GDPR - Records of Processing Activities (also: Data Inventory, Data Mapping): Information, Examples, Templates, Free Excel

The recods of processing activities is a documentation requirement of the EU General Data Protection Regulation (GDPR). Under Art. 30 GDPR, companies must draw up a list of all activities in which they process personal data (processing activities).

For the list of processing activities, the terms “Data Inventory” and “Data Mapping” are also used somewhat imprecisely.

Jul

15

Post by
Dr. Thomas Helbing
Comment:0

Not interested in lengthy and expensive GDPR audits? Think about the following five questions to easily get a first idea of an organization’s level of GDPR compliance:

  1. What data protection awareness measures have been taken in the last 12 months...

Jul

09

Post by
Dr. Thomas Helbing
Comment:0

A Data Protection Policy (or SOP) is a work instruction that sets out responsibilities and processes to ensure compliance with the GDPR in your company. It covers much more than just data security. In my opinion, a Data Protection Policy is the most important and often neglected data protection instrument in medium and large-sized companies.

May

24

Post by
Dr. Thomas Helbing
Comment:0

Overview of data protection law (GDPR) requirements for websites, apps and online platforms in Germany.

Mar

13

Post by
Dr. Thomas Helbing
Comment:0

The Data Protection Authority for the German federal state of Schleswig-Holstein ("Unabhängiges Landeszentrum für Datenschutz - ULD", the "DPA") has published in June 2010 a paper about cloud computing under German data protection law. The most doubtful statement is that the usage of clouds outside the EU might be in violation of German data protection law.

In this analysis I give an overview over some statements of the paper, explain the legal background and analyze the DPA's position.

Mar

26

Post by
Dr. Thomas Helbing
Comment:0

On 5 February 2010 the Commission of the European Union (EU) has updated the set of standard contractual clauses for the transfer of personal data to processors in non-EU countries. The old clauses are repealed with effect from 15 May 2010.

Feb

02

Post by
Dr. Thomas Helbing
Comment:0

The amended German data protection law obliges parties to data processing agreements to include into their contracts clauses on breach notifications, audit rights, subcontractingand a couple of other aspects. Nonconforming contracts can trigger administrative fines of up to € 50,000. Agreements already in place should be reviewed and policies implemented to ensure the compliance of future contracts.