Record of processing activities and deletion concept: mandatory content under Art. 30 GDPR, deletion periods and structure
The record of processing activities is the first document a supervisory authority wants to see, the deletion concept the second. This guide explains who has to keep a record (almost everyone, despite the 250-employee exemption), which details Art. 30 GDPR requires, which retention periods determine the deletion periods and how to link the two so that they work in everyday business.

Table of contents
- In short
- Why the record and the deletion concept belong together
- Who has to keep a record of processing activities?
- The mandatory content under Art. 30 GDPR
- Typical processing activities in a small business
- The deletion concept: structure based on ISO/IEC 27555
- Retention obligations that determine the deletion periods
- Deletion in practice: backups, cloud tools and paper
- Linking the record and the deletion concept in everyday business
- The most common mistakes
- When the authority asks for the record
- Record and deletion concept with Dieter
- Conclusion
In short
- The record of processing activities (RoPA) is mandatory for almost every business. The exemption for organisations with fewer than 250 employees in Art. 30(5) GDPR practically never applies, because HR and customer data are processed on more than an “occasional” basis.
- The RoPA is the map, the deletion concept the rulebook that goes with it. For every processing activity, the record has to state a deletion period (Art. 30(1)(f)). The deletion concept defines how those periods are actually put into practice.
- Deletion periods follow from retention obligations. Accounting records 8 years, commercial letters 6 years, annual financial statements 10 years, applicant data a few months. If you know these periods, you have 80 per cent of your deletion concept.
- Both are living documents. Every new service, every new form, every new process is an entry. A record from 2019 is a violation today.
Why the record and the deletion concept belong together
The record of processing activities under Art. 30 GDPR documents which personal data your business processes for which purpose, who receives it and how long it is stored. The deletion concept implements that last point: it defines, for every type of data, when and how it is deleted, and makes sure that this actually happens. The principle behind it is storage limitation under Art. 5(1)(e) GDPR: data may only be stored in identifiable form for as long as it is necessary for the purpose. And because Art. 5(2) requires you to be able to demonstrate compliance with all the principles, you need both in writing.
In practice, the record is also the backbone of all your other data protection documents. The privacy policy is the public-facing presentation of the website processing activities listed in the record. The data processing agreements belong to the recipients named in the record. The technical and organisational measures are required as a general description under Art. 30(1)(g). If you keep the record properly, half of the rest is already done.
Who has to keep a record of processing activities?
In principle, every controller and every processor (Art. 30(1) and (2) GDPR). Art. 30(5) exempts organisations with fewer than 250 employees, but only if none of the three exceptions to the exemption applies: the processing poses a risk to the rights and freedoms of data subjects, it is not merely occasional, or it includes special categories of data under Art. 9 (health, religion, trade union membership) or data relating to criminal offences under Art. 10.
The second exception is the reason why the 250 threshold is meaningless in practice. HR data, customer data, supplier data and the operation of a website are processed permanently and regularly, in other words on more than an occasional basis. The German Data Protection Conference (DSK) makes clear in its short paper no. 1 that the exemption only applies to individual processing operations that are genuinely occasional, not to the business as a whole. The result: even a two-person business needs the record, at least for HR, customers and website.
The mandatory content under Art. 30 GDPR
The record consists of a general part with the details of the organisation and one entry per processing activity. Art. 30(1) requires the following from controllers:
| Letter | Mandatory detail | Example |
|---|---|---|
| a | Name and contact details of the controller and, where applicable, of the representative and the data protection officer | Example Ltd, address, email; DPO: [email protected] |
| b | Purposes of the processing | Payroll, customer support, newsletter distribution, applicant selection |
| c | Categories of data subjects and categories of personal data | Employees: master data, salary, sick leave; customers: contact details, order history, payment data |
| d | Categories of recipients | Tax adviser, payroll provider, hosting provider, social insurance institutions, tax office |
| e | Transfers to third countries and the safeguards for them | USA: newsletter provider under the EU-US Data Privacy Framework |
| f | Envisaged time limits for erasure, where possible | Applicant data: 6 months after rejection; accounting records: 8 years after the end of the calendar year |
| g | General description of the technical and organisational measures, where possible | Reference to the TOM document, version and date |
Under paragraph 2, processors keep their own record with the categories of processing carried out on behalf of each client, third-country transfers and TOM. Anyone who is both, such as an agency with its own customers, keeps both parts. The record must be in writing, an electronic format is sufficient (paragraph 3), and it has to be made available to the supervisory authority on request (paragraph 4). It is not a public document and does not need to go on your website.
Typical processing activities in a small business
The hardest question when drawing up the first record is how to cut it: what counts as a processing activity? The approach that has proven itself is to structure the record by business process, not by system. “CRM software” is not an entry, “customer support and sales” is, and the software appears in it as a means. A business with 10 to 50 employees typically ends up with 12 to 20 entries:
| Processing activity | Legal basis (typical) | Deletion period (guide value) |
|---|---|---|
| HR administration and payroll | Art. 6(1)(b), (c) GDPR, § 26 BDSG | Payroll account 6 years (§ 41 EStG), personnel file 3 years after leaving, social insurance records up to 10 years |
| Applicant management | Art. 6(1)(b) GDPR, § 26 BDSG | Up to 6 months after rejection (periods under § 15(4) AGG and § 61b ArbGG), longer only with consent for a talent pool |
| Customer management, quotes, contracts | Art. 6(1)(b) GDPR | Contract data 3 years after the end of the year in which the contract ended (§ 195, § 199 BGB), invoices 8 or 10 years |
| Bookkeeping and accounting | Art. 6(1)(c) GDPR | Accounting records 8 years, books and annual financial statements 10 years (§ 147 AO, § 257 HGB) |
| Supplier and service provider management | Art. 6(1)(b) GDPR | Same as customer data |
| Website operation and server log files | Art. 6(1)(f) GDPR | Log files 7 to 14 days |
| Contact enquiries and customer service | Art. 6(1)(b) or (f) GDPR | After the matter is closed, at the latest after 12 months, unless a contract follows |
| Newsletter and marketing | Art. 6(1)(a) GDPR | Until withdrawal; proof of consent 3 years after withdrawal |
| Web analytics and consent management | Art. 6(1)(a) GDPR, § 25 TDDDG | Depends on the provider, typically 14 months; consent records 12 months |
| Video surveillance | Art. 6(1)(f) GDPR | Usually 48 to 72 hours, longer only in the event of a specific incident |
| Time recording and access control | Art. 6(1)(c), (f) GDPR, § 26 BDSG | Working time records 2 years (§ 16 ArbZG), access logs a few weeks |
| Data protection organisation (requests, data breaches, training) | Art. 6(1)(c) GDPR | Documentation of data breaches and requests 3 years, training records for the duration of employment |
The deletion concept: structure based on ISO/IEC 27555
There is an international standard for deletion concepts: ISO/IEC 27555, into which the German DIN 66398 has been absorbed. You do not need to buy it to use its method. It consists of five steps that work for a small business too:
- 1Define the types of data. Which groups of data are there? Customer master data, invoice data, application documents, log files, newsletter addresses. The data types come straight from the record of processing activities.
- 2Form deletion classes. Every deletion class has a standard period and a starting point. Examples: “6 months after rejection” (applicants), “8 years after the end of the calendar year in which the invoice was issued” (accounting records), “immediately after withdrawal” (newsletter). Six to eight classes are usually enough for all data types.
- 3Formulate deletion rules. For every data type: which deletion class applies, what triggers the starting point, who is responsible, in which system the data type is held, how it is deleted (physically, anonymised, blocked).
- 4Organise implementation. Automatic deletion runs wherever the system supports them (CRM, newsletter tool, applicant management). Manual deletion dates in the calendar where it does not. Paper goes through document destruction in line with DIN 66399.
- 5Keep evidence. A deletion log for every deletion run: date, data type, number of records or period covered, who did it. That is the proof under Art. 5(2) that the authority wants to see.
Retention obligations that determine the deletion periods
You may only delete once no statutory retention obligation stands in the way (Art. 17(3)(b) GDPR). The most important periods for German businesses, each counted from the end of the calendar year in which the document was created:
| Document | Period | Legal basis |
|---|---|---|
| Books, records, inventories, annual financial statements, management reports, opening balance sheet | 10 years | § 147(3) of the German Fiscal Code (AO), § 257(4) of the German Commercial Code (HGB) |
| Accounting records (invoices, receipts, bank statements) | 8 years (since 2025, previously 10 years) | § 147(3) AO, § 257(4) HGB as amended by the Fourth Bureaucracy Relief Act |
| Commercial and business letters received and sent, other tax-relevant documents | 6 years | § 147(3) AO, § 257(4) HGB |
| Payroll accounts and payroll records | 6 years after the last entry | § 41(1) of the German Income Tax Act (EStG) |
| Working time records | 2 years | § 16(2) of the German Working Hours Act (ArbZG) |
| Application documents after rejection | Up to 6 months | Period for asserting claims under § 15(4) of the German General Equal Treatment Act (AGG) plus period for filing a claim under § 61b of the German Labour Court Act (ArbGG) |
| Contract data after the end of the contract | 3 years from the end of the year (standard limitation period) | § 195, § 199 of the German Civil Code (BGB) |
During the retention period, you may no longer actively use the data. The GDPR calls this restriction of processing (Art. 18): the invoice stays in the archive, but the customer disappears from the marketing list. Technically, this means blocking rather than deleting, and that belongs in the deletion concept too.
Deletion in practice: backups, cloud tools and paper
- Backups. Data in backup copies does not have to be deleted immediately if that would be technically disproportionate. The deletion concept must, however, ensure that backups are overwritten after their cycle and that deleted data does not find its way back into the production system after a restore. Document the backup cycle as a deletion period.
- Cloud and SaaS tools. Deleting something in your own account does not mean it is deleted at the provider. The data processing agreement stipulates under Art. 28(3)(g) that data is deleted at the end of the contract. For ongoing contracts, check the retention settings of the tool; many CRM and newsletter providers have their own automatic deletion features.
- Anonymisation as an alternative. If you want to keep data for statistics, anonymise it so that no link to a person can be restored. The processing then falls outside the GDPR. Pseudonymisation is not enough for this.
- Paper. Personnel files, application folders and paper invoices are covered by the deletion concept just the same. Destruction in line with DIN 66399, at least security level P-4 for personal data and P-5 for sensitive data. Proof comes from the destruction service provider, with whom a DPA is in place.
- Email mailboxes. The classic forgotten data store. The rule: business-relevant emails are transferred to the document management system, the rest is deleted after a fixed period. Mailboxes of employees who have left are shut down after a transition period of a few weeks.
Linking the record and the deletion concept in everyday business
Both documents rarely fail at the drafting stage; they almost always fail at maintenance. Three rules that have proven themselves:
- 1Every new service is an entry. Before a new tool, form or service provider goes live, the processing activity goes into the record, with a deletion period and, where needed, a DPA. Anyone who does it the other way round never catches up.
- 2Quarterly review. 30 minutes: have new processes been added, have tools been switched, are the recipients still correct? The change history is updated.
- 3Annual deletion run with a log. For all data types that are not deleted automatically: a fixed date on which applicant data, old customer contacts and expired records are deleted and the deletion is documented.
The most common mistakes
- Record structured by systems instead of processes. “Microsoft 365” as a processing activity says nothing about purpose, data subjects or period.
- Deletion period “as long as necessary”. That is not a period. Art. 30(1)(f) requires a specific figure wherever one is possible.
- No starting point. “3 years” without saying from when. From the end of the contract? From the last invoice? From the end of the year?
- Deletion concept without implementation. The document says “6 months”, the applicant tool still holds documents from 2021.
- Backups forgotten. The deletion rule applies in the production system, the backup from three years ago still contains everything.
- No evidence. Data was deleted, but nobody can say when or what. Without a log, the authority treats the deletion as if it had not happened.
Record and deletion concept with Dieter
Dieter creates the record of processing activities from a guided questionnaire, with pre-built processing activities for the typical processes of a small business, suggested deletion periods and links to the data processing agreements and TOM. The starting point is the GDPR Check-up, which shows you which processing activities and documents you are missing. You can find all prices under Pricing.
Conclusion
The record of processing activities is the inventory of your data protection, the deletion concept the house rules that go with it. Both are mandatory for almost every business, and both can be set up in an afternoon if you structure them by process and take the statutory retention periods as your starting point. What counts after that is routine: new service, new entry, delete and log once a year.
Author

Sebastian Schenk
Co-Founder & CEO
Lawyer and data protection officer. Drives product vision at simply Legal and ensures Dieter is sound legally and in practice.
Sources and further reading
- Art. 30 GDPR: Records of processing activities (full text)
- Art. 5 GDPR: Principles, in particular storage limitation and accountability (full text)
- Art. 17 GDPR: Right to erasure (full text)
- DSK: Short paper no. 1, Record of processing activities (in German)
- § 147 AO: Rules on the retention of documents (full text, in German)
- § 257 HGB: Retention of documents, retention periods (full text, in German)
- § 15 AGG: Compensation and damages, period for asserting claims (full text, in German)
- § 41 EStG: Record-keeping obligations for wage tax deduction (full text, in German)
Frequently asked questions
Do I really have to keep a record of processing activities as a small business?
Yes, in almost all cases. The exemption for organisations with fewer than 250 employees in Art. 30(5) GDPR only applies if the processing is merely occasional, poses no risk and does not involve sensitive data. HR, customer and website data are processed on a permanent basis, so the exemption does not apply to those areas. That is why even a sole trader needs a record, even if it is a short one.
Does the record of processing activities have to be published?
No. It is an internal document that only has to be made available to the supervisory authority on request (Art. 30(4) GDPR). Data subjects have no right to inspect the record, but they do have a right of access to their own data under Art. 15 GDPR.
How long may I keep application documents?
After a rejection, usually up to six months. The period follows from the possibility that rejected applicants assert claims under the German General Equal Treatment Act (AGG): two months for asserting the claim (§ 15(4) AGG) and three months for filing a claim in court (§ 61b of the German Labour Court Act, ArbGG), plus a buffer for service of documents. Longer only with express consent, for instance for a talent pool.
How long do invoices have to be kept?
Since 1 January 2025, eight years instead of ten, counted from the end of the calendar year in which the invoice was issued (§ 147(3) of the German Fiscal Code (AO) and § 257(4) of the German Commercial Code (HGB) following the Fourth Bureaucracy Relief Act). For books, inventories and annual financial statements, it remains ten years.
Do I have to delete data from backups too?
Not immediately, if that would be technically disproportionate. The deletion concept must, however, define the cycle after which backups are overwritten and ensure that deleted data does not end up back in the production system after a restore. The backup cycle is documented as a deletion period in its own right.
What is the difference between deleting, blocking and anonymising?
Deleting removes the data irretrievably. Blocking, called restriction of processing under Art. 18 GDPR, keeps the data for retention obligations but withdraws it from active use. Anonymising permanently removes the link to a person, so that the GDPR no longer applies and the data may be kept for statistics. Pseudonymised data, by contrast, is still personal data.
This article reflects the position at the date of publication. We update our content when the law changes.
Related articles

Thursday, 10 July 2025
How to create a privacy policy: mandatory information, examples and common mistakes
Every website needs a privacy policy, because even loading a page processes personal data. This guide shows which information Art. 13 GDPR requires, how to describe services such as analytics, newsletters or Google Fonts correctly, what the TDDDG means for cookies and which mistakes most often lead to cease-and-desist letters.

Thursday, 11 September 2025
Technical and organisational measures (TOM): What Art. 32 GDPR requires and how small businesses implement it
Technical and organisational measures (TOM) are the part of the GDPR that decides over fines and data breaches. This guide explains the requirements of Art. 32 GDPR, the classic TOM catalogue with examples, how to rate your protection needs, which measures are realistic for a company of ten people and how to build the TOM document that authorities and clients want to see.

Thursday, 23 October 2025
Data processing agreement (DPA): when you need one, what it must contain and when you don’t
A data processing agreement is mandatory as soon as a service provider processes personal data on your behalf: hosting, cloud, newsletters, CRM. With tax advisers, lawyers or banks, on the other hand, you don’t need one. This guide explains how to tell the difference, the mandatory contents under Art. 28 GDPR, how to deal with sub-processors and US providers, and how to check a provider’s DPA in ten minutes.
