Insight
Records of processing and DPIAs for marketing and sales systems: the GDPR paperwork that actually helps
Two GDPR obligations are often treated as bureaucracy: the record of processing activities and the data protection impact assessment. Done properly, they are the map of where customer data goes and the moment to catch risky designs before a new CRM, tracking setup or AI tool goes live.
Records of processing activities
Article 30 of the GDPR requires controllers to maintain a record of processing activities under their responsibility. Processors, such as agencies or software providers processing data on behalf of clients, must keep their own record of processing carried out for each controller.
The record is not a privacy notice for the public. It is an internal document that the supervisory authority can request, and it gives the organisation an overview of what personal data it processes, why, where it goes and how long it is kept.
- Controller details
- Name and contact details of the controller, any joint controller, representative and data protection officer.
- Purposes
- Why the data is processed, such as lead management, newsletters, customer support or recruitment.
- Categories
- Categories of data subjects, such as leads, customers or applicants, and of personal data.
- Recipients
- Categories of recipients, including service providers and group companies.
- Transfers
- Transfers to third countries and the safeguards used.
- Retention
- Where possible, the envisaged time limits for erasure.
- Security
- Where possible, a general description of technical and organisational security measures.
The small business exemption is narrower than it looks
Article 30 includes an exemption for organisations with fewer than 250 employees. It does not apply if the processing is likely to result in a risk to rights and freedoms, is not occasional, or includes special categories of data or data relating to criminal convictions and offences.
Most businesses process customer, lead and employee data continuously, which is not occasional. Supervisory authorities have therefore pointed out that many small and medium-sized organisations still need records at least for their regular processing activities, even if the exemption covers occasional ones.
In practice, maintaining a record is also the easiest way to answer data subject requests, prepare privacy notices and respond to customers’ security questionnaires, so small companies benefit from it regardless of the exemption.
What marketing and sales records should cover
Marketing and sales functions typically involve many processing activities and tools. A useful record describes activities by purpose and lists the systems involved, rather than listing tools without context.
Common entries include website analytics, advertising and retargeting, newsletter and marketing automation, lead capture and CRM, sales outreach, event registrations, webinars, customer reviews, social media management, chat and messaging, and customer support. Each entry names the systems, the data involved, the lawful basis, the recipients such as software providers, transfers outside the EEA and retention periods.
Keep the record current. A record created once for a compliance project and never updated becomes misleading as new tools are adopted, integrations change and retention rules evolve.
Data protection impact assessments
Article 35 requires a data protection impact assessment, or DPIA, before processing that is likely to result in a high risk to individuals’ rights and freedoms, particularly when using new technologies. The GDPR names examples: systematic and extensive evaluation of personal aspects based on automated processing, including profiling, that produces legal or similarly significant effects; large-scale processing of special categories of data; and systematic monitoring of publicly accessible areas on a large scale.
European data protection authorities have published guidance with criteria indicating high risk, such as evaluation or scoring, automated decisions with significant effects, systematic monitoring, sensitive data, large-scale processing, matching or combining data sets, vulnerable data subjects, innovative technology and processing that prevents people exercising rights or using a service. Processing meeting two or more criteria is generally expected to require a DPIA. National authorities also publish lists of processing operations that require one.
When marketing projects may need a DPIA
Not every CRM or newsletter tool needs a DPIA. Projects deserve closer assessment when they combine data from many sources to profile individuals, use automated scoring to decide which customers receive offers or prices, process health or other sensitive data such as for clinics or insurance, track behaviour extensively across websites and apps, or introduce AI tools that analyse customer conversations or generate decisions about individuals.
A DPIA describes the processing, assesses necessity and proportionality, identifies risks to individuals and sets out measures to address them. If high risk remains after mitigation, the controller must consult the supervisory authority before starting.
The most valuable moment for a DPIA is during design, when choices about data minimisation, retention, access controls and vendor selection can still be changed cheaply.
Making it practical
Keep the record in a structured format that marketing, sales and IT can update, whether a spreadsheet, a privacy management tool or the organisation’s wiki. Link procurement and tool adoption to the record, so a new system cannot go live without an entry and, where needed, a DPIA screening.
Use a short screening questionnaire for new projects to decide whether a full DPIA is needed, and document the decision either way. This article is a general overview and not legal advice.
Questions
What is a record of processing activities?
An internal GDPR document listing processing activities with purposes, data categories, recipients, transfers, retention and security measures.
Do companies with fewer than 250 employees need records?
Often yes, because the exemption does not apply to processing that is not occasional, is risky or involves special categories of data.
Do processors need records too?
Yes. Processors must keep records of processing carried out on behalf of each controller.
What is a DPIA?
A data protection impact assessment required before processing likely to result in high risk to individuals.
Does a new CRM need a DPIA?
Not necessarily. It depends on factors such as profiling, sensitive data, scale, data combination and automated decisions.
What if high risk remains after a DPIA?
The controller must consult the supervisory authority before starting the processing.
When should a DPIA be done?
Before processing begins, ideally during design when changes are still easy.
Where this sits in what we do
This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.
- Marketing Automation — CRM, lead capture and automated follow-up built as one system — so nothing arrives in an inbox and nothing depends on someone remembering.
- The EU AI Act: what actually applies from 2 August 2026
- Belgium's B2B e-invoicing mandate: the January 2026 big bang
- Candidate experience for recruitment agencies: the pipeline clients never see
- Saudi Arabia’s Personal Data Protection Law: what marketing teams need to change
- All insight articles
Do you know where your customer data goes?
We map marketing and sales systems, build maintainable records of processing and help design new projects with privacy risks addressed early.
Get in touch