What this is
What is a personal data processing record?
What is a personal data processing record?
A register, one entry per processing activity, recording what personal data is held, the purpose it is held for, the lawful basis relied on, how long it is kept, who it is shared with, and what security measures apply. It is the organisation's answer to 'what do you do with personal data', built to satisfy the records-of-processing duty that most privacy regimes impose in some form.
What counts as an activity for the purposes of one entry?
A distinct purpose for which personal data is processed - payroll, recruitment, CCTV monitoring, occupational health screening - not a system or a department. A single HR platform can support several activities each needing its own entry, because the lawful basis and retention period can differ between them even where the software is the same.
When is the register reviewed?
Yearly as a baseline, and whenever an activity is added, materially changed or retired - a new monitoring system, a new processor, a change in what is collected. The annual date catches drift; the change trigger is what actually keeps the register accurate, and it is the one most registers rely on least.
Scope
When is a personal data processing record required?
This register is the inventory step in a larger programme. Using it to do the work of a neighbouring template - assessing a new system, recording a breach, answering a request - produces an inventory entry with the wrong content and leaves the actual duty undischarged.
Use this template when
- A new processing activity starts, or an existing one is added, changed or retired
- The register is being set up for the first time, tied to a specific site
- You are running the Data Protection and Information Security programme and this is its master inventory step
- A new monitoring system, health screening or biometric access control goes live and needs an entry
- A linked record needs this one to exist first: retention schedule alignment, a DPIA reference, a subject access response
Do not use it for
- Data Protection Impact Assessment, which assesses a new system or monitoring activity before it is introduced, rather than logging an activity already running.
- Data Breach Record, which records loss, exposure or unauthorised access to personal data, not what is ordinarily held.
- Subject Access Request Record, which records answering an individual's request for the data held about them.
- CCTV and Monitoring Review, which reviews whether an existing monitoring system remains justified, not whether it has been logged.
- Anything outside KnowComply, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 27701 cl.7.2 requirements does this satisfy?
ISO/IEC 27701 requires PIMS-specific controls for PII controllers under clause 7.2, and clause 7.2.8 specifically calls for records related to the processing of PII - the same functional obligation most jurisdictions separately mandate as a record or register of processing activities. The standard names what the record must contain, not the form it must take.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 27701 cl.7.2.8 | Records related to the processing of PII maintained and kept current | Completeness |
| ISO 27701 cl.7.2.1 | Purpose of processing identified and documented for each activity | For each activity |
| ISO 27701 cl.7.2.2 | Lawful basis for processing identified and recorded | For each activity |
| ISO 27701 cl.7.4.7 | Retention period defined and PII not kept beyond what is necessary for the purpose | For each activity |
| ISO 27701 cl.7.5 | Recipients and cross-border transfers of PII identified and controlled | For each activity |
| ISO 27701 cl.7.2.6 | Contracts with PII processors define processing terms and obligations | Governance |
What it does not cover
- Data Protection Impact Assessment, which sits upstream of this register and belongs where a new system or monitoring activity is being weighed before it goes live.
- Data Breach Record, which handles what happens once data is lost, exposed or accessed without authorisation.
- Subject Access Request Record, which handles an individual's request for the data held about them, not the inventory of what is generally held.
- Records Retention Schedule (CMP-024), which sets the retention periods this register must agree with, rather than setting them itself.
- The processor contracts and privacy notices themselves, which are legal documents held elsewhere - this register only confirms they exist.
Global
Personal Data Processing Record requirements by country
The duty to keep a record of processing exists in most comprehensive privacy regimes, though what triggers it and what it must contain differs by jurisdiction.
State comprehensive privacy laws (CCPA/CPRA, Colorado, Virginia, Connecticut)
No federal records-of-processing duty; several states require a data inventory or disclosure of processing purposes, with data protection assessments for higher-risk activities.
A US-only organisation still needs a working register to answer state-law data subject and regulator requests, even without one named recording obligation forcing it.
UK GDPR Art.30; Data Protection Act 2018
Record of processing activities mandatory for controllers with 250 or more employees, or any size where processing is not occasional, includes special category data, or risks individuals' rights.
Because this register explicitly tracks health, biometric and monitoring data, the size exemption does not apply - the record is mandatory regardless of headcount.
EU GDPR Art.30; ISO/IEC 27701 cl.7.2.8
An equivalent recording duty under EU GDPR, and the certifiable overlay under ISO 27701 for organisations seeking PIMS certification.
An auditor or regulator checks the register's content against the Article 30 list directly - purpose, categories, recipients, transfers, retention, security - not against how complete it appears.
How to complete it
How to complete a personal data processing record, step by step
The register can be filled in without anyone having gone looking for the data that is hardest to find. The judgement calls are about what counts as an activity and how far to chase down what is actually held.
Health, biometric and monitoring data are rarely declared by the function that holds them - occupational health keeps its own files, CCTV sits with facilities, access badges with security. Marking the Completeness fields Yes with confidence requires asking those functions directly, not waiting for them to raise it.
Recipients Stated and Transfers Outside The Region Identified are only honest if they include the cloud processor hosting the HR system, not just the internal department that uses it. A processor based overseas creates a transfer even when nobody in the organisation crosses a border.
Retention Period Stated is satisfied by any answer; Retention Schedule Aligned tests whether that answer agrees with CMP-024. An activity can pass the first and fail the second, and that gap is where most retention exposure actually sits.
An activity with a lawful basis but no recipients mapped is Partly, not Yes rounded up. Resolving every field to Yes to close the register removes the signal that tells the privacy lead which activities still need work.
What auditors find
Most common personal data processing record findings
The register almost always exists. What an audit tests is whether it covers the activities that were never framed as personal data processing at all.
| Finding | Clause | What fixes it |
|---|---|---|
| Purpose and lawful basis marked stated, but the text is generic - 'HR purposes' - rather than naming the specific activity. | ISO 27701 cl.7.2.1 | Require the purpose field to name the activity precisely enough that a different lawful basis could apply to it than to a neighbouring one. |
| Health, biometric or monitoring data answered No for activities that plainly include them. | ISO 27701 cl.7.2.8 | Cross-check the Completeness answers against the site's actual CCTV, access control and occupational health systems before accepting No. |
| Retention period stated on the register does not match the retention schedule. | ISO 27701 cl.7.4.7 | Reconcile the two records at each review; treat a mismatch as an open finding, not a rounding difference. |
| International transfer not identified though the processor hosting the data is based overseas. | ISO 27701 cl.7.5 | Map processor locations directly, not office locations - a transfer exists wherever the data is actually processed. |
| Processor Contracts In Place marked N/A for a relationship that is a genuine processor. | ISO 27701 cl.7.2.6 | Confirm N/A applies only where no third party processes the data on the controller's behalf. |
| A new monitoring system went live without a corresponding entry being added to the register. | ISO 27701 cl.7.2.8 | Route every new system, camera or access-control installation through the register as a mandatory step of go-live, not an optional one. |
Case in point
Case in point: the register that was complete and missed a camera
A warehouse operator's processing register listed payroll, recruitment and access control as its three activities, each scored Yes across purpose, lawful basis and retention. An ANPR camera system covering the yard had gone live eight months earlier, installed by facilities to track trailer movements, and had never been logged because nobody involved considered it a personal data activity.
A subject access request from a former driver asking for footage of a specific date exposed the gap: the register said nothing about the camera system, retention for the footage had never been set, and the operator could not confirm how long it had actually been kept. The fix was not a better register template; it was routing every new monitoring installation through the register as a mandatory step rather than something facilities was expected to remember on its own.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
6 sections
- Reference
- CMP-031
- Archetype
- Register
- Record ID
- PDP-2026-000
- Scoring
- Records complete
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 27701 cl.7.2
- Links
- Links Records retention, Health records
- Tags
- Privacy, Data
- Sections
- 6
- Fields
- 41
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 3
Header
8 fieldsRegister ID*
Auto sequence. Format PDP-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Last Reviewed*
Privacy Lead*
Next Review Due*
Health And Monitoring Data Carry The Strictest Rules
Occupational health records, biometric access and camera footage are the categories most likely to be held wrongly and least likely to be on the register.
Completeness
6 fieldsAll Processing Activities Listed*
- Yes3 pts
- Partly1 pt
- No0 pts
Special Category Data Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Health Data Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Biometric Data Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Monitoring Data Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Contractor And Visitor Data Included*
- Yes3 pts
- Partly1 pt
- No0 pts
For each activity
6 fieldsPurpose Stated*
- Yes3 pts
- Partly1 pt
- No0 pts
Lawful Basis Stated*
- Yes3 pts
- Partly1 pt
- No0 pts
Retention Period Stated*
- Yes3 pts
- Partly1 pt
- No0 pts
Recipients Stated*
- Yes3 pts
- Partly1 pt
- No0 pts
Security Measures Stated*
- Yes3 pts
- Partly1 pt
- No0 pts
Transfers Outside The Region Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Governance
6 fieldsPrivacy Notices Issued*
- Yes3 pts
- Partly1 pt
- No0 pts
Worker Rights Explained*
- Yes3 pts
- Partly1 pt
- No0 pts
Processor Contracts In Place*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Impact Assessments Where Required*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Breach Process Defined*
- Yes3 pts
- Partly1 pt
- No0 pts
Retention Schedule Aligned*
- Yes3 pts
- Partly1 pt
- No0 pts
Related records
1 fieldRetention Schedule ID
The retention schedule these periods must agree with.
Links to CMP-024 Schedule ID
Outcome
14 fieldsActivities Registered*
Activities Without A Lawful Basis*
Register Complete*
- Yes3 pts
- Partly1 pt
- No0 pts
Retention Schedule Aligned*
- Yes3 pts
- Partly1 pt
- No0 pts
Feeds Management Review*
- Yes3 pts
- Partly1 pt
- No0 pts
Next Review Due*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Privacy Lead*
Signature*
Site Manager*
Second Signature*
CMP-031 · record IDs look like PDP-2026-000 · Links Records retention, Health records
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
Keeping the register current is the work, not filling it in once. It slips at the exact point a new system goes live and nobody remembers the register exists to be told.
Holds the processing register against the retention schedule and DPIA library, and flags an activity whose retention period has drifted from the schedule it should agree with.
Surfaces occupational health and wellness data holdings that the register otherwise depends on someone remembering to declare.
Flags new CCTV, access control or monitoring installations at go-live so they reach the register instead of arriving only when something goes wrong.

Watches for new systems and monitoring activity going live and prompts a register entry, rather than waiting for the annual review to catch what was missed.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Personal Data Processing Record definitions and key terms
- Processing activity
- A distinct purpose for which personal data is used, the unit the register is built around - not a system or a department, since one system can support several activities with different bases and retention periods.
- Lawful basis
- The legal ground relied on to process personal data - consent, contract, legal obligation, vital interests, public task or legitimate interests under most GDPR-derived regimes.
- Special category data
- Data revealing health, biometric identity, race, religion, sexual orientation or similar, which carries additional conditions for lawful processing beyond an ordinary basis.
- Data controller and processor
- The controller decides why and how data is processed; the processor acts on the controller's instructions. The register records both the controller's own activities and its relationships with processors.
- Cross-border transfer
- Personal data processed or stored outside the jurisdiction it was collected in, including by a processor hosted overseas - the trigger is where the data goes, not where the controller sits.
FAQ
Frequently asked questions about personal data processing record
What is a personal data processing record for?+
It is the organisation's inventory of what personal data it holds, why, on what basis and for how long - the record most privacy regimes expect to exist and to be produced on request, and the document a DPIA, breach response or subject access request all refer back to.
What counts as an 'activity' for one entry?+
A distinct purpose, not a system. Payroll and recruitment can run on the same HR platform but need separate entries, because their lawful basis and retention periods differ. A single entry covering 'HR systems' as a whole hides exactly the detail the register exists to surface.
Which data categories get missed most often?+
Health, biometric and monitoring data - occupational health files, CCTV footage, telematics, access badges. These sit with facilities, security or occupational health rather than HR, and are rarely brought to the privacy lead's attention unprompted.
How does this register relate to the retention schedule?+
The retention schedule (CMP-024) sets the periods; this register states what period applies to each activity and is checked against the schedule for agreement. A mismatch between the two is a finding in itself, not a formatting difference.
Who should be consulted before marking Completeness fields Yes?+
Facilities for CCTV and access control, occupational health for health data, IT or fleet for biometric and telematics systems. A privacy lead working from the register alone will consistently mark these No simply because nothing has crossed their desk.
Can the register be a spreadsheet instead?+
It can be, but a spreadsheet has no link to the retention schedule, no trigger when a new system goes live, and no evidence trail when a regulator asks how current it is. The content required is the same either way; what the register format buys is the connections.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Data Protection and Information Security
Data Protection Impact Assessment
Assesses the privacy impact of a new system or monitoring activity before it is introduced
Data Breach Record
Records loss, exposure or unauthorised access to personal data, with the assessment of harm and notification decision
Subject Access Request Record
Records a request from an individual for the data held about them, and how it was answered within the deadline
Information Security Risk Assessment
Assesses threats to systems, data and operational technology, including plant control systems
System Access Review
Reviews who has access to which systems and at what privilege level
Cyber Incident Record
Records a cyber event affecting systems, data or plant operation, with containment, recovery and notification
More in Data and Privacy
Data Protection Impact Assessment
Assesses the privacy impact of a new system or monitoring activity before it is introduced
Data Breach Record
Records loss, exposure or unauthorised access to personal data, with the assessment of harm and notification decision
Subject Access Request Record
Records a request from an individual for the data held about them, and how it was answered within the deadline

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO/IEC 27701:2019 clauses 7.2 and 7.4.7
- UK GDPR Article 30; Data Protection Act 2018
- ICO guidance on records of processing activities
- EU GDPR Article 30
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.