Record of processing activities
The written record controllers and processors must keep of their processing, including purposes, categories of data, recipients and transfers (GDPR Article 30).
Controllers record, among other things, the purposes, the categories of data subjects and personal data, the recipients, transfers to third countries, retention periods and security measures; processors keep a shorter record of the processing they carry out for each controller. The record must be made available to the supervisory authority on request. Organisations with fewer than 250 employees are exempt in some cases (Article 30(5)).
Source: GDPR Art. 30 ↗
Related terms
ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.