Does a small business have to keep a record of processing activities?
Almost always, yes. Article 30(5) GDPR exempts businesses with fewer than 250 employees, but only where the processing is occasional, poses no risk to data subjects and involves no special or criminal offence data. Daily customer contact by email, WhatsApp or phone is by definition not occasional, so the exemption falls away. The Dutch data protection authority puts it plainly: a record of processing activities is nearly always mandatory, usually for small businesses too.
Published on
Almost every business owner who reads up on the GDPR eventually hears the same reassurance: below 250 employees you do not have to keep a record of processing activities. That sentence is half right. There is indeed an exemption in the law, and it does indeed mention 250 people. But it is immediately followed by a word that closes the exemption again: unless. And for a business that deals with customers every day by email, WhatsApp or phone, that unless almost always applies.
This article explains where the threshold comes from, why it rarely helps in practice, what belongs in a record, how detailed it needs to be for a company of a few people, and what changes the moment you connect an AI assistant to your customer contact.
Where does the 250-employee threshold come from?
The obligation sits in Article 30 GDPR. Paragraph 1 says that the controller — that is you, the business owner who decides why and how customer data is used — keeps a record of all processing activities carried out under their responsibility. Paragraph 2 imposes a comparable duty on processors: parties that process data on someone else's instructions.
Paragraph 5 is the exemption everyone refers to. It states that the obligations in paragraphs 1 and 2 do not apply to enterprises or organisations employing fewer than 250 persons. So far the story holds. The Dutch data protection authority puts the other side just as plainly: if your organisation has more than 250 employees, you are obliged to keep a record, full stop. Above the line there is nothing to discuss.
The problem is what people stop reading. After the word unless, Article 30(5) simply carries on with three situations in which the exemption does not apply. Trigger any one of them and you are back under the obligation. These are not edge cases. They are precisely the things an ordinary business does all day.
The supervisory authority sums up the outcome in plain language: a record of processing activities is nearly always mandatory, and usually for small businesses too. That is not a strict reading; it is simply the sum of the three exceptions.
Why the exemption rarely survives contact with customers
The three escape clauses in Article 30(5) are: the processing is likely to result in a risk to the rights and freedoms of data subjects; the processing is not occasional; or the processing involves special categories of data under Article 9 GDPR or criminal conviction and offence data under Article 10 GDPR.
The second one is the quiet killer. Not occasional means: not by chance, not a one-off, not outside your normal course of business. Customer contact is structural by definition. You do not happen to answer an email once; you have an inbox, and something lands in it every working day. You keep names, phone numbers, addresses, order histories. There is a payroll administration in your accounting package. The moment something is a recurring part of how you run the business, it is not occasional, and the exemption is gone.
The first clause catches whatever is left. "Risk to rights and freedoms" is a low bar — it speaks of a likely risk, not a high risk. A file containing contact details, conversation histories and complaints that ends up in the wrong hands affects those people. That is exactly the kind of risk meant here.
The third clause is the most concrete. If you process health data, or data on religion, race, political opinion, sexual orientation, trade union membership or biometrics, the exemption disappears immediately. A clinic, a practice, or any business that asks about a medical situation at intake lands here almost automatically. The same goes for criminal offence data, for instance if you keep screening outcomes or an incident log.
Note the wording of the law itself: the exemption only covers processing that is genuinely occasional and risk-free. It is not a company-wide stamp. In theory a single isolated processing activity could fall under it while the rest of your business remains fully subject to the obligation. In practice that means a record with one line fewer, and nothing saved.
When does the exemption apply, and when does it not?
| What you do in your business | Which clause in paragraph 5 is triggered | Record required? |
|---|---|---|
| You answer customer questions daily by email, WhatsApp or phone | Not occasional | Yes |
| You keep a customer list, quotation list or newsletter list | Not occasional | Yes |
| You run a personnel or payroll administration | Not occasional | Yes |
| You store conversation histories, chat logs or call recordings | Not occasional, and a risk to data subjects | Yes |
| You record health data, for example at intake | Special categories, Article 9 GDPR | Yes |
| You log screening outcomes or incidents of a criminal nature | Criminal offence data, Article 10 GDPR | Yes |
| You let an AI assistant read and answer incoming customer messages | Not occasional, and a risk to data subjects | Yes |
| You send a one-off letter to a list you then destroy, outside any standing process | None of the three, provided it really is a one-off and carries no risk | Possibly not |
The bottom row is the only one where the exemption stands a chance, and even that is fragile: the second time you do that "one-off", it has become a process. So the practical conclusion for almost every small business is this — assume the obligation applies, and put your energy into a good record rather than into proving you do not need one.
What has to be in a record of processing activities?
Article 30(1) lists the minimum content. Translated into everyday business language, it comes down to seven questions you answer per processing activity.
- Who are you? The name and contact details of your business, and of a data protection officer if you have one.
- Why are you doing it? The purpose of the processing. "Answering customer questions" is a purpose. "Marketing" is too vague to be usable.
- Who is it about? The categories of data subjects: customers, prospects, employees, applicants, suppliers.
- Which data? The categories of personal data: name, email address, phone number, order history, message content.
- Who gets to see it? The categories of recipients. Your accounting package, your mail provider, your AI supplier, your hosting company: they all belong here.
- Does it leave the EEA? Transfers to a third country, naming that country and the safeguards you have put in place.
- How long do you keep it and how is it secured? The retention periods, where possible, and a general description of the security measures under Article 32 GDPR.
Two fields cause most of the head-scratching. Retention is one. The Dutch data protection authority offers nothing reassuring here: the starting point is that you do not keep personal data longer than necessary, what is necessary depends on the situation, and therefore you have to determine yourself what is appropriate in your case. No table of numbers is coming. You set the period, and you have to be able to explain it.
The other awkward field is recipients. Many owners only list the parties they receive invoices from. But every service that customer data passes through belongs in there, including free ones and including those that only run in the background.
How detailed does a small company's record have to be?
Far less detailed than most templates suggest. The law prescribes no format. Article 30(3) only requires the record to be in writing, including in electronic form. A spreadsheet qualifies. A text document qualifies. There is no mandatory layout, no mandatory software and no mandatory page count.
What it does have to be is complete and accurate. Article 30(4) says you make the record available to the supervisory authority on request. That is the moment the thing has to prove itself. Two accurate pages beat forty pages of copied model text in which your own situation cannot be found.
A workable measure for a small business: one line per process in which personal data occurs. In most cases that produces a handful of lines. Customer contact and order handling. Invoicing and bookkeeping. Personnel and payroll. Job applications. Newsletter or marketing. Website and cookie data. Camera surveillance, if you have it. A small business rarely has more processes than that.
Do not descend into detail. You do not have to name every individual customer or every field in your database; the law asks for categories. That word is deliberate, and it saves you an enormous amount of work.
What changes in the record once you connect AI to your customer contact?
An AI assistant handling your email, WhatsApp or phone is not a new purpose. You were answering those questions before. What changes is the other fields — and that makes updating your record less of a formality and more the moment you see what is actually happening.
First, a recipient is added. The AI supplier processes customer data on your instructions and is therefore a processor. Article 28 GDPR requires that processing to be governed by a contract that binds the processor to you and that sets out, among other things, the subject matter, duration, nature and purpose of the processing. The Dutch data protection authority stresses that the GDPR requires such a contract from both the controller and the processor, and that both parties are liable if it is missing. So you cannot point at your supplier. In the record, the supplier goes under recipients; the processing agreement itself you keep alongside it.
Second, the transfer field often changes. If the model or the storage sits outside the European Economic Area, that is a transfer to a third country, and that country plus the safeguards belong in the record. This is the field most often left blank with off-the-shelf AI tooling, even though there is something to fill in. Ask your supplier and write down the answer.
Third, the data categories column usually grows. An AI assistant works with the full content of messages, not just a name and address. A conversation about a complaint, an appointment or an order surfaces things you never explicitly designed a field for. And if you retain conversations in order to improve the assistant, that is a purpose of its own with a retention period of its own — a second line in your record, not a footnote to the first.
Finally, updating the record is often the moment another obligation becomes visible. Article 35 GDPR provides that a data protection impact assessment must be carried out prior to the processing where a type of processing, in particular one using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. New technology is named in the text itself. Your record is where you notice this, and the word "prior" means you make that assessment before the assistant goes live.
A record is not a privacy notice, and not a DPIA
These three are often confused, even though they have different audiences and different purposes.
The record of processing activities is internal. It is your own overview, and you show it when the supervisory authority asks for it. It does not go on your website.
The privacy notice is external. You write it for your customers, in plain language, and it follows from the information duties in Articles 13 and 14 GDPR. It draws on the same facts as the record, but it is not a copy of it.
The DPIA under Article 35 GDPR is a risk assessment for one specific processing activity that is likely to be high risk. You do not do one for your whole company, but for the processing that calls for it.
The practical order is: the record first, because that is where you see what you actually do. Then the privacy notice, so that it matches reality. And if the record surfaces a processing activity that calls for a DPIA, then that.
How do you keep the record current without turning it into a project?
The record is not a document you write once. It is a snapshot that only has value while it is current. Three habits keep it alive.
- Tie it to purchasing. Every time you switch on a new tool that customer or personnel data flows through, a line is added or a recipient is appended. Make that a fixed step when you sign up for a subscription, together with requesting the processing agreement.
- Put a date on it. A record without a last-reviewed date cannot be assessed. Walk through it once a year and note when you did.
- Let it be your memory. When a customer asks what data you hold on them, or when something goes wrong and you need to know quickly where their data sits, the record is the one document that answers that in a single go. That is the real return, quite apart from the obligation.
Bear in mind what applies outside the GDPR as well. Customer correspondence can form part of your business administration, and data held by a third party still falls under your own retention duty: if you have your administration kept wholly or partly by third parties, the data those third parties hold about your business must be retained too. Which means "it sits with my supplier" is not an answer — not for tax purposes, and not in your record.
What you can do next
Do not start with a template; start with a list of your own processes. Walk through your week: where does personal data come in, where does it go, where does it stay. Write down the seven points from Article 30(1) for each process. Add the suppliers you use for it, and check whether you have a processing agreement with each of them. Set a retention period per process that you can explain, and write down the reason. If you use or are considering an AI connection, update the record before you switch it on rather than after: that is also exactly the moment Article 35 GDPR asks you whether an impact assessment is needed.
This article is general explanation of what the law says and is not legal advice. Whether a specific processing activity in your business falls under the exemption depends on your own situation; if in doubt, have it checked by a lawyer.