under Article 30(2), organised per controller they serve, covering the categories of processing carried out for each controller and the transfers involved. A software vendor processing data for many clients keeps one processor record, populated per client.
The 250-employee exemption is narrower than it looks
Article 30(5) exempts organisations with fewer than 250 employees — but only where the processing is occasional, involves no special category or criminal offence data, and is unlikely to result in risk to the people concerned.
Payroll, a CRM, or customer orders are none of these. A twelve-person firm still needs records for anything regular, which in practice means most organisations keep the register regardless of headcount.
The register powers everything else
The Article 30 record is the foundation document. A RoPA is the register itself. When a DPIA needs a description of the processing, it extracts it from here. When a DSAR arrives, the register tells you which systems to search. The framework does not stop at the register — the record is the load-bearing wall the rest of the structure hangs on.
For the full legal breakdown, paragraph by paragraph, see our complete guide to GDPR Article 30.