Knowella

Personal Data Processing Record

A personal data processing record lists what the organisation holds, why, and for how long, one entry per activity. Its recurring failure is not omission of the obvious - payroll, recruitment - but omission of the categories nobody frames as personal data at all: CCTV footage, biometric access badges, occupational health files and telematics. These carry the strictest obligations and are consistently the ones marked absent, because whoever holds them never thought of them as processing.

KnowComplyRegisterCMP-03141 fields across 6 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 27701 cl.7.2
Workspace
KnowComply
Form type
Register
Review cycle
Yearly, plus whenever an entry is added, changed or retired
Owned by
The privacy lead

The short version

  • The register exists to satisfy the records-of-processing duty embedded in ISO/IEC 27701 cl.7.2, and the test is not length but whether every activity carries a purpose, a lawful basis, a retention period and a security measure - the four things a regulator or auditor checks first.
  • Special category, health, biometric and monitoring data are scored as separate yes/no checks precisely because they are the categories most often left off ordinary registers - not because they are rare, but because the functions that hold them rarely think of themselves as data processors.
  • The register holds 41 fields across 6 sections: header, completeness, for-each-activity, governance, related records and outcome. Retention periods here must agree with the retention schedule (CMP-024), not restate it independently.
  • Scoring is records complete, where high is good, and the score only means something if 'Partly' is used honestly - an activity with a lawful basis but no mapped recipients is Partly, not a rounded-up Yes.

What this is

What is a personal data processing record?

What is a personal data processing record?

A register, one entry per processing activity, recording what personal data is held, the purpose it is held for, the lawful basis relied on, how long it is kept, who it is shared with, and what security measures apply. It is the organisation's answer to 'what do you do with personal data', built to satisfy the records-of-processing duty that most privacy regimes impose in some form.

What counts as an activity for the purposes of one entry?

A distinct purpose for which personal data is processed - payroll, recruitment, CCTV monitoring, occupational health screening - not a system or a department. A single HR platform can support several activities each needing its own entry, because the lawful basis and retention period can differ between them even where the software is the same.

When is the register reviewed?

Yearly as a baseline, and whenever an activity is added, materially changed or retired - a new monitoring system, a new processor, a change in what is collected. The annual date catches drift; the change trigger is what actually keeps the register accurate, and it is the one most registers rely on least.

Scope

When is a personal data processing record required?

This register is the inventory step in a larger programme. Using it to do the work of a neighbouring template - assessing a new system, recording a breach, answering a request - produces an inventory entry with the wrong content and leaves the actual duty undischarged.

Use this template when

  • A new processing activity starts, or an existing one is added, changed or retired
  • The register is being set up for the first time, tied to a specific site
  • You are running the Data Protection and Information Security programme and this is its master inventory step
  • A new monitoring system, health screening or biometric access control goes live and needs an entry
  • A linked record needs this one to exist first: retention schedule alignment, a DPIA reference, a subject access response

Do not use it for

  • Data Protection Impact Assessment, which assesses a new system or monitoring activity before it is introduced, rather than logging an activity already running.
  • Data Breach Record, which records loss, exposure or unauthorised access to personal data, not what is ordinarily held.
  • Subject Access Request Record, which records answering an individual's request for the data held about them.
  • CCTV and Monitoring Review, which reviews whether an existing monitoring system remains justified, not whether it has been logged.
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 27701 cl.7.2 requirements does this satisfy?

ISO/IEC 27701 requires PIMS-specific controls for PII controllers under clause 7.2, and clause 7.2.8 specifically calls for records related to the processing of PII - the same functional obligation most jurisdictions separately mandate as a record or register of processing activities. The standard names what the record must contain, not the form it must take.

ClauseRequirementWhere it lands
ISO 27701 cl.7.2.8Records related to the processing of PII maintained and kept currentCompleteness
ISO 27701 cl.7.2.1Purpose of processing identified and documented for each activityFor each activity
ISO 27701 cl.7.2.2Lawful basis for processing identified and recordedFor each activity
ISO 27701 cl.7.4.7Retention period defined and PII not kept beyond what is necessary for the purposeFor each activity
ISO 27701 cl.7.5Recipients and cross-border transfers of PII identified and controlledFor each activity
ISO 27701 cl.7.2.6Contracts with PII processors define processing terms and obligationsGovernance

What it does not cover

  • Data Protection Impact Assessment, which sits upstream of this register and belongs where a new system or monitoring activity is being weighed before it goes live.
  • Data Breach Record, which handles what happens once data is lost, exposed or accessed without authorisation.
  • Subject Access Request Record, which handles an individual's request for the data held about them, not the inventory of what is generally held.
  • Records Retention Schedule (CMP-024), which sets the retention periods this register must agree with, rather than setting them itself.
  • The processor contracts and privacy notices themselves, which are legal documents held elsewhere - this register only confirms they exist.

Global

Personal Data Processing Record requirements by country

The duty to keep a record of processing exists in most comprehensive privacy regimes, though what triggers it and what it must contain differs by jurisdiction.

United States

State comprehensive privacy laws (CCPA/CPRA, Colorado, Virginia, Connecticut)

No federal records-of-processing duty; several states require a data inventory or disclosure of processing purposes, with data protection assessments for higher-risk activities.

A US-only organisation still needs a working register to answer state-law data subject and regulator requests, even without one named recording obligation forcing it.

United Kingdom

UK GDPR Art.30; Data Protection Act 2018

Record of processing activities mandatory for controllers with 250 or more employees, or any size where processing is not occasional, includes special category data, or risks individuals' rights.

Because this register explicitly tracks health, biometric and monitoring data, the size exemption does not apply - the record is mandatory regardless of headcount.

International

EU GDPR Art.30; ISO/IEC 27701 cl.7.2.8

An equivalent recording duty under EU GDPR, and the certifiable overlay under ISO 27701 for organisations seeking PIMS certification.

An auditor or regulator checks the register's content against the Article 30 list directly - purpose, categories, recipients, transfers, retention, security - not against how complete it appears.

How to complete it

How to complete a personal data processing record, step by step

The register can be filled in without anyone having gone looking for the data that is hardest to find. The judgement calls are about what counts as an activity and how far to chase down what is actually held.

Chase the categories nobody volunteers

Health, biometric and monitoring data are rarely declared by the function that holds them - occupational health keeps its own files, CCTV sits with facilities, access badges with security. Marking the Completeness fields Yes with confidence requires asking those functions directly, not waiting for them to raise it.

Map recipients to where the data actually goes, not to the org chart

Recipients Stated and Transfers Outside The Region Identified are only honest if they include the cloud processor hosting the HR system, not just the internal department that uses it. A processor based overseas creates a transfer even when nobody in the organisation crosses a border.

Reconcile retention against the schedule, don't just restate it

Retention Period Stated is satisfied by any answer; Retention Schedule Aligned tests whether that answer agrees with CMP-024. An activity can pass the first and fail the second, and that gap is where most retention exposure actually sits.

Let Partly mean partly

An activity with a lawful basis but no recipients mapped is Partly, not Yes rounded up. Resolving every field to Yes to close the register removes the signal that tells the privacy lead which activities still need work.

What auditors find

Most common personal data processing record findings

The register almost always exists. What an audit tests is whether it covers the activities that were never framed as personal data processing at all.

FindingClauseWhat fixes it
Purpose and lawful basis marked stated, but the text is generic - 'HR purposes' - rather than naming the specific activity.ISO 27701 cl.7.2.1Require the purpose field to name the activity precisely enough that a different lawful basis could apply to it than to a neighbouring one.
Health, biometric or monitoring data answered No for activities that plainly include them.ISO 27701 cl.7.2.8Cross-check the Completeness answers against the site's actual CCTV, access control and occupational health systems before accepting No.
Retention period stated on the register does not match the retention schedule.ISO 27701 cl.7.4.7Reconcile the two records at each review; treat a mismatch as an open finding, not a rounding difference.
International transfer not identified though the processor hosting the data is based overseas.ISO 27701 cl.7.5Map processor locations directly, not office locations - a transfer exists wherever the data is actually processed.
Processor Contracts In Place marked N/A for a relationship that is a genuine processor.ISO 27701 cl.7.2.6Confirm N/A applies only where no third party processes the data on the controller's behalf.
A new monitoring system went live without a corresponding entry being added to the register.ISO 27701 cl.7.2.8Route every new system, camera or access-control installation through the register as a mandatory step of go-live, not an optional one.

Case in point

Case in point: the register that was complete and missed a camera

A warehouse operator's processing register listed payroll, recruitment and access control as its three activities, each scored Yes across purpose, lawful basis and retention. An ANPR camera system covering the yard had gone live eight months earlier, installed by facilities to track trailer movements, and had never been logged because nobody involved considered it a personal data activity.

A subject access request from a former driver asking for footage of a specific date exposed the gap: the register said nothing about the camera system, retention for the footage had never been set, and the operator could not confirm how long it had actually been kept. The fix was not a better register template; it was routing every new monitoring installation through the register as a mandatory step rather than something facilities was expected to remember on its own.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

41fields
6 sections
Reference
CMP-031
Archetype
Register
Record ID
PDP-2026-000
Scoring
Records complete
Direction
High is good
Singleton
No
Basis
ISO 27701 cl.7.2
Links
Links Records retention, Health records
Tags
Privacy, Data
Sections
6
Fields
41
Follow up fields
3
Repeating sections
0
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

8 fields
Text

Register ID*

Generated on save

Auto sequence. Format PDP-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Date & Time

Last Reviewed*

Users

Privacy Lead*

Date & Time

Next Review Due*

Info

Health And Monitoring Data Carry The Strictest Rules

Occupational health records, biometric access and camera footage are the categories most likely to be held wrongly and least likely to be on the register.

Completeness

6 fields
Single Choice

All Processing Activities Listed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Special Category Data Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Health Data Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Biometric Data Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Monitoring Data Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Contractor And Visitor Data Included*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

For each activity

6 fields
Single Choice

Purpose Stated*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Lawful Basis Stated*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Retention Period Stated*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Recipients Stated*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Security Measures Stated*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Transfers Outside The Region Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Governance

6 fields
Single Choice

Privacy Notices Issued*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Worker Rights Explained*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Processor Contracts In Place*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Impact Assessments Where Required*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Breach Process Defined*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Retention Schedule Aligned*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Related records

1 field
Text

Retention Schedule ID

OptionalLinked

The retention schedule these periods must agree with.

Links to CMP-024 Schedule ID

Outcome

14 fields
Numeric Answer

Activities Registered*

Scored
Numeric Answer

Activities Without A Lawful Basis*

Scored
Single Choice

Register Complete*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Retention Schedule Aligned*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Feeds Management Review*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Date & Time

Next Review Due*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Privacy Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-031 · record IDs look like PDP-2026-000 · Links Records retention, Health records

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

Keeping the register current is the work, not filling it in once. It slips at the exact point a new system goes live and nobody remembers the register exists to be told.

KnowComply

Holds the processing register against the retention schedule and DPIA library, and flags an activity whose retention period has drifted from the schedule it should agree with.

KnowHealth

Surfaces occupational health and wellness data holdings that the register otherwise depends on someone remembering to declare.

KnowSafe

Flags new CCTV, access control or monitoring installations at go-live so they reach the register instead of arriving only when something goes wrong.

Ella
Ella

Watches for new systems and monitoring activity going live and prompts a register entry, rather than waiting for the annual review to catch what was missed.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Personal Data Processing Record definitions and key terms

Processing activity
A distinct purpose for which personal data is used, the unit the register is built around - not a system or a department, since one system can support several activities with different bases and retention periods.
Lawful basis
The legal ground relied on to process personal data - consent, contract, legal obligation, vital interests, public task or legitimate interests under most GDPR-derived regimes.
Special category data
Data revealing health, biometric identity, race, religion, sexual orientation or similar, which carries additional conditions for lawful processing beyond an ordinary basis.
Data controller and processor
The controller decides why and how data is processed; the processor acts on the controller's instructions. The register records both the controller's own activities and its relationships with processors.
Cross-border transfer
Personal data processed or stored outside the jurisdiction it was collected in, including by a processor hosted overseas - the trigger is where the data goes, not where the controller sits.

FAQ

Frequently asked questions about personal data processing record

What is a personal data processing record for?+

It is the organisation's inventory of what personal data it holds, why, on what basis and for how long - the record most privacy regimes expect to exist and to be produced on request, and the document a DPIA, breach response or subject access request all refer back to.

What counts as an 'activity' for one entry?+

A distinct purpose, not a system. Payroll and recruitment can run on the same HR platform but need separate entries, because their lawful basis and retention periods differ. A single entry covering 'HR systems' as a whole hides exactly the detail the register exists to surface.

Which data categories get missed most often?+

Health, biometric and monitoring data - occupational health files, CCTV footage, telematics, access badges. These sit with facilities, security or occupational health rather than HR, and are rarely brought to the privacy lead's attention unprompted.

How does this register relate to the retention schedule?+

The retention schedule (CMP-024) sets the periods; this register states what period applies to each activity and is checked against the schedule for agreement. A mismatch between the two is a finding in itself, not a formatting difference.

Who should be consulted before marking Completeness fields Yes?+

Facilities for CCTV and access control, occupational health for health data, IT or fleet for biometric and telematics systems. A privacy lead working from the register alone will consistently mark these No simply because nothing has crossed their desk.

Can the register be a spreadsheet instead?+

It can be, but a spreadsheet has no link to the retention schedule, no trigger when a new system goes live, and no evidence trail when a regulator asks how current it is. The content required is the same either way; what the register format buys is the connections.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO/IEC 27701:2019 clauses 7.2 and 7.4.7
  • UK GDPR Article 30; Data Protection Act 2018
  • ICO guidance on records of processing activities
  • EU GDPR Article 30

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.