Insight

Records of processing and DPIAs for marketing and sales systems: the GDPR paperwork that actually helps

Two GDPR obligations are often treated as bureaucracy: the record of processing activities and the data protection impact assessment. Done properly, they are the map of where customer data goes and the moment to catch risky designs before a new CRM, tracking setup or AI tool goes live.

Published by Somnium Digital

A wireframe of the Insight page: headline, supporting sections and a single call to action. Insight Records of processing and DPIAs Get in touch 01 Records of processing… 02 The small business ex… 03 What marketing and sa…

Records of processing activities

Article 30 of the GDPR requires controllers to maintain a record of processing activities under their responsibility. Processors, such as agencies or software providers processing data on behalf of clients, must keep their own record of processing carried out for each controller.

The record is not a privacy notice for the public. It is an internal document that the supervisory authority can request, and it gives the organisation an overview of what personal data it processes, why, where it goes and how long it is kept.

Controller details
Name and contact details of the controller, any joint controller, representative and data protection officer.
Purposes
Why the data is processed, such as lead management, newsletters, customer support or recruitment.
Categories
Categories of data subjects, such as leads, customers or applicants, and of personal data.
Recipients
Categories of recipients, including service providers and group companies.
Transfers
Transfers to third countries and the safeguards used.
Retention
Where possible, the envisaged time limits for erasure.
Security
Where possible, a general description of technical and organisational security measures.

The small business exemption is narrower than it looks

Article 30 includes an exemption for organisations with fewer than 250 employees. It does not apply if the processing is likely to result in a risk to rights and freedoms, is not occasional, or includes special categories of data or data relating to criminal convictions and offences.

Most businesses process customer, lead and employee data continuously, which is not occasional. Supervisory authorities have therefore pointed out that many small and medium-sized organisations still need records at least for their regular processing activities, even if the exemption covers occasional ones.

In practice, maintaining a record is also the easiest way to answer data subject requests, prepare privacy notices and respond to customers’ security questionnaires, so small companies benefit from it regardless of the exemption.

What marketing and sales records should cover

Marketing and sales functions typically involve many processing activities and tools. A useful record describes activities by purpose and lists the systems involved, rather than listing tools without context.

Common entries include website analytics, advertising and retargeting, newsletter and marketing automation, lead capture and CRM, sales outreach, event registrations, webinars, customer reviews, social media management, chat and messaging, and customer support. Each entry names the systems, the data involved, the lawful basis, the recipients such as software providers, transfers outside the EEA and retention periods.

Keep the record current. A record created once for a compliance project and never updated becomes misleading as new tools are adopted, integrations change and retention rules evolve.

Data protection impact assessments

Article 35 requires a data protection impact assessment, or DPIA, before processing that is likely to result in a high risk to individuals’ rights and freedoms, particularly when using new technologies. The GDPR names examples: systematic and extensive evaluation of personal aspects based on automated processing, including profiling, that produces legal or similarly significant effects; large-scale processing of special categories of data; and systematic monitoring of publicly accessible areas on a large scale.

European data protection authorities have published guidance with criteria indicating high risk, such as evaluation or scoring, automated decisions with significant effects, systematic monitoring, sensitive data, large-scale processing, matching or combining data sets, vulnerable data subjects, innovative technology and processing that prevents people exercising rights or using a service. Processing meeting two or more criteria is generally expected to require a DPIA. National authorities also publish lists of processing operations that require one.

When marketing projects may need a DPIA

Not every CRM or newsletter tool needs a DPIA. Projects deserve closer assessment when they combine data from many sources to profile individuals, use automated scoring to decide which customers receive offers or prices, process health or other sensitive data such as for clinics or insurance, track behaviour extensively across websites and apps, or introduce AI tools that analyse customer conversations or generate decisions about individuals.

A DPIA describes the processing, assesses necessity and proportionality, identifies risks to individuals and sets out measures to address them. If high risk remains after mitigation, the controller must consult the supervisory authority before starting.

The most valuable moment for a DPIA is during design, when choices about data minimisation, retention, access controls and vendor selection can still be changed cheaply.

Making it practical

Keep the record in a structured format that marketing, sales and IT can update, whether a spreadsheet, a privacy management tool or the organisation’s wiki. Link procurement and tool adoption to the record, so a new system cannot go live without an entry and, where needed, a DPIA screening.

Use a short screening questionnaire for new projects to decide whether a full DPIA is needed, and document the decision either way. This article is a general overview and not legal advice.

Questions

What is a record of processing activities?

An internal GDPR document listing processing activities with purposes, data categories, recipients, transfers, retention and security measures.

Do companies with fewer than 250 employees need records?

Often yes, because the exemption does not apply to processing that is not occasional, is risky or involves special categories of data.

Do processors need records too?

Yes. Processors must keep records of processing carried out on behalf of each controller.

What is a DPIA?

A data protection impact assessment required before processing likely to result in high risk to individuals.

Does a new CRM need a DPIA?

Not necessarily. It depends on factors such as profiling, sensitive data, scale, data combination and automated decisions.

What if high risk remains after a DPIA?

The controller must consult the supervisory authority before starting the processing.

When should a DPIA be done?

Before processing begins, ideally during design when changes are still easy.

Where this sits in what we do

This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.

Do you know where your customer data goes?

We map marketing and sales systems, build maintainable records of processing and help design new projects with privacy risks addressed early.

Get in touch

Tell us what you are trying to change

Describe the problem rather than the service — the two frequently differ, and working out which is which is the useful part of a first conversation. We reply within one working day, and if it is outside what we do well you will hear that in the reply rather than after a call.

We use what you send to reply to you. Nothing else, and no list.

WhatsApp