KlarComply
HomeKnowledge › Records of processing

Records of processing activities: who needs them, what goes in — and what might change

“Under 250 employees we are exempt” — this is the most widespread misconception about the records of processing activities. The exemption is in the law, but it almost never applies. At the same time, a proposal is on the table in Brussels that would change exactly that — and it is stuck in the Council. Both halves deserve to be told honestly.

By , Founder of KlarComply · Reviewed on

Infographic: Records of processing: who really needs them — The 250-employee exemption is in the law — and almost never applies.
The key points of this article as a graphic — feel free to share or download it.

Why the 250-employee exemption almost never applies

Art. 30(5) GDPR exempts organisations under 250 employees — unless the processing is “not occasional”. And that is where the exemption fails in practice: a customer database is maintained daily, the newsletter goes out regularly, payroll runs monthly. All of that is regular processing. In practice, almost every company needs the records from its first customer onwards — the exemption fits the club that compiles one participant list a year.

What goes in — less than many think

The records are a structured stocktake, not a legal opinion. Per processing activity (say “customer management”, “recruitment”, “newsletter”):

EntryExample
Purpose of the processingHandling customer orders
Categories of data subjects and dataCustomers; name, address, order data
RecipientsAccountant, shipping provider, cloud provider
Third-country transfersUS newsletter tool — see the third-country guide
Erasure periodsQuotation data 2 years, invoices 10 years
Description of security measures (Art. 32)Access concept, encryption, backups

The best source is a maintained tool inventory: whoever notes per tool whether it touches personal data, whether a DPA exists and whether data flows to third countries has half the records already — one survey, two sets of evidence.

Digital Omnibus: the 750-employee exemption is NOT adopted

The Commission proposal of 19 November 2025 (COM(2025) 837) would loosen the duty substantially: exemption for organisations under 750 employees, records only for processing likely to result in high risk. For most SMEs that would end the duty — but the data strand of the omnibus is stuck in the Council: the compromise text was withdrawn in June 2026 and a Council position is missing. As of 1 September 2026, Art. 30 applies unchanged. Skipping the records today because “it will be abolished anyway” confuses a proposal with a law.

The pragmatic route for SMEs

The records need to be neither pretty nor long — they need to be accurate and findable. A typical SME has eight to twelve processing activities on a few pages. Set up cleanly once, upkeep takes minutes per quarter: add new tools, remove retired ones, review erasure periods. On request the records are presented to the supervisory authority — and they are regularly the first thing it asks for.

Where to start

The free 2-minute check shows where you stand. In the subscription (from €49/month) your tool inventory carries the privacy entries per tool — the foundation from which records and audit file grow.

Frequently asked questions

Do companies under 250 employees need records of processing activities?

As a rule, yes. The Art. 30(5) exemption falls away as soon as processing is regular — and a customer database, newsletter or payroll is regular processing. The exemption practically only covers genuinely occasional processing.

Does the Digital Omnibus abolish the records for SMEs?

Proposed yes (exemption under 750 employees, duty only for high-risk processing), adopted no: the data strand has no Council position as of 1 September 2026. Until agreement and entry into force, Art. 30 applies unchanged.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Article 30 GDPR — records of processing activities
COM(2025) 837 — the Commission's Digital Omnibus proposal
Reviewed on 1 September 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.