A record of processing activities describes how personal information is used across an organisation. It supports accountability and makes requests, supplier reviews and policy updates easier. Assess the applicable documentation duty rather than assuming every small organisation is exempt because of its headcount.
Build the record around actual activities, such as recruitment, order fulfilment and marketing. Link each activity to its owner, systems, people, information categories, recipients and retention approach. Include transfer and security information where required, and keep the record aligned with operational changes.
Start with activities rather than product names
A software inventory tells you where information may be held, but not why the organisation uses it. Begin with recognisable activities such as handling enquiries, delivering orders, managing employees and collecting debts. Trace each activity across its systems, email and informal working files. One platform may support several purposes, and one purpose may involve several suppliers; the processing record should make those relationships understandable.
Interview the people who perform the work. Ask what information arrives, what they add, who receives it and when they stop needing it. Include paper records and exports used outside the main system. A record copied entirely from policy templates can omit the spreadsheet that staff actually rely on every day. Mark uncertain answers for follow-up instead of turning an assumption into an apparently verified entry.
Check the documentation duty and useful fields
The ICO explains the limited exemption for organisations with fewer than 250 staff. Regular processing, risky processing and sensitive categories can still require documentation. [1] Do not treat headcount as a universal exemption. Controllers and processors have different documentation requirements, so identify the organisation's role for each activity, particularly where a business provides outsourced services as well as managing its own customers.
Use the applicable required fields, then add practical references that make the record useful: responsible owner, system links, relevant notice, contract and assessment location. Keep these references separate from the underlying personal information. The processing record should describe categories and arrangements, not become another large customer database. Avoid including real case details merely to illustrate the category being documented.
Make entries specific enough to guide action
For retention, state the category and trigger or link to the controlled schedule rather than entering indefinitely in every row. For security, describe the relevant type of control without publishing sensitive access credentials. For recipients and transfers, identify the actual relationship and point to the current assessment. Empty fields labelled not applicable need a reason if the workflow plainly involves external providers.
Use Creating a personal data retention schedule when refining retention entries and International transfers of personal data for international transfer references. These documents should inform one another without requiring duplicated prose in every file. If the retention schedule changes, the processing record should lead the reader to the current version. A collection of disconnected spreadsheets with conflicting periods creates uncertainty during an access request or supplier review.
Establish a manageable update process
Assign ownership by activity rather than expecting one administrator to know every operational change. Add a short privacy check to the introduction of a new form, supplier or data use. The owner should confirm whether the activity is new, whether an existing entry changes and which linked documents need review. Keep a dated change history that explains material updates without burying current information under obsolete entries.
Review a sample activity from start to finish. Can staff find the right notice, identify the supplier contact and explain where an old record is deleted? If not, improve the links or underlying process. This practical check is more useful than measuring only whether every column is filled. It also exposes situations where different departments use the same information for purposes that were never assessed together.
Bring the draft register, system list and uncertain entries to Business privacy notice review. Ask for help with scope, role classification and gaps affecting legal decisions. The resulting action list should identify who must verify each missing fact. A completed document is valuable when it supports ordinary decisions about data use; it should not depend on the original author being available to interpret every abbreviation.
Use the register to answer an operational question
Choose a practical question such as which suppliers hold identification documents from former clients. Try answering it from the register without relying on the memory of the person who created it. If the entry says only customer administration, add the categories, systems and relevant recipient information needed to locate the records.
Keep links to detailed supporting assessments rather than copying every contract into the register. The register should help an incident handler or project owner find the right evidence quickly. After an acquisition, department closure or new integration, check the affected entries against reality and record who confirmed the update. This makes the record useful beyond a single compliance review.
Illustrative scenario
A business starts with a software inventory but discovers that staff also maintain client records in email and spreadsheets. Its processing record follows the activity across those tools. When a supplier changes, the owner updates the relevant activity and checks the associated notice, contract and retention entries.
Preparation checklist
- List activities rather than only software products.
- Identify owners, people and information categories.
- Record recipients, retention and relevant transfer details.
- Set review triggers for new purposes and suppliers.
Frequently asked questions
Do businesses with fewer than 250 staff need records?
The exemption is limited. Regular activities and certain risky or sensitive processing can still need documentation. Assess the applicable ICO criteria instead of relying on headcount alone.
Should the record contain actual customer details?
Usually it describes categories, purposes and arrangements. Avoid turning it into another unnecessary copy of personal records; link to controlled process documents where appropriate.
Is a list of our software sufficient?
No. Record the processing activities and their purposes across systems. A product name alone does not explain the people affected, recipients, retention or responsibility for decisions.
Who should maintain the register?
Assign activity owners with central coordination. Build updates into changes of purpose, supplier and collection method so the record reflects actual operations rather than an annual reconstruction.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction