“Under 250 employees we are exempt” — this is the most widespread misconception about the records of processing activities. The exemption is in the law, but it almost never applies. At the same time, a proposal is on the table in Brussels that would change exactly that — and it is stuck in the Council. Both halves deserve to be told honestly.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
Art. 30(5) GDPR exempts organisations under 250 employees — unless the processing is “not occasional”. And that is where the exemption fails in practice: a customer database is maintained daily, the newsletter goes out regularly, payroll runs monthly. All of that is regular processing. In practice, almost every company needs the records from its first customer onwards — the exemption fits the club that compiles one participant list a year.
The records are a structured stocktake, not a legal opinion. Per processing activity (say “customer management”, “recruitment”, “newsletter”):
| Entry | Example |
|---|---|
| Purpose of the processing | Handling customer orders |
| Categories of data subjects and data | Customers; name, address, order data |
| Recipients | Accountant, shipping provider, cloud provider |
| Third-country transfers | US newsletter tool — see the third-country guide |
| Erasure periods | Quotation data 2 years, invoices 10 years |
| Description of security measures (Art. 32) | Access concept, encryption, backups |
The best source is a maintained tool inventory: whoever notes per tool whether it touches personal data, whether a DPA exists and whether data flows to third countries has half the records already — one survey, two sets of evidence.
The Commission proposal of 19 November 2025 (COM(2025) 837) would loosen the duty substantially: exemption for organisations under 750 employees, records only for processing likely to result in high risk. For most SMEs that would end the duty — but the data strand of the omnibus is stuck in the Council: the compromise text was withdrawn in June 2026 and a Council position is missing. As of 1 September 2026, Art. 30 applies unchanged. Skipping the records today because “it will be abolished anyway” confuses a proposal with a law.
The records need to be neither pretty nor long — they need to be accurate and findable. A typical SME has eight to twelve processing activities on a few pages. Set up cleanly once, upkeep takes minutes per quarter: add new tools, remove retired ones, review erasure periods. On request the records are presented to the supervisory authority — and they are regularly the first thing it asks for.
The free 2-minute check shows where you stand. In the subscription (from €49/month) your tool inventory carries the privacy entries per tool — the foundation from which records and audit file grow.
As a rule, yes. The Art. 30(5) exemption falls away as soon as processing is regular — and a customer database, newsletter or payroll is regular processing. The exemption practically only covers genuinely occasional processing.
Proposed yes (exemption under 750 employees, duty only for high-risk processing), adopted no: the data strand has no Council position as of 1 September 2026. Until agreement and entry into force, Art. 30 applies unchanged.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free