Processing directory template according to GDPR: What an auditable template really needs to contain
A processing directory template in accordance with Art. 30 GDPR can be found online in five minutes. Whether it is test-proof is not determined by the column head, but by how it is maintained. The article shows mandatory fields, typical gaps and the transition from the template to the maintained directory.
Art. 30 GDPR obliges every person responsible with at least 250 employees and, in fact, almost every smaller company to keep a register of processing activities. The obligation arises if the processing poses a risk to the rights and freedoms of the data subjects, occurs regularly or includes special categories of data in accordance with Article 9 GDPR. In practice, this applies to every HR department, every online shop and every newsletter database. Search queries for a processing directory template are correspondingly high, but the quality of the freely available templates varies considerably.
A template is not a directory. It is an empty framework that must be maintained, otherwise it becomes a false sense of security. Supervisory authorities do not check whether an Excel sheet exists, but rather whether the entries made correspond to lived reality and whether every processing has a documented legal basis. This article is aimed at data protection officers, management and compliance officers. You will find out which mandatory fields are specifically required by Art. 30 GDPR, which additional fields experienced supervisory authorities expect, why most templates fail and how the CIVAC Compliance Platform and Officer-as-a-Service transfers the template into a well-maintained directory that, in the event of an audit, requires two working days and not two weeks of preparation time.
Key Takeaways
- Art. 30 GDPR lists seven mandatory pieces of information for those responsible and four for processors; a blanket template without maintenance does not replace any of them.
- In addition to the mandatory fields, supervisory authorities expect a documented legal basis, deletion periods and technical and organisational measures for each processing.
- A well-maintained directory is the only document that can be presented in the audit within a few days, without hasty research in specialist departments.
What Art. 30 GDPR requires as minimum content
Art. 30 Paragraph 1 GDPR names seven pieces of information that a list of processing activities at the person responsible must contain at least. Firstly, the name and contact details of the controller and, if applicable, the joint controller and the data protection officer. Secondly, the purposes of the processing. Third, a description of the categories of data subjects and the categories of personal data. Fourth, the categories of recipients to whom the data have been or will be disclosed, including recipients in third countries. Fifthly, if necessary, transfers to third countries with the documentation of suitable guarantees in accordance with Art. 46 GDPR. Sixth, deadlines provided for deletion. Seventh, a general description of the technical and organisational measures in accordance with Art. 32 GDPR.
These seven pieces of information are mandatory. But they are not sufficient. In practice, the German supervisory authorities require further information, without which a list in the audit can hardly be defended. This includes, above all, the respective legal basis according to Art. 6 GDPR and, if applicable, Art. 9 GDPR, the specific IT application or database in which the processing takes place, and the date of the last update. Anyone who adopts a template from the Internet without these extensions formally documents the set of mandatory fields, but not the status of their compliance.
The external data protection officer therefore checks in every initial contact not only whether a directory is available, but also whether the mandatory fields have been designed in accordance with the DSK short papers. A blanket statement such as “fulfilment of the contract” as the purpose or “general TOM” as the measure is not a sufficient answer in the audit case. Experienced auditors immediately question which specific contracts are meant, which TOM actually apply and whether the assigned recipient categories correspond to the actual data flows. A reliable template forces you to be more specific because it provides mandatory fields with selection lists and validations instead of ending with an open column.
Mandatory fields for processors according to Art. 30 Para. 2 GDPR
Art. 30 Paragraph 2 GDPR regulates a separate directory for contract processors with a reduced scope. Four pieces of information are mandatory: name and contact details of the processor, each controller and the respective data protection officer, the categories of processing carried out on behalf of each controller, third country transfers with guarantees, if applicable, and a general description of the TOM in accordance with Article 32 GDPR. Many medium-sized companies overlook the fact that their own role can not only be the person responsible, but also the processor in individual processes, for example when HR data is processed for a group company.
Those who are processors keep two directories in parallel. One documents your own processing as the controller, the other the processing carried out on behalf of the controller. A clean separation is important because the duties are different. The processor is also liable according to Art. 82 GDPR if he acts without instructions or against instructions. A template that only provides for controller processing is inadequate for processors. Additional columns are required here for the client, order, contract date and status of the TOM check.
In 2026, the Hessian supervisory authority imposed several fines of between 25,000 and 180,000 euros because contract processors in IT outsourcing and HR services did not keep their own directory, but instead referred to the directories of their clients. This construction is legally inadmissible. Anyone who processes data on behalf of the customer must keep their own register, even if it corresponds in detail to the client's register. A platform solution allows the same process to be represented in both roles without entering the data twice, which reduces update errors. The separation is represented via views and authorizations, not via separate Excel files, which quickly diverge in practice.
Typical errors in freely available Excel templates
Freely available Excel templates are useful in the initial stages. However, they regularly fail in three places. Firstly, validations are missing. Columns for legal bases or deletion periods are kept as free text, which leads to inconsistent entries such as "Art. 6 GDPR", "Art. 6 Para. 1 lit. b", "Contract" and "Fulfillment of the contract" for the same matter. This appears chaotic in the audit and creates follow-up questions. A verifiable template forces a selection from a closed list that corresponds exactly to the six letters of Article 6 (1) GDPR.
Secondly, versioning is missing. Excel does not store any systematic history. Anyone who changes processing in March and is audited in November can rarely prove what applied before. Although the GDPR does not have an explicit versioning requirement, the accountability requirement pursuant to Article 5 Para. 2 GDPR requires proof of legality at the time of processing. This proof cannot be achieved without versioning. A professional template therefore maintains a change log with the date, author and description of the change.
Thirdly, there is no link to other compliance artifacts. Processing without a link to the appropriate data protection notice version, to the order processing contract with the respective service provider or to the data protection impact assessment is only an entry in the audit, not proof. Anyone who uses a template that is networked with information texts, AVV templates and DPIA templates halves their maintenance effort and eliminates the most common audit gap. The CIVAC platform provides these links as a standard architecture so that a change to a processing automatically marks the dependent documents. Others run compliance like a filing cabinet. We run it like software. Added to this is the lack of multilingualism: If you process in several EU countries, you will also need the directory in English upon request, which Excel solutions with German column headers do not cover.
Maintenance as a permanent task: the directory is alive
A directory is not a one-time project. It's an ongoing task that grows with every new database, every new cloud service and every new staff category. In Brief Paper No. 1, the Data Protection Conference recommends a cyclical review at least once a year, and in high-risk areas every six months. In practice, supervisory authorities can immediately see from a random sample whether a directory is alive or just gathering dust in a closet. Indicators are the date of the last update, the number of processings with status "under review", the consistency of recipient lists and the timeliness of TOM descriptions.
Nursing needs a reporting line. The data protection officer reports quarterly to management which processing operations have been added, which have been eliminated and which require a risk reassessment. This reporting line is not just a question of good manners, but an obligation under Section 38 BDSG for the data protection officer, who is to report directly to the highest management level. Anyone who cannot reflect this in their own organisation is given a compliance lever.
An automated maintenance cycle helps in practice. In the CIVAC platform, every processing receives a resubmission date and a responsible owner from the specialist department. If the resubmission remains unprocessed, the system escalates to the data protection officer and, after a further deadline, to the management. This escalation does not replace a content check, but it ensures that no entry sits unprocessed for years. The appointment certificate, signed, filed, verifiable. The same logic applies to the directory: maintained, dated, filed, verifiable. Anyone who does not actively manage the care cycle will have to present a historical document in an emergency, not current proof of compliance. Three clearly documented updates per year and processing are the limit below which supervisory authorities become critical in practice.
Interface to order processing contracts and TOM
Every processing in the directory in which an external service provider is involved has an associated order processing contract in accordance with Art. 28 GDPR. The template must make this link visible. In practice, a column with the contract name, the contract date, the date of the last update and a reference to the stored document is useful. Anyone who cannot present the contract within a few minutes has a maintenance problem. Supervisory authorities specifically check the link for larger cloud service providers and for transfers to third countries.
The technical-organisational measures in accordance with Art. 32 GDPR are typically included in the template as a general reference to your own TOM document. This is insufficient in most cases. Supervisory authorities expect the TOM per processing to be as detailed as the need for protection requires. A payslip with salary data and tax IDs needs a different TOM depth than a newsletter distribution list. A verifiable template therefore contains a TOM classification in at least three levels and links each processing with the relevant level.
Anyone who operates an information security management according to ISO/IEC 27001:2022 can systematically map the 93 controls of this standard to the TOM description in the directory. This illustration is not only efficient, it also strengthens the basis for argumentation in the audit. The supervisory authority immediately recognises that the TOM was not documented out of thin air, but is based on an established security standard. The CIVAC platform provides this link as a standard mapping and updates it when changes to the control set, such as the adjustments that the transition to ISO/IEC 27001:2022 entails in the transition period until October 2026. In practical terms, this means: Processing with high protection requirements is automatically assigned the appropriate control set; the DSB does not have to check each TOM selection manually.
Clearly document third-country transfers
Transfers to third countries are a particularly sensitive mandatory area according to the Schrems II ruling of the ECJ (C-311/18). The template must clearly indicate which countries data will be transferred to, the basis on which the transfer takes place in accordance with Art. 44 ff. GDPR and what additional measures have been taken. The standard contractual clauses as amended by Implementing Decision 2021/914 are the most common instrument. However, simply mentioning it is not enough; the platform must document the respective module choice (modules 1 to 4) and name the additional measures such as encryption or pseudonymization.
Since the EU-US Data Privacy Framework, which the EU Commission recognised as appropriate in July 2023, transmission to the USA to certified companies is again possible without SCC. However, recognition can be revoked, which is why directories should continue to list SCC as a fallback option. An auditable template shows the certification in the DPF for every US transmission, with a link to the US Department of Commerce list, and in parallel the SCC variant with module selection. For transfers to other third countries without an adequacy decision, the documentation is more complex because a transfer impact assessment must be carried out in accordance with Recommendation 01/2020 of the European Data Protection Board.
The consequences of missing or incomplete documentation are significant. The Irish Data Protection Authority fined Meta Platforms Ireland €1.2 billion in 2026 for inadequately documented transfers to the US. Even if this case remains an isolated case in its magnitude, it shows that supervisory authorities strictly examine the formal documentation for third-country transfers. A template that only lists third country transmissions as free text is a risk here. The auditor calls, the evidence is ready. if the transmission is available as a structured data record with the recipient country, recipient, legal basis, additional measures and TIA reference.
Access rights, views and role separation in the directory
A directory contains sensitive information about a company's entire data landscape. It may not be visible to every employee. At the same time, department heads must be able to maintain their own processing, the data protection officer needs read access to all processing, and management needs an aggregated overview with key figures. An Excel template usually does not solve this rights problem. It is either too open or too restrictive.
A platform-based template cleanly separates roles. Department owners only see and maintain the processing assigned to them. The data protection officer sees everyone, but can only approve changes to content upon suggestion. Management receives a dashboard with key figures such as number of processing operations, number of third-country transfers, number of overdue reviews and number of open DPIAs. This separation corresponds to the principle of minimum authorisation according to Art. 32 GDPR and is at the same time a control according to Annex A.5.15 of ISO/IEC 27001:2022.
Audit-proof, documented, Art. 30-proof specifically means that every change to the directory is assigned to an identifiable processor and does not come from a released Excel file with anonymous processors. The CIVAC platform's EU data residency ensures that the directory itself is processed in the European Union, providing additional security when transmitting the directory to external auditors. Licence the workspace for your internal representatives, or have our representatives order it. Both models use the same platform, the separation of roles remains identical. An authorisation matrix is defined once and applies to all processing, regardless of the model chosen. During an audit, time-limited read access can also be set up for the auditor, which automatically expires after completion and is documented in the audit trail.
Migration from Excel to the structured template in practice
Most companies start with an Excel file and at some point are faced with the question of whether and how to migrate to a structured platform. A migration is not a data transfer, but a cleanup. It forces all processing to have a uniform structure, merge duplicate entries and archive outdated entries. Experience has shown that an average Excel directory contains between 15 and 40 percent outdated or duplicate entries.
The migration path in practice: First, inventory all existing entries. Second, mapping the Excel columns to the platform mandatory fields. Thirdly, eliminating duplicates and updating the legal basis notation. Fourth, transfer to the platform, usually via an import. Fifth, owner assignment per processing. Sixth, first round of care by the owners with a fixed deadline. Seventh, handover to the data protection officer for approval.
The CIVAC platform offers its own migration template and a guided import for this path. The 490 audit templates in the workspace cover all standard processing of a medium-sized company, so that the owner does not start from scratch, but simply adapts a technically prepared description to reality. These templates are not static, but are updated as the DSK briefs, EDPB guidelines or relevant case law change. Anyone who maintains their own template in Excel has to keep track of these updates themselves, which rarely happens in practice. The migration is not just a technical change, but also a leap in quality. Deadline expires as soon as we become aware of it: Anyone who discovers a defect in the existing directory does not have a grace period but must make improvements immediately. The migration is therefore usually a conscious decision by management, not a no-brainer from the IT department, and it should be given a clear deadline by which the old Excel version will be frozen and only the platform will be used.
From template to maintained directory: a concrete next step
A template alone is not compliance. It is a start that requires a culture of care and a role structure. The mandatory fields and extensions described in this article are already stored in the CIVAC platform, including the links to DPIA, AVV and TOM. If you want to build a directory or consolidate an existing one, you have two options. If you licence the workspace for your internal representatives, then your internal data protection officer and the department owners maintain the directory themselves, with all templates, reviews and escalation paths. Or you can have our representatives appointed, then CIVAC will take over the appointment of the external data protection officer, including maintaining the directory and reporting to the management.
Experience has shown that the effort required to initially fill a directory for a medium-sized company is between three and six working days. Ongoing maintenance amounts to around two hours per month for the data protection officer and ten to thirty minutes per month per department owner. Anyone who doesn't invest these hours will have a problem in the audit that can hardly be caught up within the CIVAC SLA of two working days. The usual preparation time without a platform is two to six weeks, during which specialist departments are consulted, documents are searched for and gaps are frantically closed.
Turn reading into an assignment. If you want an audit-proof template and a well-maintained reporting line without building your own, write to info@civac.de or use the contact form on civac.de. In the initial consultation, we will clarify whether the workspace will be combined with your internal data protection officer or whether CIVAC will appoint the external data protection officer. Both paths lead to a directory that can withstand unannounced scrutiny. With the EU data residency and the ISO/IEC 27001:2022 certification, the platform is set up in such a way that a future group audit or a supply chain requirement according to LkSG no longer requires any additional adjustments.
FAQ
Who is obliged to keep a directory according to Art. 30 GDPR?
In principle, all responsible parties and processors with at least 250 employees are obliged. However, the exception under Article 30 Para. 5 GDPR only applies if the processing does not take place regularly and no special categories of data are affected. In practice, this applies to almost every company with HR data, customer database or online shop, so there is in fact a general obligation.
What format does a directory template need to have, Excel or platform?
Art. 30 Para. 3 GDPR requires written form, which can also be fulfilled in electronic form. Excel is permitted, but risky in practice because validation, versioning and separation of roles are missing. A platform-supported template with an audit trail clearly fulfils the obligation and is easier to present during audits than a grown Excel collection with multiple versions.
How often does a directory have to be updated according to GDPR?
The GDPR does not specify a fixed deadline. In Brief Paper No. 1, the Data Protection Conference recommends a cyclical review at least once a year, and in high-risk areas every six months. Depending on the circumstances, an update must be carried out immediately if new processing operations are added, legal bases change or new recipients are added. A pure annual audit without event-related updates does not fulfil the accountability requirement pursuant to Article 5 (2) GDPR.
Do I have to mention the legal basis according to Art. 6 GDPR in the directory?
Art. 30 GDPR does not explicitly mention the legal basis as a mandatory field. The supervisory authorities still expect them in practice and the list is not meaningful without this information. The Data Protection Conference expressly recommends the inclusion of the legal basis in Brief Paper No. 1. Anyone who leaves them out runs the risk of questions that call the entire directory into question.
What happens if the directory is not available during an audit?
According to Article 83 Para. 4 GDPR, missing or incomplete maintenance of the directory is punishable by a fine of up to 10 million euros or two percent of the global annual turnover. In practice, the German supervisory authorities rarely impose the maximum, but a fine of between 5,000 and 50,000 euros for SMEs for structural gaps is realistic.
Can CIVAC adopt an existing Excel template?
Yes, the CIVAC platform offers a guided import of existing Excel directories. During the migration process, duplicates are cleaned up, legal bases are standardised and owners are assigned. The initial cleanup takes three to six working days, depending on the scope. Either the internal data protection officer then maintains the data or an appointed external representative from CIVAC; both models use the same structured template.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.