EU GDPR Article 30(1), (3), (4) and (5) — Records of processing activities
Maintain a written record of processing activities covering purposes, data subjects, data categories, recipients, transfers, retention and security measures
Where this comes from
Provision: Article 30(1), (3), (4) and (5) — Records of processing activities
Instrument: EU General Data Protection Regulation (Regulation (EU) 2016/679)
Citation: Article 30, Regulation (EU) 2016/679
Text version: Regulation (EU) 2016/679 (GDPR), OJ L 119, 4.5.2016, p. 1 (CELEX 32016R0679)
Checked against the source: 6 September 2026
Who it applies to
Personal data is processed (GDPR Art. 2(1)) — all of these:
- Service processes personal data
…unless:
- Employees is fewer than 250
- Processing of personal data is occasional
- GDPR Article 30 risk: NO
- GDPR Article 9 data: NO
- GDPR Article 10 data: NO
- DPIA screening criteria includes None of these criteria apply
- Data categories collected does not include Special category data
- Art. 2(2)(c): the Regulation does not apply to processing of personal data 'by a natural person in the course of a purely personal or household activity'. Recital 18 keeps controllers or processors providing the means for such processing in scope. (GDPR Art. 2(2)(c))
- Art. 30(5): the Art. 30(1)-(2) obligations 'shall not apply to an enterprise or an organisation employing fewer than 250 persons UNLESS the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing... (GDPR Art. 30(5))
Scope in the source's own terms
- Art. 3(1)/(2): the processing is carried out in the context of the activities of an establishment in the Union, or relates to offering goods or services to, or monitoring the behaviour of, data subjects in the Union
- Art. 2(1) read with Art. 4(1): the activity is the processing of personal data — any information relating to an identified or identifiable natural person
- Art. 4(7): the duty binds the 'controller' — the person which, alone or jointly with others, determines the purposes and means of the processing (a processor's parallel duties sit in Art. 28/30(2))
What engineering work it implies
- AI Decision Logging (Append-Only Decision Record)Foundation only
Append-only, tamper-evident log of every AI-assisted decision: model and version, hashed inputs, output, confidence, human-override flag, and an enforced retention floor.
Sample acceptance criteria Landfall generates for this obligation:
- Every entry carries an owner and a last-reviewed date with the reviewer named
- Changes to an entry are versioned and attributable, so the record in force on any past date is recoverable
- Adding a processing activity to the system creates or updates its record, rather than relying on a periodic sweep
- The record is exportable in full for a supervisory-authority request
- Test: an entry missing a retention limit, a recipient category or a security description fails validation
Evidence an auditor expects
- Process recordDocument reviewReviewed reviewed on each new or materially changed processing activity, and at least annually
Record of processing activities extract containing the Art. 30(1)(a)-(g) items
A written (including electronic) record containing, for each processing activity: (a) the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the DPO; (b) the purposes of the processing; (c) the categories of data subjects and of personal data; (d) the categories of recipients including recipients in third countries or international organisations; (e) where applicable, third-country transfers with the identification of the country or organisation and, for Art. 49(1) second subparagraph transfers, the documentation of suitable safeguards; (f) where possible, the envisaged erasure time limits; and (g) where possible, a general description of the Art. 32(1) technical and organisational security measures
- Process recordDocument review
Evidence the record can be made available to the supervisory authority on request (Art. 30(4))
A maintained, current export of the record and the named owner responsible for producing it on request — Art. 30(4) makes availability to the supervisory authority the operative test
Questions people ask
- Does EU GDPR Article 30(1), (3), (4) and (5) — Records of processing activities apply to my service?
- It applies when Service processes personal data. It does not apply where Employees is fewer than 250.
- When does this become enforceable?
- EU GDPR Article 30(1), (3), (4) and (5) — Records of processing activities is enforceable from 25 May 2018. Its current status is: in force.
- What evidence does an auditor expect?
- Record of processing activities extract containing the Art. 30(1)(a)-(g) items; Evidence the record can be made available to the supervisory authority on request (Art. 30(4)).
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.