AURA

Record of processing activities in a small business: when you need one despite having fewer than 250 staff

A company employing fewer than 250 people is not automatically exempt from maintaining a record of processing activities. UODO indicates three situations where the obligation exists despite small scale.

Published
15 min read3007 words

AURA — a virtual business manager. Management on facts, not impressions. Who we are

Key takeaways

  • The 250-employee threshold does not provide automatic exemption from maintaining the record
  • Three conditions: risk to people's rights, regularity of processing, special categories of data
  • Only one of three criteria is sufficient for a process to require an entry in the record
  • Client health data is a special category — requires a record even in a small salon
  • UODO templates are only examples, not the only correct forms of the document
  • Lack of a record can result in an administrative penalty — even for a small business

A record of processing activities is a document that shows what personal data your company collects, for what purpose, who has access to it, and who you share it with. Many small business owners in Poland assume that because they employ fewer than 250 people, they are automatically exempt from this obligation. This is not true — and this is exactly where the risk lies that could cost you dearly.

In this article you will learn when, despite having few employees, you must maintain a record, what three conditions the Personal Data Protection Office indicates, and how to describe your processing activities on your own without external specialists.

Wooden drawer cabinet in an organized office — symbol of order in company documentation
Order in company documentation is the foundation of GDPR compliance

What is a record of processing activities

A record of processing activities is not another form to fill out for the office. It is an internal document of your company that clearly shows how personal data processing looks in your business. According to Article 30(1) and (2) of GDPR, the record must contain information about who is the data controller, what categories of data subjects and what categories of data you process, for what purpose, who you share it with and how long you keep it.

The Personal Data Protection Office (UODO) emphasizes in its guide that the record templates provided by the office should not be treated as the only correct patterns. Due to the diversity of controllers, sectors and processing activities, each controller can adapt the document format to their needs, provided it contains all elements required by Article 30 GDPR. Most importantly, you as the business owner must be able to clearly present this information if asked by the DPO or inspector.

Why the record matters even for small businesses

The record of processing activities is not a document you create once and put in a drawer. It is a tool that helps you understand what data you actually process and where problems might arise. Without a record, it will be difficult to answer a customer's question about what you do with their data, and it will be harder to implement new processes in your business in a compliant manner.

In a small business, the record also helps identify places where data is transferred to external entities — for example, an accounting firm, software provider or marketing agency. Without a clear picture of these flows, it is easy to miss the moment when you share data with someone with whom you do not have a data processing agreement.

If you want to deepen the topic of automation and GDPR in your business, read the article Automation and GDPR: where your customer data physically ends up, Process automation in a company: what can realistically be handed over to a system and what cannot, Errors when implementing automation: five situations where we advise against starting and Where to start automation in a small business: four thresholds instead of general analysis.

The 250-employee threshold and three situations that change everything

The common belief that a company employing fewer than 250 people does not need to keep a record is wrong. This is only a simplification that does not reflect the reality of data processing in daily operations.

According to the position of the Article 29 Working Party, adopted by the President of UODO, controllers and processors employing fewer than 250 employees must maintain a record when at least one of three situations applies. It is sufficient that any of these situations applies, and for those specific types of processing you must have a ready record. You can find the detailed explanation in the UODO guide on recording processing activities.

less than 250 → risk? → regular? → sensitive data? → one "yes" → to the record

When processing can cause risk

The first situation is when data processing may create a risk to the rights and freedoms of natural persons. The Personal Data Protection Office does not specify the threshold of this risk — you must assess yourself whether something in your business could expose customers or employees to harm. This concerns processes where data leakage or misuse could actually affect the lives of specific people.

When processing is non-incidental

The second situation is processing that is not occasional or incidental. This is a key concept that in practice means regularity. If in your business you collect customer data daily or cyclically, maintain their records, send newsletters, process employee data — this definitely goes beyond occasional activity.

When you process special categories of data

The third situation is processing of special categories of personal data, as referred to in Article 9(1) GDPR, or data about criminal convictions and offenses. In small business practice, this primarily concerns health-related data — and this appears in many service industries much more often than business owners would expect.

Practical example: small company, regular employees

The Article 29 Working Party gives a specific example in its position that well illustrates the problem. It concerns a small organization that most likely systematically processes data about its employees. As the office indicates, as a result such processing cannot be considered incidental and must be included in the record of processing activities.

Take a company with three employees. It is not a large organization, but if you regularly keep records of working time, calculate salaries, store employment contracts and data for Social Insurance Institution — you systematically process personal data of employees. This is not an occasional activity that happens once a year. This is daily practice that requires entry in the record.

The situation with customers is similar. If you keep appointments for clients, store their contact details, send appointment reminders — even with a small number of people this is regular processing. Only one of the three criteria is sufficient for that specific process to require a record.

What this means in practice for your business

For a company with three employees and a hundred clients, this means the need for at least two entries in the record: one for HR processes, another for customer service. Even if you previously thought the record exemption applied to you, these two regular processes mean you must have documentation.

Hands sorting coloured glass beads into small ceramic dishes — symbol of systematic data organization
Systematic data organization — how to organize the register

When a record is actually not required

It is important to understand that not every processing activity in your business must appear in the record. The Personal Data Data Protection Office clearly indicates that the record is kept only for those indicated types of processing. So if some activity in your business is truly incidental, does not involve risk to individuals and does not concern special categories of data — that specific activity may not require an entry in the record.

Examples of incidental processing

Imagine a situation where once a year, during some promotional action, you send a one-time mailing to a group of people who themselves asked you about it. That is incidental activity. Or a situation where you process data of one specific customer in connection with one specific complaint — that is also not systematic processing.

In practice, such cases are rare in a beauty salon or car service, but it is worth being able to distinguish regular processes from those that appear occasionally. In case of doubt, it is worth consulting with a DPO who will help assess whether a specific process requires an entry in the record.

Industry test: how it looks in different service businesses

There is no single simple answer for every industry. Each business must analyze its own processes, but the table below can guide you toward the right thinking. Remember that the final assessment is worth verifying with a DPO or lawyer specializing in personal data protection.

IndustryRegularity of processingSpecial categories of dataConclusion
Beauty salonYes — client appointments, treatment historyYes — client health dataDefinitely yes, entry required
Hair salonYes — appointments, client contact detailsUsually noEntry required (regularity), DPO consultation for certainty
Car serviceYes — client and vehicle dataNoEntry required (regularity), DPO consultation for certainty
Real estate agencyYes — client data, offersNoEntry required (regularity), DPO consultation for certainty
Law firmYes — client data, casesYes — sensitive data by nature of casesDefinitely yes, entry required

How to describe a process in one line: record fields

You do not need to create a complicated document. The Personal Data Protection Office provides templates you can use as a starting point. Below you will find an example structure of a record entry for a typical process in a small service business.

FieldExample entry
Process nameClient appointment handling
Purpose of processingDelivery of cosmetic services, sending appointment reminders
Categories of data subjectsSalon clients
Categories of dataFirst name, last name, phone, email, treatment history, health contraindications
RecipientsCRM software provider (processor), possibly accounting firm
Retention periodFor the duration of the contract + 3 years (varies for different purposes)

Each entry in the record answers the questions: what you do, why, what data you need for this, who else has access to it, and how long you keep it. These are simple questions, but you answer them for each process in your business separately.

Where to get this information

Most of the information for the record is already in your business, you just need to gather it in one place. Check your CRM or customer management system — you will see what fields about clients you collect. Check agreements with software providers — you need to know who has access to data based on a data processing agreement.

Also review the spreadsheets you use. If any employee keeps an informal list of customers with their data in Excel — that is also processing and must be included in the record. The same applies to documents in the cloud or on a local computer.

Keeping the record up to date

The record of processing activities is not a document you create once and forget. This is why it is worth keeping it in digital form and regularly checking whether it still reflects reality. When changes occur in the business, the record should be updated.

When to update the record

Changing your CRM provider, adding a new communication channel with customers, implementing a new invoicing program — each such change can affect personal data flows. Also changing the scope of collected data, for example adding a "date of birth" field for appointments, requires updating the record.

There is no set deadline for reviewing the record. The rule is simple: when you introduce something new in your business related to personal data, check whether the record is still complete. In practice, it is worth doing a review at least once a year, even if you have not introduced any changes.

Common mistakes when maintaining a record

Many business owners make the same mistakes that can then cost them problems during UODO inspections. Awareness of these pitfalls will help you avoid them.

Template from the internet without adaptation

Downloading a ready-made template from the internet and filling it with data from the first company that comes along is a trap. The template may not fit the specifics of your business, making the document unreadable or incomplete. The office clearly emphasizes that templates are only examples, not the only correct forms.

Record for "show" not for reality

Another mistake is creating a record that looks good on paper but does not correspond to what actually happens in the business. The Personal Data Protection Office in the McDonald's Polska case imposed a total penalty of over 16 million złotych precisely for such a situation — the company lacked proper risk analysis and did not implement data processing agreement provisions. It is worth remembering this. You can find details of this case on the UODO website.

Forgotten Excel spreadsheets with employees

A common problem is when you only enter main systems in the record but omit unorganized data sets. If any employee keeps an informal customer list in a spreadsheet on their computer — that is also data processing and must be included. Before creating the record, thoroughly review all places where personal data may be stored or processed in your business.

Do it yourself: how to create a record in 90 minutes

You do not need an external consultant to create a basic record of processing activities for your small business. A systematic approach and about an hour and a half of work is enough.

Step 1: List all processes

Take a sheet or spreadsheet and list all activities in your business that involve personal data. Start with client registration, then move to order handling, sending newsletters, maintaining employee documentation, cooperation with an accountant and other external entities.

Step 2: Answer three questions for each process

For each listed process, answer the questions: Can this processing create risk for customers or employees? Do you perform this activity regularly, not just occasionally? Does it concern health data or other special categories?

Step 3: Fill in the table

For processes where you answered at least once "yes," fill in the record table. Use the UODO template or create your own spreadsheet — most importantly, it must contain all elements required by Article 30 GDPR.

Step 4: Verify with DPO

If you have doubts about any process, consult with the Data Protection Officer or lawyer. Sometimes the situation is not clear-cut and you need professional assessment before entering a given process in the record.

How it looks when processes are in one system

When all client data, appointments, cooperation history and communication are gathered in one place — for example in a CRM system — it is easier to see exactly what data you process and who has access to it. You then immediately see what fields are filled, how long data is kept and whether it is shared with external entities.

The system also shows who from your team has access to what data — this is important both for security and for the record. Then maintaining a current record becomes simpler because changes in the system are immediately reflected in the documentation.

In Aura you will find tools that help in this process: the Customer Data module collects all information in one place, CRM and automations allow managing appointments and communication, and Admin panels show who has access to what in the system. This is not automatic record-keeping — you still decide what and how you process — but the system makes it easier to keep your finger on the pulse.

Aura also offers connections with other systems (Integrations) you already use — this way all data flows are visible in one place. If you plan shift schedules, check Team — the schedule set against a traffic forecast.

Check how CRM and automations in Aura work and see what managing customer data in one place looks like.

Frequently asked questions

Does a company with two employees need to maintain a record of processing activities?

There is no automatic exemption from the obligation to maintain a record for companies employing fewer than 250 people. If you process data regularly — and in the case of two employees and a client base this is usually the case — you must have a record at least for those processes.

What exactly does "processing does not have an incidental character" mean?

It means that you perform the activity regularly, cyclically or continuously. Collecting client data for appointments, maintaining employee documentation, sending newsletters — this is processing that is not incidental. Incidental is something that happens from case to case, for example once a year.

Are health data of beauty salon clients special categories of data?

Yes. Data concerning health, including contraindications to treatments, allergies, information about skin condition — this is special categories of personal data within the meaning of Article 9(1) GDPR. Their processing requires a specific legal basis and an entry in the record.

Can I use a ready-made record template from the internet?

You can, but remember that UODO templates are not the only correct patterns. You must adapt the template to the specifics of your business and ensure it contains all elements required by Article 30 GDPR. Just copying a template without analyzing your own processes is not enough.

How often must I update the record of processing activities?

There is no set deadline. The record should be updated whenever you introduce changes in your business related to personal data processing: new system, new provider, new client communication channel. It is also worth reviewing the documentation at least once a year for currency.

What is the penalty for lacking a record when it is required?

The Personal Data Protection Office may impose an administrative penalty. In the case of McDonald's Polska, the penalty totaled over 16 million złotych for irregularities related to data processing entrustment and lack of proper documentation. The penalty amount depends on the scale of the violation.

Can a DPO help assess whether I need to maintain a record?

Yes. The Data Protection Officer will help you assess which processes in your business require an entry in the record. It is worth consulting with a DPO especially in case of doubts that are not clear-cut.

Who writes this

See your business as a system.

Aura is a virtual business manager: management on facts, not impressions. For a company that wants a system running its processes instead of the owner’s memory.

The website, CRM, admin panel and automations are modules of the same system. We are not a website agency.

Look at my business

You will land on the home page. Give a company name — Aura looks at it in public data and shows what a client sees before calling you. No promises of a result.

See what we do

Related services

Read next Scroll for more

Let us look at your numbers

Tell us how enquiries are handled today — how many there are, who picks them up, where they get lost. Aura walks the process with you and shows what can be taken off a person, and what is better left alone.

Talk to Aura

The home page with Aura opens. Give a company name — she looks at it in public data and shows what a client sees. No promises of a result.

Prefer to write? marketing@auraglobal-merchants.com

Next step

Let us check whether Aura fits your place

We do not take everyone: first we look at your processes, sales and current systems and tell you honestly whether it makes sense for us to come in. A few questions, about five minutes.

Take the assessment →