Les DPO de la Santé
All articles
GDPR

The record of processing activities: where to start?

Les DPO de la SantéPublished Updated 4 min
The record of processing activities: where to start?

The cornerstone of compliance, the record of processing activities is too often neglected. A method to build it and keep it alive.

The record of processing activities is mandatory and is one of the structuring documents the CNIL may request during an inspection. It is also an excellent tool for steering compliance.

Keeping it alive

A record is only worth something if it is kept up to date. Building it into the organization’s processes — new projects, new tools — is the key to lasting compliance.

What the GDPR says — and why the exemption does not apply to you

Article 30 of the GDPR requires the controller to keep a record describing, for each activity: purposes, categories of data subjects and of data, recipients, any transfers outside the Union, retention periods and a general description of the security measures. The processor keeps its own, briefer record. As for the exemption for organizations with fewer than 250 employees: it falls away as soon as the processing is not occasional, involves sensitive data or is likely to result in a risk to rights and freedoms — conditions that are systematically met in healthcare. In practice, no care or digital-health player escapes it.

The five-step method

A record is not filled in from a desk: it is built with the business teams. Step 1: list the organization’s actual processes — admissions and patient management, care and patient records, billing, human resources, research, quality, video surveillance, website. Step 2: for each one, ask the people who do the work (which data, which tools, who has access, for how long). Step 3: qualify the roles — controller, joint controllership, processor — because that is what allocates the obligations. Step 4: fill in legal bases, retention periods and recipients, resolving the inconsistencies discovered along the way (there always are some). Step 5: have it validated, date it, and appoint an owner for each entry.

The specifics of the healthcare sector

Some processing operations call for particular vigilance: the electronic patient record and its access rights; remote monitoring and connected devices; research processing, which relies on the CNIL’s reference methodologies; exchanges with partners along the care pathway; critical processors — software vendors and HDS hosting providers, whose certificates and contracts must be referenced in the corresponding entry. The record then becomes much more than an obligation: it is the map of your health information system as seen by the law.

What a well-made record entry looks like

For each processing operation, an entry fits on one page and answers eight questions: which precise purpose (“patient record management”, not “IT”); which legal basis, and for health data which Article 9 exception; which categories of data subjects and of data, flagging sensitive data; who has access internally (by role, not by name); which recipients and processors, with the contract reference and, for a hosting provider, the HDS certificate; which retention periods in active storage and in archive, with the final disposition; which main security measures; and who is the business owner of the entry. Date every entry and every update: an undated record proves nothing.

The processing operations everyone forgets

In a healthcare facility or care organization: video surveillance, telephony and its recordings, access badges, vehicle geolocation, on-call rosters, complaint and adverse event management, website cookies, the newsletter, unsolicited job applications. At a software vendor: support data (tickets containing patient data!), technical logs, demo environments, remote maintenance. These “peripheral” processing operations are precisely the ones inspections uncover first, because they fly under the DPO’s radar when the record was built in isolation.

From the record to living compliance

A well-built record becomes the dashboard for everything else: it reveals the processing operations that require a DPIA, the missing processor contracts, the retention periods never applied, the forgotten transfers outside the Union. Hence the golden rule: every new application, every new provider, every new project goes through an update of the record before going into production. It is this discipline — more than the perfection of the initial document — that makes the difference on the day you have to account for yourself.

This article is provided for general information purposes and does not constitute personalized legal advice.

Turn your obligations into opportunities.

A free, no-obligation first conversation to review your compliance posture and identify your priorities — in English.

Response within 24 business hours · No obligation