Skip to main content
Start free
Premium

French GDPR Register of Processing Activities (Art. 30)

Template register of processing activities under GDPR Article 30, mandatory from 250 employees or for high-risk processing, compliant with CNIL guidance.

Is the RGPD register mandatory for companies with fewer than 250 employees?

Yes. The Article 30(5) exemption for sub-250-employee organisations is very narrow. It disappears as soon as processing is non-occasional (payroll, customer management, HR), poses a risk to individuals' rights and freedoms, or involves special-category data under Article 9 (health, biometrics, political opinions, religious or philosophical beliefs, trade-union membership) or data on criminal convictions under Article 10. In practice, almost every TPE and PME must maintain a register covering at least their routine processing activities.

Source: CNIL - Les registres RGPD (official page and downloadable template) · updated 2026

About this form

The RGPD (Règlement Général sur la Protection des Données - the French name for the EU General Data Protection Regulation, directly applicable in France) requires every organisation that processes personal data to maintain a formal record of those activities under Article 30. This document is called the registre des activités de traitement (record of processing activities). Many assume the sub-250-employee exemption in Article 30(5) removes this obligation, but the carve-out falls away whenever processing is non-occasional, poses a risk to individuals' rights and freedoms, or involves special-category data under Article 9 (health, biometrics, genetic data, political opinions, religious or philosophical beliefs, trade-union membership) or data on criminal convictions and offences under Article 10. In practice, almost every French business - including TPE and PME (very small and small-to-medium enterprises) - must maintain at least a partial register. The CNIL (Commission Nationale de l'Informatique et des Libertés - France's data-protection authority) publishes a reference template and may demand immediate access to the register during an inspection under Article 30(4).

Worked example

A sports association with 30 employees manages payroll for its staff, a membership database, and a purchased prospect list. Despite falling well below the 250-employee threshold, the payroll processing is non-occasional and HR files contain health-related data (sick-leave records): the association must register at least two processing activities. For payroll, it documents the purpose (payroll management), data categories (civil status, bank details, NIR national identification number, absences), recipients (URSSAF, the provident fund), and retention period. Payroll justification documents are kept for 3 years under the standard URSSAF prescription (Article L244-3 of the Code de la sécurité sociale), extended to 5 years in the event of a tax audit or fraud; salary-claim prescriptions run for 3 years (Article L3245-1 of the Code du travail). In practice the association retains pay slips until each employee's retirement rights are liquidated, in line with CNIL guidance on proving career history.

How to fill out the form

  1. Map all processing activities across your organisation: interview each department (HR, sales, finance, marketing, IT) to list every use of personal data - payroll, customer files, recruitment, CCTV, email marketing, and so on - before attempting to fill in any register entries.
  2. Determine your role for each processing activity: decide whether you are the data controller (responsable de traitement), a processor (sous-traitant) acting for a client, or both. This determines whether you complete the Article 30(1) section, the Article 30(2) section, or separate entries in each.
  3. Document each processing activity with all Article 30 mandatory fields: purpose, categories of data subjects and personal data, recipients, any transfers outside the EU, planned retention periods, and a description of the technical and organisational security measures applied.
  4. Flag high-risk and special-category processing: identify any activities involving Article 9 data (health, biometrics, political opinions, religious or philosophical beliefs, trade-union membership) or Article 10 data (criminal convictions and offences). These entries are mandatory regardless of your employee headcount and may trigger a mandatory AIPD.
  5. Keep the register current: date every entry, update it whenever a new processing activity is introduced or an existing one changes, and store it in a format you can present immediately to the CNIL upon request during an inspection (Article 30(4) obligation).

Good to know

  • The 250-employee threshold is a near-myth: the exemption vanishes the moment processing is regular (payroll, clients, HR) or touches Article 9 special-category data. This covers almost every organisation active in France. Assume you need a register unless a data-protection specialist confirms otherwise.
  • Severe fines apply: up to 10 million euros or 2% of total worldwide annual turnover under Article 83(4) GDPR, whichever is higher. The register is almost always the first document the CNIL requests on inspection - its absence immediately signals non-compliance.
  • If you act as a processor for clients (SaaS provider, outsourced payroll bureau, cloud host), you must maintain a second separate register under Article 30(2) alongside your own controller register. The processor register is one of the most commonly overlooked RGPD compliance requirements.

Frequently asked questions

Is the RGPD register mandatory for companies with fewer than 250 employees?

Yes. The Article 30(5) exemption for sub-250-employee organisations is very narrow. It disappears as soon as processing is non-occasional (payroll, customer management, HR), poses a risk to individuals' rights and freedoms, or involves special-category data under Article 9 (health, biometrics, political opinions, religious or philosophical beliefs, trade-union membership) or data on criminal convictions under Article 10. In practice, almost every TPE and PME must maintain a register covering at least their routine processing activities.

What must the Article 30 register contain?

For each processing activity you must record: the name and contact details of the data controller (and DPO if one is appointed), the purposes of processing, the categories of data subjects and personal data involved, the categories of recipients, any transfers outside the EU, planned retention periods, and a general description of technical and organisational security measures. Processors (sous-traitants - service providers acting on a client's behalf) must keep a separate register of all processing carried out for each client under Article 30(2).

What are the penalties for failing to maintain the register?

Failure to comply with Article 30 falls under the Article 83(4) sanction tier: an administrative fine of up to 10 million euros or 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. The CNIL regularly checks register compliance and it is typically the first document requested during an inspection - its absence immediately signals non-compliance and can accelerate enforcement action.

What is the difference between the controller's register and the processor's register?

The data controller (responsable de traitement - the entity that determines the purposes of processing) records activities carried out under its own authority under Article 30(1). A processor (sous-traitant - a service provider such as a payroll bureau, SaaS vendor or hosting provider) keeps a separate register of processing categories performed for each client under Article 30(2). The same organisation can hold both roles simultaneously and must maintain both register sections separately.

Does the CNIL provide an official register template?

Yes. The CNIL publishes a downloadable spreadsheet template for organisations whose processing activities are limited in number and low in risk, covering all mandatory Article 30 fields. For more complex or sensitive processing the template must be supplemented, and a data-protection impact assessment (AIPD - analyse d'impact relative à la protection des données) may be required. The template is available on the CNIL's dedicated register page at cnil.fr.

Must the register be submitted to the CNIL?

No. The register is an internal compliance management document; it is not filed with or proactively sent to the CNIL. However, under Article 30(4) it must be kept up to date and made available immediately upon request during an inspection. It must be maintained in writing, which includes electronic format such as a spreadsheet or dedicated compliance software.

Updated on 2026-06-27

A question about this form?

Ask Solva, ActioFin's AI finance advisor — answers sourced from official texts.

5 free questions per day with a free account

Ask Solva

Related forms

French GDPR Register of Processing Activities (Art. 30)