VVT software: Keep the register of processing activities in an audit-proof manner
Excel lists do not stand up to regulatory audits. VVT software bundles processing activities, TOMs and reporting lines in one system. This article shows which functions Art. 30 GDPR really requires and how you can recognise an audit-proof tool.
According to Art. 30 GDPR, every person responsible with at least 250 employees and in many smaller constellations must keep a register of processing activities (VVT). The supervisory authorities require it in writing, upon request and in full. Anyone who answers it with an unstructured Excel list or a collection of Word files runs into two risks at the same time: fines according to Art. 83 GDPR of up to 20 million euros or four percent of the global annual turnover and the personal liability of the management according to Section 130 OWiG. Both risks add up if the directory is found to be out of date or incomplete in the audit.
VVT software addresses exactly this gap. It bundles processing activities, technical and organisational measures, processors, third-country transfers and deletion periods in a system with versioning, a complete reporting line, a clear role model and a machine-readable export function. This article explains which functions the tool really has to cover, where Excel reaches its limits, which eight criteria count before purchasing and how CIVAC, as a compliance platform and officer-as-a-service, relieves the data protection officer without taking the responsibility of the person responsible. Licence the workspace for your internal representatives, or have our representatives order it. Both models share the same data and the same audit trail.
Key Takeaways
- Art. 30 GDPR requires a complete, written list of all processing activities, including versioning and TOM connection, which can be presented upon request.
- Excel does not scale: without a role model, version history and audit trail, there is no proof to supervisory authorities as soon as a deadline export is required.
- CIVAC bundles VVT, TOMs, appointment certificate and reporting line in a workspace with EU data residency and 93 ISO 27001:2022 controls, optionally including external DSB.
What Article 30 GDPR specifically requires
Art. 30 Para. 1 GDPR lists the mandatory contents of the list for those responsible: name and contact details of the person responsible and the data protection officer, purposes of processing, categories of data subjects and personal data, categories of recipients including recipients in third countries, third country transfers including appropriate guarantees in accordance with Art. 46 GDPR, planned deletion periods and a general one Description of the technical and organisational measures in accordance with Art. 32 GDPR. Each of these points is mandatory, none is optional.
Art. 30 Paragraph 2 GDPR regulates the counterpart for processors with their own, slightly different list of contents. Both variants must be kept in writing, including electronically, and made available to the supervisory authority upon request. The relief for companies with fewer than 250 employees only applies if there is no high-risk processing, no regular processing and no special data categories according to Art. 9 or criminally relevant data according to Art. 10 GDPR. In practice, this exception does not apply to most SMEs because at least HR data and applicant processes are processed regularly.
The Conference of Independent Data Protection Supervisory Authorities (DSK) has made it clear in several short papers that a directory may not only be created on request. It must exist at the time of the request, be complete and reflect the actual processing landscape. Anyone who only closes gaps after receiving a request for information has already lost proof of the prior obligation. The auditor calls, the evidence is ready. It is precisely this verifiability that distinguishes a managed compliance function from a documentary facade. The Federal Commissioner for Data Protection and Freedom of Information has also repeatedly pointed out in his activity reports that the directory should be kept as a central control instrument and not as a compulsory bureaucratic exercise. Anyone who understands Art. 30 GDPR as an operational tool will already have the answer ready in an emergency.
Why Excel and Word reach their limits
Excel lists are popular as an entry-level tool because they are quickly available and do not incur any licence costs. However, during operation they create four structural problems. Firstly, there is no version history: who changed which entry, when, and which version was valid on the key date of an audit? A shared file on a network drive does not answer this question reliably; even if SharePoint saves version statuses, the difference in content per processing activity is not displayed.
Secondly, the role and authorisation model is missing. A specialist department should maintain its own processing activities, but should not be able to read or change those of the HR department. Applicant data in HR is particularly sensitive and must not be in an open directory. This separation is practically impossible to reproduce in Excel without working with dozens of separate files that no one can merge.
Thirdly, the links are missing. A processing activity depends on a procedure, an order processing contract, a TOM description, a data protection impact assessment and a deletion rule. In a flat table, these relationships remain implicit. If the processor changes, dozens of lines have to be updated manually without any evidence that all relevant activities have been updated. When there is a supervisory query about a specific service provider, there is no clear answer list.
The fourth problem is rejection. A supervisory authority requires the directory in a structured format and as of a specific date. Anyone who spends hours on manual filtering signals to the auditor that the system is not operationally under control. Others run compliance like a filing cabinet. We run it like software. VVT software delivers an audit export at the push of a button, with date, version status and completeness indicators for each processing activity. This not only saves time, it also sends a clear signal to the supervisory authority that the directory is actually being maintained in day-to-day business and has not just been reconstructed for the day of the exam.
Mandatory functions of an audit-proof VVT software
VVT software must display the mandatory content from Art. 30 GDPR as structured fields, not as free text. Only structured fields allow filtering, reporting and completeness checking. These include: processing purpose, legal basis according to Art. 6 or Art. 9 GDPR, categories of data subjects, categories of personal data, recipient categories, third country transfers with a mechanism according to Art. 46 GDPR, deletion periods with specific rules and a link to the TOMs according to Art. 32 GDPR. Each field is its own search key and its own filter.
The second pillar is versioning. Every change to a processing activity creates a new version, with a time stamp, processor and reason for the change. The software must be able to reconstruct previous versions at the push of a button. This also includes blocking activities that are no longer active without the history disappearing. The third pillar is the connection to the reporting line. The DPO signs the statement, the management indicates that they have taken note, and the person responsible remains in the foreground. The appointment certificate, signed, filed, verifiable.
Fourth pillar: Interfaces. VVT software is not isolated. It depends on the processor register, the directory of data protection impact assessments, the data breach reporting path in accordance with Art. 33 GDPR and the information management in accordance with Art. 15 GDPR. CIVAC bundles these modules in the workspace so that an entry in the VVT automatically flows into the downstream processes. The fifth pillar is the EU data residency: the software in which the VVT is managed must not itself become a third country transfer problem. Sixth pillar: pre-filled audit templates that standardise typical activities and give specialist departments a quick start without starting every directory from scratch. A seventh pillar that is underestimated in many companies is multilingual handling.
Roles and responsibilities in VVT operations
The directory is not the work of the data protection officer alone. According to Art. 24 GDPR, the management of the person responsible, usually the management, remains responsible for content and completeness. The DPO monitors, advises and checks in accordance with Art. 39 GDPR, but does not write all the entries himself. The operational responsibility lies with the specialist departments that know the respective processing activity: HR for personnel data, marketing for campaigns, IT for log data, sales for CRM, financial accounting for payment data, purchasing for supplier contacts.
An audit-proof VVT software maps this model as a workflow. Specialist departments enter processing activities and answer structured questions, such as the legal basis or deletion deadlines. The DPO receives the activity for review, comments, requests improvements and approves or raises concerns with the management in accordance with Art. 39 GDPR. Each of these actions creates an audit entry. This makes it possible to understand who made which decision and when. The DSB statement remains documented, even if management decides otherwise.
The Compliance Officers benefit from the same architecture because money laundering risk analyses, whistleblower channels and VVT can converge in one reporting line. CIVAC provides the underlying platform and, if desired, takes on the role: Licence the workspace for your internal representatives, or have our representatives order it. Both models share the same data, the same templates and the same audit trail. If the model changes over time, for example because an internal DPO position becomes vacant, there is no break in the documentation and no migration to a new platform. The replacement rule in the event of vacation or illness also remains contractually guaranteed, so that the person responsible does not have to bear any personnel issues if the DPO is not available.
Think VVT, TOMs and data breach reporting path together
A directory without a connection to the TOMs according to Art. 32 GDPR remains incomplete. The GDPR requires a general description of the protective measures for each processing activity. In practice, these are access control, access control, access control, forwarding control, input control, order control, availability control and separation control, now often based on Appendix A of ISO/IEC 27001:2022 with 93 controls. VVT software allows TOMs to be maintained centrally once and assigned to a processing activity instead of copying them per activity. Changes to the TOMs therefore have a consistent impact on all activities.
The second connection is the data breach reporting path. Art. 33 GDPR obliges the person responsible to report a reportable breach to the supervisory authority within 72 hours of becoming aware of it. Deadline begins as soon as we become aware of it. A platform that maintains the VVT can directly link a data breach to the affected processing activity, the affected data categories and the documented TOMs. This means that the report on the matter is complete within hours, instead of having to be reconstructed from Excel tables. The notification of data subjects in accordance with Art. 34 GDPR can be prepared with the same data points.
The third link concerns the data protection impact assessment in accordance with Art. 35 GDPR. High-risk activities must undergo a DPIA before starting. VVT software flags these activities based on the criteria of the European Data Protection Board and automatically starts a DPIA process. This reduces the likelihood that risky processing will subsequently come to light, for example during a supervisory audit or complaint procedure. The DPIA remains linked to the original activity, so that even years later it can be traced which risk assessment was responsible for the start of the processing. In this way, the directory becomes the shared memory of the data protection organisation.
Cost question: licence, internal effort, officer-as-a-service
The question of costs cannot be answered using licence fees alone. Three items count. Firstly, the software itself, usually an annual workspace price with modules for VVT, AVV, DPIA, data breaches, information and reporting lines. Secondly, the internal personnel costs: without a tool, a DSB in a medium-sized company typically invests 30 to 60 percent of his working time in administrative activities, which a platform reduces to 15 to 25 percent. Thirdly, the risk: A fine according to Art. 83 GDPR can amount to 20 million euros or four percent of global annual turnover, whichever is higher.
The CIVAC SLA sets two working days for standard processes, instead of the classic two to six weeks. This speed advantage is particularly effective where many specialist departments introduce or change activities in parallel, for example after reorganizations, product launches or M&A transactions. Anyone who purchases an external DPO as an officer-as-a-service is not just buying advice, but also a person with an appointment document, reporting line and tools, all from a single source. The representation arrangement in the event of vacation and illness is covered by the contract and therefore no personnel risk for the client.
The central workspace is worthwhile for groups with several companies because the multi-client capability allows directories for each company to be maintained and at the same time to enforce group-wide standards for TOMs, deletion periods and AVV. This saves double maintenance and makes the reporting line to the group data protection officer more resilient. Audit-proof, documented, Art. 30 GDPR-proof. It is also possible to compare the subsidiaries with each other because the same structures are used and deviations remain visible, for example in recipient categories or third country transfers. In M&A transactions, uniform directories save several weeks in the due diligence phase because the buyer can check the data protection situation across all subsidiaries in a uniform format.
Selection criteria: Checklist before making a tool decision
Before purchasing VVT software, it is worth making a structured comparison based on eight criteria. Firstly: Is all mandatory content from Article 30 Paragraph 1 and Paragraph 2 GDPR displayed as structured fields, not as free text? Secondly, is there a complete version history with recovery of boards and difference view between two points in time? Thirdly: Can a role model be created that differentiates between specialist departments, DPOs, data protection coordinators and management, with different reading and writing rights per area? Fourth: Are there links to AVV, DPIA, data breaches, information requests and TOMs so that a change in one place marks all affected data sets as worthy of review?
Fifth: Where is the data processed? A VVT software with hosting outside the EU produces a third country transfer itself and counteracts the concern. CIVAC offers EU data residency and operates an ISMS according to ISO/IEC 27001:2022 with 93 controls. Sixth, are there 490 ready-to-use audit templates that pre-populate typical HR, marketing, IT, sales and finance processing activities and reduce inventory? Seventh: Is there an API or structured exports for audits and regulatory requests, including PDF, XLSX and machine-readable formats?
Eighth, and often underestimated: Does the provider offer an officer-as-a-service model? Software without a human is not helpful in the audit if the appointment certificate is missing or the DPO is overloaded. CIVAC provides both: the workspace for internal officers and the option to appoint an external data protection officer via the same platform. Anyone who systematically checks these eight criteria avoids expensive tool migrations after 18 months and ensures a compliance architecture that supports multiple audit cycles. A tool change quickly costs quarters of internal commitment and destabilizes the documentation.
Migration path: from Excel hodgepodge to structured directory
Migrating an Excel list or several Word documents into VVT software can be done in three steps. Step one is taking inventory. What processing activities actually exist? Which are documented and which are missing? In most companies there is a gap between what happens in day-to-day operations and what is written down in the directory. A structured workshop with the specialist departments closes this gap within two to four weeks. Experience has shown that between 20 and 40 percent of additional activities appear that were missing in the old directory.
Step two is the transfer to the software. The 490 CIVAC audit templates cover the most common activities and provide pre-filled structures for HR, applicant management, newsletters, customer relationship management, IT log files, video surveillance, time recording and complaint management. Specialist departments supplement the specific content. Parallel maintenance in Excel will be ended as soon as the first completeness check in the platform has been completed. Only the hard cut prevents two sources from emerging, which diverge over time and both reveal their own gaps in the audit.
Step three is ongoing operations. Every new processing activity arises in the workflow, no longer ad hoc. The DSB statement in accordance with Art. 39 GDPR becomes part of the process, the management indicates that it has been acknowledged, and the supervisory authority receives a deadline export within hours of inquiries. If you follow the migration path cleanly, you avoid the most common audit problem: an officially maintained but outdated directory, which is immediately noticeable in random samples. The ISO/IEC 27001:2022 ISMS connection ensures the technical integrity of the data and also provides evidence for clients who expect an ISO-certified processor. This creates a directory that not only withstands regulatory authorities, but also customer audits without additional effort.
Turn reading into an assignment
VVT software is not an end in itself. It is the tool with which the data protection officer operationally implements Art. 30 GDPR and at the same time relieves the burden on management. Anyone who still keeps their directory in Excel today can use the next audit date as an opportunity to fundamentally change the system. The eight selection criteria from this article provide a clear framework for this. The migration takes four to eight weeks in most medium-sized companies and three to six months in larger corporate structures, with clear stages and a comprehensible result.
CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives, or have our representatives order it. Both models share the same data, the same 490 audit templates and the same reporting line. You choose whether your DPO remains staffed internally or comes through us as an external officer-as-a-service with an appointment certificate and representation rules. In both cases, the platform is identical, and switching between models is possible at any time without breaking the documentation.
Turn reading into a mandate. Send us a short description of your initial situation to info@civac.de or use the contact form on civac.de. Within two working days you will receive a proposal with the licence scope, migration plan and, if desired, an appointment certificate for the external data protection officer. The first appointment clarifies the specific processing activities in your industry, the TOM situation and the requirements of your most important clients. It will then be clear whether a workspace is sufficient or whether an officer-as-a-service model is the more viable answer. The auditor calls, the evidence is ready., and the reporting line to management remains clearly documented.
FAQ
Do we have to maintain a VVT if we have fewer than 250 employees?
Yes, in almost all cases. The exception under Article 30 Paragraph 5 GDPR only applies if no risky, regular or particularly sensitive processing takes place. Regular HR data processing already meets the criterion, so the exception practically does not apply to most SMEs and a complete directory remains mandatory, which must be presented to the supervisory authority upon request.
Is an Excel spreadsheet sufficient for the directory?
Formally yes, operationally no. Excel fulfils the written form, but fails due to versioning, role models and links to AVV, DPIA and data breaches. In the audit, Excel stands out as soon as the supervisory authority requests a key date export or a complete version history. VVT software delivers both without manual effort and also secures the audit trail of each individual change.
Who is responsible for VVT in the company?
Responsible according to Art. 24 GDPR is the management of the person responsible, usually the management. The data protection officer monitors and advises in accordance with Art. 39 GDPR, and the specialist departments enter the operational content of their processing activities. The DSB statement remains documented, even if the management decides otherwise, and thus secures the personal liability situation in accordance with Section 130 OWiG.
How long does it take to introduce VVT software?
In medium-sized companies, four to eight weeks from kick-off to productive operation. Larger corporate structures with several companies require three to six months. Pre-filled CIVAC templates significantly shorten the inventory because 37 standard activities are not built from scratch, but are loaded into the client as a template and only supplemented with the specific content.
Does CIVAC meet EU data residency requirements?
Yes. CIVAC operates the workspace in EU data centres and runs an ISMS according to ISO/IEC 27001:2022 with 93 controls. This means that the VVT software itself does not create a third country transfer that would have to be secured in accordance with Art. 44 ff. GDPR, and the person responsible can operate the workspace without an additional standard contractual mechanism. Audit reports are available for submission to customers.
Can we order the DPO as an external officer-as-a-service via CIVAC?
Yes. CIVAC provides external data protection officers with an appointment certificate, reporting line and access to the workspace. Licence the workspace for your internal representatives, or have our representatives order it. Both models share the same data, the same 37 audit templates and the same audit trail, without a migration to a new system occurring when changing the model.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.