Short Reads

Countdown 4 weeks until GDPR : Will data controllers be required to maintain records of processing activities in all cases?

Stibbe - Will data controllers be required to maintain records

Countdown 4 weeks until GDPR : Will data controllers be required to maintain records of processing activities in all cases?

26.04.2018 EU law

Only 4 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

Will data controllers be required to maintain ​r​ecords of ​processing activities in all cases?

The GDPR requires each controller to keep a record of processing activities under its responsibility, and each processor to keep a record of the processing activities that it has carried out on behalf of a controller​​. However, these obligations do not apply if the controller or the processor is an enterprise or an organization employing fewer than 250 persons, unless the processing it carries out:

- is likely to result in a risk to the rights and freedoms of data subjects and is not occasional, or

- includes sensitive​ data, i.e., personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation (Article 9​ of the GDPR), ​or data relating to criminal convictions and offences (Article 10​ of the GDPR).

​The rationale for these exceptions is that ​small and medium-sized enterprises and organizations that do not carry out risky processing should be exempt from the requirement to keep a record of its processing activities.

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

19.08.2019 EU law
Enable “likes” and bear joint-controllership

Articles - The Court of Justice of the European Union recently ruled, in Case C-40/14 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV,  that a website operator that features “Like” social-media plugin from Facebook likely qualifies as joint-controller with Facebook for its website visitors’ personal data collection and transmission to Facebook.

Read more

08.08.2019 BE law
Regulating online platforms: piece of the puzzle

Articles - The new Regulation no. 2019/1150 of the European Parliament and of the Council of 20 June 2019 on promoting fairness and transparency for business users of online intermediation services, applicable as of 12 July 2020, is another piece of the puzzle regulating online platforms, this time focussing on the supply side of the platforms.

Read more

23.07.2019 LU law
The Revised CSSF Cloud Circular

Articles - On 27 March 2019, the Luxembourg supervisory authority for the financial sector (the Commission de surveillance du secteur financier or CSSF) published the long-awaited CSSF Circular 19/714 amending the CSSF Circular 17/654 on IT outsourcing relying on a cloud computing infrastructure (the Revised Cloud Circular).

Read more

Our website uses functional cookies for the functioning of the website and analytic cookies that enable us to generate aggregated visitor data. We also use other cookies, such as third party tracking cookies - please indicate whether you agree to the use of these other cookies:

Privacy – en cookieverklaring