Art. 30 GDPR in medium-sized businesses: When the register of processing activities becomes mandatory
The most common misconception in medium-sized businesses: If there are fewer than 250 employees, the list of processing activities is no longer necessary. In fact, three exceptions are so broad that practically every SME has to maintain a VVT. This guide shows obligations, structure and depth of documentation.
Art. Since May 25, 2018, Article 30 of the GDPR has required every controller and every processor to keep a register of all processing activities. The exception for companies with fewer than 250 employees mentioned in Article 30 (5) GDPR is often read as a general exemption in medium-sized businesses. It's not her. Three reverse exceptions, which, according to the interpretation of the data protection conference and the supervisory authorities, already apply individually, almost always undermine the threshold in practice as soon as employee data, customer or supplier data are regularly processed. Anyone who has staff must be registered. The legal situation can be summarized so easily in one sentence.
Supervisory authorities such as the LfDI Baden-Württemberg, the LfD Bayern and the DSK expressly state in their short papers that most SMEs are required to register. Anyone who does not submit a complete list during an event-related audit risks a fine according to Art. 83 Para. 4 GDPR of up to 10 million euros or 2 percent of global group sales. This article explains the obligation in detail, the content according to Art. 30 Paragraphs 1 and 2 GDPR and the structure with which the directory remains viable during an audit. It also shows the second level of obligations for processors, which is often overlooked in practice, and the twelve typical processing activities that every SME should start with.
Key Takeaways
- The 250 threshold from Art. 30 Para. 5 GDPR is no longer applicable as soon as employee, customer or applicant data is permanently processed or special categories according to Art. 9 GDPR are affected.
- Those responsible need a VVT according to Article 30 Paragraph 1, processors need their own according to Paragraph 2 with their own minimum information per commissioning responsible person.
- For each activity, an auditable VVT contains the purpose, legal basis, categories, recipients, deletion periods, TOM reference, AVV link and a reference to the DPIA.
Legal basis: What Article 30 GDPR specifically requires
Art. 30 Paragraph 1 GDPR obliges the person responsible to keep a register of all processing activities that are subject to his or her responsibility. The register must be kept in writing, including electronically, and contains nine minimum pieces of information: name and contact details of the controller, if applicable, the joint controller and the data protection officer, the purposes of the processing, a description of the categories of data subjects and personal data, categories of recipients, transfers to third countries with protection guarantees, intended deletion periods and a general description of the technical and organisational measures in accordance with Art. 32 GDPR.
Art. 30 Paragraph 2 GDPR regulates the directory of the processor separately. It is leaner, but requires the categories of processing carried out on behalf of each controller. Both lists must be presented immediately upon request by the supervisory authority in accordance with Article 30 (4) GDPR. The deadline is not rigidly regulated; in Bavaria and North Rhine-Westphalia, the supervisory authorities regularly request a response within 14 days when requesting information. A later submission is considered a breach of duty and can open the scope of fines in accordance with Art. 83 Para. 4 GDPR.
Anyone who has appointed an external data protection officer documents their data under the responsible person information. The order must be supported by an appointment certificate, the order must be reported to the supervisory authority, and the reporting line to management must be visible in the organisational documentation. The appointment certificate, signed, filed, verifiable. The person responsible remains responsible even if the operational management of the directory is delegated to the DSB or an external body. A pure outsourcing clause without documented reporting channels is considered a sham delegation from a regulatory perspective and does not protect management from personal liability. Anyone who hands over the task to an auditing firm or an external service provider must contractually fix the reporting line, the escalation rules and the response deadlines and keep them auditable.
The 250 threshold and its three return exceptions
Art. 30 Paragraph 5 GDPR exempts companies and institutions with fewer than 250 employees from the directory requirement, but only under three conditions that individually trigger a return exemption. Firstly, the exception no longer applies as soon as the processing poses a risk to the rights and freedoms of the data subjects. Secondly, it does not apply if processing is not only carried out occasionally. Thirdly, it no longer applies as soon as special categories of personal data are processed in accordance with Article 9 Para. 1 GDPR or data on criminal convictions in accordance with Article 10 GDPR. As soon as one of these three return exceptions applies, there is a full obligation to keep records for all activities, not just those that give rise to the return exception.
In consulting practice, this means: payroll, application management, customer databases in CRM, newsletters and video surveillance are permanent and not just occasional processing. As soon as health data is processed in the human resources department, i.e. sick notes, severely disabled files or BEM procedures in accordance with Section 167 SGB IX, Art. 9 GDPR is relevant. A compliance hotline with possible indications of criminally relevant behaviour also triggers Art. 10 GDPR. Religious affiliation for church tax calculation in payroll is a special category according to Art. 9 Para. 1 GDPR.
The DSK has made it clear in brief paper No. 1 that the exception does not generally apply. Since 2019, supervisory authorities have assumed by default that every SME with staff is required to register. According to Article 5 Para. 2 GDPR, the burden of proof for an exception lies with the person responsible, not with the supervisory authority. Anyone who wants to invoke the exception must document that all three conditions are met cumulatively, i.e. that there is no risk, no permanent processing takes place and no special categories are affected. In practice, this documentation is not possible for micro-businesses without employees and without a customer database, otherwise not.
Content for each processing activity: What really belongs in it
A usable directory lists at least eleven fields for each processing activity. First: serial number and descriptive title, such as personnel files, application management, payroll, video surveillance of the factory gate. Secondly: the department and process owner by name, because a contact person must be named quickly for audits. Third: purpose of processing, formulated precisely according to the actual business objectives, not in general formulas like human resources management. Fourth: Legal basis according to Art. 6 Para. 1 GDPR, for special categories additionally Art. 9 Para. 2 with the specific alternative offense. Fifth: Categories of data subjects, such as employees, applicants, customers, suppliers, visitors. Sixth: Categories of personal data, divided into master data, contract data, communication data, possibly health data or bank data.
Seventh: Recipients or categories of recipients, including processor with AVV reference and contract date. Eighth: third country transfers with protection guarantees in accordance with Chapter V GDPR, such as standard contractual clauses 2021/914, adequacy decision or binding internal data protection regulations. Ninth: Deletion periods or retention periods with a legal basis, such as § 257 HGB for business letters, § 147 AO for tax-relevant documents, § 199 BGB for contract-related data. Tenth: Reference to the TOM document according to Art. 32 GDPR with version status. Eleventh: Link to the data protection impact assessment according to Art. 35 GDPR, if one has been carried out or a threshold analysis is required.
Others run compliance like a filing cabinet. We run it like software. Anyone who consistently fills out these eleven fields will have a directory that not only meets Art. 30 GDPR, but is also suitable as a control document for the entire data protection organisation. Supervisory authorities also assess the depth of information as an indicator of the maturity of the compliance organisation, which is taken into account when calculating fines in accordance with Article 83 (2) GDPR. In more recent fine notices from the Dutch and Baden-Württemberg authorities there are explicit references to the fact that a detailed and consistent list was seen as mitigating, while an incomplete or contradictory list was seen as aggravating.
Typical processing activities in SMEs: A minimum list
If you set up a VVT from scratch, it makes sense to start with the 15 to 25 processing activities that occur in almost every medium-sized company. The human resources area includes application management, personnel file management, payroll accounting, time recording, operational integration management in accordance with Section 167 SGB IX, company pension scheme, employee appraisals, onboarding and offboarding. Already in this group there are regularly special categories according to Art. 9 GDPR, such as religious affiliation for church tax, severely disabled status, health data in the BEM or trade union membership in payroll. This alone cancels the exception according to Art. 30 Para. 5 GDPR.
In the operational area, this includes customer master data, CRM sales data, ordering and accounting, complaint processing, receivables management and debt collection, newsletter and marketing dispatch as well as website tracking. In addition, there is video surveillance with its own balancing of interests in accordance with Article 6 Paragraph 1 Letter f of the GDPR, access control, telephone system with connection data and, if necessary, a compliance or whistleblower hotline in accordance with the HinSchG. The latter must be conducted as a separate activity because it is particularly sensitive according to Art. 10 GDPR and requires its own reporting line to the internal reporting office.
Supplementary activities depending on the industry include patient files in the healthcare industry, student data in educational institutions, mandate data in law firms, policyholder data with brokers, creditworthiness data in retail, applicant scoring in recruiting, telematics data in logistics, location data in field service control or biometric access systems in production and research. Experience has shown that anyone who systematically goes through this list will cover 80 percent of the processing relevant to the audit and can add the rest, such as research projects or industry-specific processing, in a targeted manner. The CIVAC platform's 490 ready-to-use audit templates cover these standard activities as templates, reducing initial setup from weeks to days. The templates already contain the typical legal bases, the usual recipient categories and the deletion periods common in SMEs with a legal basis, so that the comprehensive technical discussion can be completed in a workshop of two to three hours per department.
Processor: Your own directory in accordance with Art. 30 Para. 2
Processors are subject to an independent obligation. Art. 30 Para. 2 GDPR requires you to have a separate list that shows the categories of processing carried out for each responsible person. Mandatory information is the name and contact details of the processor, the representatives pursuant to Art. 27 GDPR if relevant, the data protection officer if applicable, the categories of processing carried out in the order, third country transfers with protection guarantees and a general description of the technical and organisational measures. The information is significantly more concise than in the list of responsible persons, but is structurally just as strictly managed and is just as subject to submission in accordance with Art. 30 Para. 4 GDPR.
In practice, this affects every SME that provides IT hosting, cloud services, outsourcing payroll accounting, marketing agency services or maintenance with data access for others. Anyone who works as an IT service provider, tax consultant, personnel service provider, letter shop, call centre or maintenance company is regularly a processor and must keep their own directory in addition to the responsible VVT. The 250 threshold also formally applies here, but in practice it is also undermined by the return exceptions. A hosting provider that processes personnel data or patient data for clients automatically moves into Article 9 territory.
Dual roles are common: A company can be responsible for its own payroll and at the same time be a processor for customer orders. Then two directories must be kept, clearly separated, with clearly documented roles for each activity. The clock starts on awareness. The supervisory authority evaluates the missing list as an independent violation and regularly checks in parallel whether the AVV according to Art. 28 GDPR and the TOM according to Art. 32 GDPR are also available.
Form, timeliness and depth of documentation: When a VVT is auditable
Art. 30 Para. 3 GDPR leaves open whether the directory is maintained as Excel, a database or a specialised tool. However, the DSK requires timeliness, completeness and ability to submit. In practice, directories fail for three reasons: they are older than twelve months and do not reflect the current processing status, they list activities without a link to AVV, TOM and DPIA, or they are maintained in different systems and contradict each other. Supervisory authorities are increasingly paying attention to internal consistency: Anyone who documents a data transfer to the USA in the VVT must have the appropriate AVV with standard contractual clauses and a transfer impact assessment that matches the date of processing.
Documentation depth means: Every statement in the directory must be derived from a deposited document. The AVV is available in version form, the TOM is structured as a separate document in accordance with Art. 32 GDPR with reference to ISO/IEC 27001:2022, the deletion concepts are stored in a separate deletion class document, the appointment certificate from the DSB is linked, the report to the supervisory authority in accordance with Art. 37 Para. 7 GDPR is documented. Anyone who shows a gap between the VVT information and the supporting document in an audit signals systemic organisational deficiencies and opens the scope for fines.
The CIVAC platform automatically links the directory with the DSB appointment certificate, the 490 ready-to-use audit templates, the AVV register and the DPIA module, in an EU data residence according to ISO/IEC 27001:2022 with 93 controls. The appointment certificate, signed, filed, verifiable. The auditor calls, the evidence is ready. Versioning with change history is standard because it enables verification during audits that the VVT is being maintained and was not just created once as a mandatory exercise.
Obligation to update: When and how the VVT is updated
The GDPR does not specify a rigid update frequency, but requires that the directory reflects the actual processing status at all times. A two-stage rhythm has been established in consulting practice. Depending on the occasion, each new processing activity is recorded immediately upon entry, i.e. before the first processing operation. This typically concerns the introduction of new software, new marketing campaigns, new processors, changed recipients or changed legal bases. Every year at the latest, a complete review of all activities against the reality of the processes is carried out, usually as a VVT audit with the departments, documented with date, participants and change log.
In addition to process changes, triggers for an update include changes in processors, new third-country transfers, new protection guarantees according to Chapter V of the GDPR, fine proceedings or adjustments to retention periods by legislation or case law. Anyone who outsources payroll from internal to an external service provider must update the activity in the VVT, complete the AVV, add the recipient categories and, if necessary, inform those affected about the changed processing in accordance with Article 13 or 14 GDPR. Audit-proof, documented, § 30-proof.
Versioning with a change history makes sense because it enables verification during audits that the VVT is being maintained and was not just created once as a mandatory exercise. The CIVAC platform stores every change with a time stamp, editor and before-and-after comparison. In the case of a supervisory request, the historical status as of any date can be reconstructed at the push of a button, which can be crucial in fine proceedings relating to a past incident. Anyone who works without versioning has to reconstruct from backups if necessary, thereby providing evidence of an inadequate compliance system. The ease of proof in favor of the person responsible, which a complete versioned status offers, is also reflected in damages proceedings according to Art. 82 GDPR, where proof of proper organisation serves to defend against claims.
Risk of fines, compensation and reputational consequences
Violations of Art. 30 GDPR are subject to the fines set out in Art. 83 Para. 4 GDPR: up to 10 million euros or 2 percent of the global group turnover of the previous financial year, whichever is higher. In the sanctioning practice of European supervisory authorities, a missing or incomplete list rarely appears as the only violation, but regularly as an accompanying accusation in fine proceedings due to data breaches, a lack of TOM or insufficient information to those affected. In several proceedings, the Dutch Authority Persoonsgegevens and the Spanish AEPD have assessed the lack of a directory as increasing the fine because it is seen as an indicator of systemic organisational deficiencies.
There are also indirect risks: In the event of a data breach according to Art. 33 GDPR with a 72-hour reporting requirement, the supervisory authority expects the directory to be presented in order to assess the extent of processing affected. Anyone who doesn't deliver here signals organisational fault. According to Section 130 OWiG, management is personally liable for breaches of supervisory duties, which triggers direct financial risks for amounts above the insured sum of the D&O policy. Claims for damages according to Art. 82 GDPR are also increasingly being affirmed in the case law of the ECJ and the BGH if the person responsible cannot prove a reliable compliance system.
In procurement procedures and supplier audits, especially in banks, insurance companies, authorities and critical infrastructures according to NIS-2, the submission of the VVT is now a standard requirement. Anyone who does not have a usable directory will be eliminated from tenders or lose existing contracts. During takeovers and due diligence checks, the VVT is evaluated as an indicator of data protection maturity and influences the purchase price or scope of the guarantee. Deadline begins as soon as we become aware of it. This applies not only to data breaches, but also to supervisory requests that regularly arrive without prior notice.
From a directory to a resilient data protection organisation
A VVT is not an end in itself. It is the central control document of the entire data protection organisation: It connects the appointment certificate, AVV register, TOM, DPIA, deletion concepts, information obligations according to Articles 13 and 14 GDPR as well as the reporting line to the management. Anyone who keeps the directory isolated in an Excel file loses precisely these connections and thus the audit resistance. Anyone who sees it as a control document has killed 60 percent of the mandatory data protection documentation with a reliable VVT. The rest comes from consistent connection to the eleven fields per activity.
CIVAC, as a compliance platform and officer-as-a-service, is built precisely for this integration. The workspace automatically maintains the directory against the AVV inventory, the 490 audit templates and the DPIA, in an EU data residence according to ISO/IEC 27001:2022. The reporting line to the management is shown as a function, the appointment certificate is generated, ready for signature and linked to the report to the supervisory authority. The 25 representative roles are all live, from the DSB to the ISB to the Compliance Representative. Licence the workspace for your internal representatives, or have our representatives order it.
With the CIVAC SLA of two working days, the appointment certificate is signed, the directory is drawn up and the first audit appointment is planned before the classic consultancy has sent out the second appointment. If you want to have the directory checked or set up for your company, turn reading into an order. Write to info@civac.de or use the contact form on civac.de. We will respond within one business day with a concrete proposal specifying the role, scope, reporting line and SLA. Turn reading into an assignment.
FAQ
As an SME with 80 employees, do we have to run a VVT?
Yes, in almost all cases. As soon as you regularly process personnel data, applicant data or customer data, the exception under Article 30 (5) GDPR does not apply. Health data in the human resources department, religious affiliation for church tax or a whistleblower hotline trigger Art. 9 and Art. 10 GDPR, which finally revokes the exception. The burden of proof lies with the person responsible and not the supervisory authority.
Is an Excel directory enough or does it have to be software?
Art. 30 Para. 3 GDPR expressly allows Excel; the law does not prescribe a specific system. In practice, however, Excel becomes confusing after around 20 activities, loses versioning and links to AVV, TOM and DPIA and leads to inconsistent statuses between departments. Above this size, a specialised platform is the more reliable solution because it automatically ensures consistency, version history and template capability.
Who is responsible for VVT in the company?
The management is responsible in accordance with Art. 24 GDPR and is personally liable in accordance with Section 130 OWiG for breaches of supervisory duties. The data protection officer advises and monitors in accordance with Art. 39 GDPR, but does not maintain the directory himself. The content is provided by the departments that actually carry out the processing. The DPO ensures methodology, consistency and ability to submit documents, acts as an interface to the supervisory authority and documents the reporting line.
How often does the directory need to be updated?
Depending on the occasion, immediately with every new processing activity, with new processors, new recipients or new third-country transfers. In addition, a complete annual review of the actual processes, documented with date, participants and minutes. Versioning with a change history is recommended because supervisory authorities check liveness and Excel without a history is quickly considered inadequate, especially for processes with a historical reference.
What happens in the event of a supervisory audit without a VVT that can be presented?
The authority considers the missing list to be an independent violation according to Art. 30 GDPR and usually as an accompanying accusation that increases the fine according to Art. 83 Paragraph 4 GDPR with a limit of up to 10 million euros or 2 percent of group sales. In the event of data breaches, organisational negligence is also assumed, which makes claims for damages easier according to Art. 82 GDPR. According to Section 130 OWiG, management is personally liable for breach of supervisory duty.
How quickly can CIVAC set up a VVT?
With the CIVAC SLA of two working days, the workspace is set up, the data protection officer's appointment document is signed and an initial activity draft is derived from the 37 audit templates. The full expansion with 15 to 25 activities will take place in four to six weeks, depending on the availability of the specialist areas and the complexity of the third country transfers. If desired, CIVAC can take over the order as an officer-as-a-service including a reporting line.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.