Skip to content
Clarium
Back to blog
Article 30GDPRRoPArecord of processing activitiescomplianceframework

GDPR Article 30: The Record-Keeping Obligation Explained

18 August 2026Will Wilson

Article 30 is the single most frequently invoked provision in GDPR compliance. It is the obligation to keep a written record of processing activities — the register that says, in structured form, what personal data you process, why, whose it is, where it goes and how long you keep it. Almost every other compliance task, from answering a data subject access request to running a DPIA to responding to a breach, reads data off this record.

This is the framework page for the Article 30 obligation. It is where the concept is defined once, so the rest of the blog can link here instead of re-explaining the rule each time.

What Article 30 requires

Article 30 requires every controller and most processors to maintain a record of their processing activities, in writing or in electronic form, and to make it available to the supervisory authority on request.

The record is not optional. It is the demonstration mechanism for the accountability principle in Article 5(2): you must be able to show you are complying with the GDPR, and the record of processing activities is the document that does much of the showing.

Controller vs processor records

Controllers keep records under Article 30(1), with the full field list: the purposes of processing, the categories of data subjects and personal data, the recipients, details of any transfers to a third country or international organisation, retention periods, and a description of security measures.

Processors keep a narrower record under Article 30(2), organised per controller they serve, covering the categories of processing carried out for each controller and the transfers involved. A software vendor processing data for many clients keeps one processor record, populated per client.

The 250-employee exemption is narrower than it looks

Article 30(5) exempts organisations with fewer than 250 employees — but only where the processing is occasional, involves no special category or criminal offence data, and is unlikely to result in risk to the people concerned.

Payroll, a CRM, or customer orders are none of these. A twelve-person firm still needs records for anything regular, which in practice means most organisations keep the register regardless of headcount.

The register powers everything else

The Article 30 record is the foundation document. A RoPA is the register itself. When a DPIA needs a description of the processing, it extracts it from here. When a DSAR arrives, the register tells you which systems to search. The framework does not stop at the register — the record is the load-bearing wall the rest of the structure hangs on.

For the full legal breakdown, paragraph by paragraph, see our complete guide to GDPR Article 30.

Ready to simplify your GDPR compliance?

Try Clarium free — no credit card required.

Start Free Trial