Dieter
← All articlesData protection explained

Record of processing activities and deletion concept: mandatory content under Art. 30 GDPR, deletion periods and structure

The record of processing activities is the first document a supervisory authority wants to see, the deletion concept the second. This guide explains who has to keep a record (almost everyone, despite the 250-employee exemption), which details Art. 30 GDPR requires, which retention periods determine the deletion periods and how to link the two so that they work in everyday business.

Sebastian SchenkLegally reviewed by Franziska Breidenbach
Last reviewed: Thursday, 17 September 2026
Record of processing activities and deletion concept: mandatory content under Art. 30 GDPR, deletion periods and structure

Table of contents

  1. In short
  2. Why the record and the deletion concept belong together
  3. Who has to keep a record of processing activities?
  4. The mandatory content under Art. 30 GDPR
  5. Typical processing activities in a small business
  6. The deletion concept: structure based on ISO/IEC 27555
  7. Retention obligations that determine the deletion periods
  8. Deletion in practice: backups, cloud tools and paper
  9. Linking the record and the deletion concept in everyday business
  10. The most common mistakes
  11. When the authority asks for the record
  12. Record and deletion concept with Dieter
  13. Conclusion

In short

  • The record of processing activities (RoPA) is mandatory for almost every business. The exemption for organisations with fewer than 250 employees in Art. 30(5) GDPR practically never applies, because HR and customer data are processed on more than an “occasional” basis.
  • The RoPA is the map, the deletion concept the rulebook that goes with it. For every processing activity, the record has to state a deletion period (Art. 30(1)(f)). The deletion concept defines how those periods are actually put into practice.
  • Deletion periods follow from retention obligations. Accounting records 8 years, commercial letters 6 years, annual financial statements 10 years, applicant data a few months. If you know these periods, you have 80 per cent of your deletion concept.
  • Both are living documents. Every new service, every new form, every new process is an entry. A record from 2019 is a violation today.

Why the record and the deletion concept belong together

The record of processing activities under Art. 30 GDPR documents which personal data your business processes for which purpose, who receives it and how long it is stored. The deletion concept implements that last point: it defines, for every type of data, when and how it is deleted, and makes sure that this actually happens. The principle behind it is storage limitation under Art. 5(1)(e) GDPR: data may only be stored in identifiable form for as long as it is necessary for the purpose. And because Art. 5(2) requires you to be able to demonstrate compliance with all the principles, you need both in writing.

In practice, the record is also the backbone of all your other data protection documents. The privacy policy is the public-facing presentation of the website processing activities listed in the record. The data processing agreements belong to the recipients named in the record. The technical and organisational measures are required as a general description under Art. 30(1)(g). If you keep the record properly, half of the rest is already done.

Who has to keep a record of processing activities?

In principle, every controller and every processor (Art. 30(1) and (2) GDPR). Art. 30(5) exempts organisations with fewer than 250 employees, but only if none of the three exceptions to the exemption applies: the processing poses a risk to the rights and freedoms of data subjects, it is not merely occasional, or it includes special categories of data under Art. 9 (health, religion, trade union membership) or data relating to criminal offences under Art. 10.

The second exception is the reason why the 250 threshold is meaningless in practice. HR data, customer data, supplier data and the operation of a website are processed permanently and regularly, in other words on more than an occasional basis. The German Data Protection Conference (DSK) makes clear in its short paper no. 1 that the exemption only applies to individual processing operations that are genuinely occasional, not to the business as a whole. The result: even a two-person business needs the record, at least for HR, customers and website.

The mandatory content under Art. 30 GDPR

The record consists of a general part with the details of the organisation and one entry per processing activity. Art. 30(1) requires the following from controllers:

LetterMandatory detailExample
aName and contact details of the controller and, where applicable, of the representative and the data protection officerExample Ltd, address, email; DPO: [email protected]
bPurposes of the processingPayroll, customer support, newsletter distribution, applicant selection
cCategories of data subjects and categories of personal dataEmployees: master data, salary, sick leave; customers: contact details, order history, payment data
dCategories of recipientsTax adviser, payroll provider, hosting provider, social insurance institutions, tax office
eTransfers to third countries and the safeguards for themUSA: newsletter provider under the EU-US Data Privacy Framework
fEnvisaged time limits for erasure, where possibleApplicant data: 6 months after rejection; accounting records: 8 years after the end of the calendar year
gGeneral description of the technical and organisational measures, where possibleReference to the TOM document, version and date

Under paragraph 2, processors keep their own record with the categories of processing carried out on behalf of each client, third-country transfers and TOM. Anyone who is both, such as an agency with its own customers, keeps both parts. The record must be in writing, an electronic format is sufficient (paragraph 3), and it has to be made available to the supervisory authority on request (paragraph 4). It is not a public document and does not need to go on your website.

Typical processing activities in a small business

The hardest question when drawing up the first record is how to cut it: what counts as a processing activity? The approach that has proven itself is to structure the record by business process, not by system. “CRM software” is not an entry, “customer support and sales” is, and the software appears in it as a means. A business with 10 to 50 employees typically ends up with 12 to 20 entries:

Processing activityLegal basis (typical)Deletion period (guide value)
HR administration and payrollArt. 6(1)(b), (c) GDPR, § 26 BDSGPayroll account 6 years (§ 41 EStG), personnel file 3 years after leaving, social insurance records up to 10 years
Applicant managementArt. 6(1)(b) GDPR, § 26 BDSGUp to 6 months after rejection (periods under § 15(4) AGG and § 61b ArbGG), longer only with consent for a talent pool
Customer management, quotes, contractsArt. 6(1)(b) GDPRContract data 3 years after the end of the year in which the contract ended (§ 195, § 199 BGB), invoices 8 or 10 years
Bookkeeping and accountingArt. 6(1)(c) GDPRAccounting records 8 years, books and annual financial statements 10 years (§ 147 AO, § 257 HGB)
Supplier and service provider managementArt. 6(1)(b) GDPRSame as customer data
Website operation and server log filesArt. 6(1)(f) GDPRLog files 7 to 14 days
Contact enquiries and customer serviceArt. 6(1)(b) or (f) GDPRAfter the matter is closed, at the latest after 12 months, unless a contract follows
Newsletter and marketingArt. 6(1)(a) GDPRUntil withdrawal; proof of consent 3 years after withdrawal
Web analytics and consent managementArt. 6(1)(a) GDPR, § 25 TDDDGDepends on the provider, typically 14 months; consent records 12 months
Video surveillanceArt. 6(1)(f) GDPRUsually 48 to 72 hours, longer only in the event of a specific incident
Time recording and access controlArt. 6(1)(c), (f) GDPR, § 26 BDSGWorking time records 2 years (§ 16 ArbZG), access logs a few weeks
Data protection organisation (requests, data breaches, training)Art. 6(1)(c) GDPRDocumentation of data breaches and requests 3 years, training records for the duration of employment

The deletion concept: structure based on ISO/IEC 27555

There is an international standard for deletion concepts: ISO/IEC 27555, into which the German DIN 66398 has been absorbed. You do not need to buy it to use its method. It consists of five steps that work for a small business too:

  1. 1Define the types of data. Which groups of data are there? Customer master data, invoice data, application documents, log files, newsletter addresses. The data types come straight from the record of processing activities.
  2. 2Form deletion classes. Every deletion class has a standard period and a starting point. Examples: “6 months after rejection” (applicants), “8 years after the end of the calendar year in which the invoice was issued” (accounting records), “immediately after withdrawal” (newsletter). Six to eight classes are usually enough for all data types.
  3. 3Formulate deletion rules. For every data type: which deletion class applies, what triggers the starting point, who is responsible, in which system the data type is held, how it is deleted (physically, anonymised, blocked).
  4. 4Organise implementation. Automatic deletion runs wherever the system supports them (CRM, newsletter tool, applicant management). Manual deletion dates in the calendar where it does not. Paper goes through document destruction in line with DIN 66399.
  5. 5Keep evidence. A deletion log for every deletion run: date, data type, number of records or period covered, who did it. That is the proof under Art. 5(2) that the authority wants to see.

Retention obligations that determine the deletion periods

You may only delete once no statutory retention obligation stands in the way (Art. 17(3)(b) GDPR). The most important periods for German businesses, each counted from the end of the calendar year in which the document was created:

DocumentPeriodLegal basis
Books, records, inventories, annual financial statements, management reports, opening balance sheet10 years§ 147(3) of the German Fiscal Code (AO), § 257(4) of the German Commercial Code (HGB)
Accounting records (invoices, receipts, bank statements)8 years (since 2025, previously 10 years)§ 147(3) AO, § 257(4) HGB as amended by the Fourth Bureaucracy Relief Act
Commercial and business letters received and sent, other tax-relevant documents6 years§ 147(3) AO, § 257(4) HGB
Payroll accounts and payroll records6 years after the last entry§ 41(1) of the German Income Tax Act (EStG)
Working time records2 years§ 16(2) of the German Working Hours Act (ArbZG)
Application documents after rejectionUp to 6 monthsPeriod for asserting claims under § 15(4) of the German General Equal Treatment Act (AGG) plus period for filing a claim under § 61b of the German Labour Court Act (ArbGG)
Contract data after the end of the contract3 years from the end of the year (standard limitation period)§ 195, § 199 of the German Civil Code (BGB)

During the retention period, you may no longer actively use the data. The GDPR calls this restriction of processing (Art. 18): the invoice stays in the archive, but the customer disappears from the marketing list. Technically, this means blocking rather than deleting, and that belongs in the deletion concept too.

Deletion in practice: backups, cloud tools and paper

  • Backups. Data in backup copies does not have to be deleted immediately if that would be technically disproportionate. The deletion concept must, however, ensure that backups are overwritten after their cycle and that deleted data does not find its way back into the production system after a restore. Document the backup cycle as a deletion period.
  • Cloud and SaaS tools. Deleting something in your own account does not mean it is deleted at the provider. The data processing agreement stipulates under Art. 28(3)(g) that data is deleted at the end of the contract. For ongoing contracts, check the retention settings of the tool; many CRM and newsletter providers have their own automatic deletion features.
  • Anonymisation as an alternative. If you want to keep data for statistics, anonymise it so that no link to a person can be restored. The processing then falls outside the GDPR. Pseudonymisation is not enough for this.
  • Paper. Personnel files, application folders and paper invoices are covered by the deletion concept just the same. Destruction in line with DIN 66399, at least security level P-4 for personal data and P-5 for sensitive data. Proof comes from the destruction service provider, with whom a DPA is in place.
  • Email mailboxes. The classic forgotten data store. The rule: business-relevant emails are transferred to the document management system, the rest is deleted after a fixed period. Mailboxes of employees who have left are shut down after a transition period of a few weeks.

Linking the record and the deletion concept in everyday business

Both documents rarely fail at the drafting stage; they almost always fail at maintenance. Three rules that have proven themselves:

  1. 1Every new service is an entry. Before a new tool, form or service provider goes live, the processing activity goes into the record, with a deletion period and, where needed, a DPA. Anyone who does it the other way round never catches up.
  2. 2Quarterly review. 30 minutes: have new processes been added, have tools been switched, are the recipients still correct? The change history is updated.
  3. 3Annual deletion run with a log. For all data types that are not deleted automatically: a fixed date on which applicant data, old customer contacts and expired records are deleted and the deletion is documented.

The most common mistakes

  • Record structured by systems instead of processes. “Microsoft 365” as a processing activity says nothing about purpose, data subjects or period.
  • Deletion period “as long as necessary”. That is not a period. Art. 30(1)(f) requires a specific figure wherever one is possible.
  • No starting point. “3 years” without saying from when. From the end of the contract? From the last invoice? From the end of the year?
  • Deletion concept without implementation. The document says “6 months”, the applicant tool still holds documents from 2021.
  • Backups forgotten. The deletion rule applies in the production system, the backup from three years ago still contains everything.
  • No evidence. Data was deleted, but nobody can say when or what. Without a log, the authority treats the deletion as if it had not happened.

When the authority asks for the record

Art. 30(4) GDPR obliges you to make the record available to the supervisory authority on request. In practice, it is the first document requested after a complaint, a data breach or during a routine audit, usually with a deadline of two to four weeks. A missing or incomplete record falls within the fine range of up to 10 million euros or 2 per cent of worldwide annual turnover (Art. 83(4)(a)). More important than the fine, though, is the effect: a clean record ends many audits right there, because it shows that data protection is organised.

Record and deletion concept with Dieter

Dieter creates the record of processing activities from a guided questionnaire, with pre-built processing activities for the typical processes of a small business, suggested deletion periods and links to the data processing agreements and TOM. The starting point is the GDPR Check-up, which shows you which processing activities and documents you are missing. You can find all prices under Pricing.

Conclusion

The record of processing activities is the inventory of your data protection, the deletion concept the house rules that go with it. Both are mandatory for almost every business, and both can be set up in an afternoon if you structure them by process and take the statutory retention periods as your starting point. What counts after that is routine: new service, new entry, delete and log once a year.

Author

Sebastian Schenk

Co-Founder & CEO

Lawyer and data protection officer. Drives product vision at simply Legal and ensures Dieter is sound legally and in practice.

Sources and further reading

Frequently asked questions

Do I really have to keep a record of processing activities as a small business?

Yes, in almost all cases. The exemption for organisations with fewer than 250 employees in Art. 30(5) GDPR only applies if the processing is merely occasional, poses no risk and does not involve sensitive data. HR, customer and website data are processed on a permanent basis, so the exemption does not apply to those areas. That is why even a sole trader needs a record, even if it is a short one.

Does the record of processing activities have to be published?

No. It is an internal document that only has to be made available to the supervisory authority on request (Art. 30(4) GDPR). Data subjects have no right to inspect the record, but they do have a right of access to their own data under Art. 15 GDPR.

How long may I keep application documents?

After a rejection, usually up to six months. The period follows from the possibility that rejected applicants assert claims under the German General Equal Treatment Act (AGG): two months for asserting the claim (§ 15(4) AGG) and three months for filing a claim in court (§ 61b of the German Labour Court Act, ArbGG), plus a buffer for service of documents. Longer only with express consent, for instance for a talent pool.

How long do invoices have to be kept?

Since 1 January 2025, eight years instead of ten, counted from the end of the calendar year in which the invoice was issued (§ 147(3) of the German Fiscal Code (AO) and § 257(4) of the German Commercial Code (HGB) following the Fourth Bureaucracy Relief Act). For books, inventories and annual financial statements, it remains ten years.

Do I have to delete data from backups too?

Not immediately, if that would be technically disproportionate. The deletion concept must, however, define the cycle after which backups are overwritten and ensure that deleted data does not end up back in the production system after a restore. The backup cycle is documented as a deletion period in its own right.

What is the difference between deleting, blocking and anonymising?

Deleting removes the data irretrievably. Blocking, called restriction of processing under Art. 18 GDPR, keeps the data for retention obligations but withdraws it from active use. Anonymising permanently removes the link to a person, so that the GDPR no longer applies and the data may be kept for statistics. Pseudonymised data, by contrast, is still personal data.

This article reflects the position at the date of publication. We update our content when the law changes.

Related articles

Dieter helps you avoid fines

Ready to go

Dieter takes care of your data protection.

Get started without a demo call and set up your data protection in a few steps.

Get started