A record of processing activities is a document that shows what personal data your company collects, for what purpose, who has access to it, and who you share it with. Many small business owners in Poland assume that because they employ fewer than 250 people, they are automatically exempt from this obligation. This is not true — and this is exactly where the risk lies that could cost you dearly.
In this article you will learn when, despite having few employees, you must maintain a record, what three conditions the Personal Data Protection Office indicates, and how to describe your processing activities on your own without external specialists.

What is a record of processing activities
A record of processing activities is not another form to fill out for the office. It is an internal document of your company that clearly shows how personal data processing looks in your business. According to Article 30(1) and (2) of GDPR, the record must contain information about who is the data controller, what categories of data subjects and what categories of data you process, for what purpose, who you share it with and how long you keep it.
The Personal Data Protection Office (UODO) emphasizes in its guide that the record templates provided by the office should not be treated as the only correct patterns. Due to the diversity of controllers, sectors and processing activities, each controller can adapt the document format to their needs, provided it contains all elements required by Article 30 GDPR. Most importantly, you as the business owner must be able to clearly present this information if asked by the DPO or inspector.
Why the record matters even for small businesses
The record of processing activities is not a document you create once and put in a drawer. It is a tool that helps you understand what data you actually process and where problems might arise. Without a record, it will be difficult to answer a customer's question about what you do with their data, and it will be harder to implement new processes in your business in a compliant manner.
In a small business, the record also helps identify places where data is transferred to external entities — for example, an accounting firm, software provider or marketing agency. Without a clear picture of these flows, it is easy to miss the moment when you share data with someone with whom you do not have a data processing agreement.
If you want to deepen the topic of automation and GDPR in your business, read the article Automation and GDPR: where your customer data physically ends up, Process automation in a company: what can realistically be handed over to a system and what cannot, Errors when implementing automation: five situations where we advise against starting and Where to start automation in a small business: four thresholds instead of general analysis.
The 250-employee threshold and three situations that change everything
The common belief that a company employing fewer than 250 people does not need to keep a record is wrong. This is only a simplification that does not reflect the reality of data processing in daily operations.
According to the position of the Article 29 Working Party, adopted by the President of UODO, controllers and processors employing fewer than 250 employees must maintain a record when at least one of three situations applies. It is sufficient that any of these situations applies, and for those specific types of processing you must have a ready record. You can find the detailed explanation in the UODO guide on recording processing activities.
less than 250 → risk? → regular? → sensitive data? → one "yes" → to the record
When processing can cause risk
The first situation is when data processing may create a risk to the rights and freedoms of natural persons. The Personal Data Protection Office does not specify the threshold of this risk — you must assess yourself whether something in your business could expose customers or employees to harm. This concerns processes where data leakage or misuse could actually affect the lives of specific people.
When processing is non-incidental
The second situation is processing that is not occasional or incidental. This is a key concept that in practice means regularity. If in your business you collect customer data daily or cyclically, maintain their records, send newsletters, process employee data — this definitely goes beyond occasional activity.
When you process special categories of data
The third situation is processing of special categories of personal data, as referred to in Article 9(1) GDPR, or data about criminal convictions and offenses. In small business practice, this primarily concerns health-related data — and this appears in many service industries much more often than business owners would expect.
Practical example: small company, regular employees
The Article 29 Working Party gives a specific example in its position that well illustrates the problem. It concerns a small organization that most likely systematically processes data about its employees. As the office indicates, as a result such processing cannot be considered incidental and must be included in the record of processing activities.
Take a company with three employees. It is not a large organization, but if you regularly keep records of working time, calculate salaries, store employment contracts and data for Social Insurance Institution — you systematically process personal data of employees. This is not an occasional activity that happens once a year. This is daily practice that requires entry in the record.
The situation with customers is similar. If you keep appointments for clients, store their contact details, send appointment reminders — even with a small number of people this is regular processing. Only one of the three criteria is sufficient for that specific process to require a record.
What this means in practice for your business
For a company with three employees and a hundred clients, this means the need for at least two entries in the record: one for HR processes, another for customer service. Even if you previously thought the record exemption applied to you, these two regular processes mean you must have documentation.

When a record is actually not required
It is important to understand that not every processing activity in your business must appear in the record. The Personal Data Data Protection Office clearly indicates that the record is kept only for those indicated types of processing. So if some activity in your business is truly incidental, does not involve risk to individuals and does not concern special categories of data — that specific activity may not require an entry in the record.
Examples of incidental processing
Imagine a situation where once a year, during some promotional action, you send a one-time mailing to a group of people who themselves asked you about it. That is incidental activity. Or a situation where you process data of one specific customer in connection with one specific complaint — that is also not systematic processing.
In practice, such cases are rare in a beauty salon or car service, but it is worth being able to distinguish regular processes from those that appear occasionally. In case of doubt, it is worth consulting with a DPO who will help assess whether a specific process requires an entry in the record.
Industry test: how it looks in different service businesses
There is no single simple answer for every industry. Each business must analyze its own processes, but the table below can guide you toward the right thinking. Remember that the final assessment is worth verifying with a DPO or lawyer specializing in personal data protection.
| Industry | Regularity of processing | Special categories of data | Conclusion |
|---|---|---|---|
| Beauty salon | Yes — client appointments, treatment history | Yes — client health data | Definitely yes, entry required |
| Hair salon | Yes — appointments, client contact details | Usually no | Entry required (regularity), DPO consultation for certainty |
| Car service | Yes — client and vehicle data | No | Entry required (regularity), DPO consultation for certainty |
| Real estate agency | Yes — client data, offers | No | Entry required (regularity), DPO consultation for certainty |
| Law firm | Yes — client data, cases | Yes — sensitive data by nature of cases | Definitely yes, entry required |
How to describe a process in one line: record fields
You do not need to create a complicated document. The Personal Data Protection Office provides templates you can use as a starting point. Below you will find an example structure of a record entry for a typical process in a small service business.
| Field | Example entry |
|---|---|
| Process name | Client appointment handling |
| Purpose of processing | Delivery of cosmetic services, sending appointment reminders |
| Categories of data subjects | Salon clients |
| Categories of data | First name, last name, phone, email, treatment history, health contraindications |
| Recipients | CRM software provider (processor), possibly accounting firm |
| Retention period | For the duration of the contract + 3 years (varies for different purposes) |
Each entry in the record answers the questions: what you do, why, what data you need for this, who else has access to it, and how long you keep it. These are simple questions, but you answer them for each process in your business separately.
Where to get this information
Most of the information for the record is already in your business, you just need to gather it in one place. Check your CRM or customer management system — you will see what fields about clients you collect. Check agreements with software providers — you need to know who has access to data based on a data processing agreement.
Also review the spreadsheets you use. If any employee keeps an informal list of customers with their data in Excel — that is also processing and must be included in the record. The same applies to documents in the cloud or on a local computer.
Keeping the record up to date
The record of processing activities is not a document you create once and forget. This is why it is worth keeping it in digital form and regularly checking whether it still reflects reality. When changes occur in the business, the record should be updated.
When to update the record
Changing your CRM provider, adding a new communication channel with customers, implementing a new invoicing program — each such change can affect personal data flows. Also changing the scope of collected data, for example adding a "date of birth" field for appointments, requires updating the record.
There is no set deadline for reviewing the record. The rule is simple: when you introduce something new in your business related to personal data, check whether the record is still complete. In practice, it is worth doing a review at least once a year, even if you have not introduced any changes.
Common mistakes when maintaining a record
Many business owners make the same mistakes that can then cost them problems during UODO inspections. Awareness of these pitfalls will help you avoid them.
Template from the internet without adaptation
Downloading a ready-made template from the internet and filling it with data from the first company that comes along is a trap. The template may not fit the specifics of your business, making the document unreadable or incomplete. The office clearly emphasizes that templates are only examples, not the only correct forms.
Record for "show" not for reality
Another mistake is creating a record that looks good on paper but does not correspond to what actually happens in the business. The Personal Data Protection Office in the McDonald's Polska case imposed a total penalty of over 16 million złotych precisely for such a situation — the company lacked proper risk analysis and did not implement data processing agreement provisions. It is worth remembering this. You can find details of this case on the UODO website.
Forgotten Excel spreadsheets with employees
A common problem is when you only enter main systems in the record but omit unorganized data sets. If any employee keeps an informal customer list in a spreadsheet on their computer — that is also data processing and must be included. Before creating the record, thoroughly review all places where personal data may be stored or processed in your business.
Do it yourself: how to create a record in 90 minutes
You do not need an external consultant to create a basic record of processing activities for your small business. A systematic approach and about an hour and a half of work is enough.
Step 1: List all processes
Take a sheet or spreadsheet and list all activities in your business that involve personal data. Start with client registration, then move to order handling, sending newsletters, maintaining employee documentation, cooperation with an accountant and other external entities.
Step 2: Answer three questions for each process
For each listed process, answer the questions: Can this processing create risk for customers or employees? Do you perform this activity regularly, not just occasionally? Does it concern health data or other special categories?
Step 3: Fill in the table
For processes where you answered at least once "yes," fill in the record table. Use the UODO template or create your own spreadsheet — most importantly, it must contain all elements required by Article 30 GDPR.
Step 4: Verify with DPO
If you have doubts about any process, consult with the Data Protection Officer or lawyer. Sometimes the situation is not clear-cut and you need professional assessment before entering a given process in the record.
How it looks when processes are in one system
When all client data, appointments, cooperation history and communication are gathered in one place — for example in a CRM system — it is easier to see exactly what data you process and who has access to it. You then immediately see what fields are filled, how long data is kept and whether it is shared with external entities.
The system also shows who from your team has access to what data — this is important both for security and for the record. Then maintaining a current record becomes simpler because changes in the system are immediately reflected in the documentation.
In Aura you will find tools that help in this process: the Customer Data module collects all information in one place, CRM and automations allow managing appointments and communication, and Admin panels show who has access to what in the system. This is not automatic record-keeping — you still decide what and how you process — but the system makes it easier to keep your finger on the pulse.
Aura also offers connections with other systems (Integrations) you already use — this way all data flows are visible in one place. If you plan shift schedules, check Team — the schedule set against a traffic forecast.
Check how CRM and automations in Aura work and see what managing customer data in one place looks like.
Frequently asked questions
Does a company with two employees need to maintain a record of processing activities?
There is no automatic exemption from the obligation to maintain a record for companies employing fewer than 250 people. If you process data regularly — and in the case of two employees and a client base this is usually the case — you must have a record at least for those processes.
What exactly does "processing does not have an incidental character" mean?
It means that you perform the activity regularly, cyclically or continuously. Collecting client data for appointments, maintaining employee documentation, sending newsletters — this is processing that is not incidental. Incidental is something that happens from case to case, for example once a year.
Are health data of beauty salon clients special categories of data?
Yes. Data concerning health, including contraindications to treatments, allergies, information about skin condition — this is special categories of personal data within the meaning of Article 9(1) GDPR. Their processing requires a specific legal basis and an entry in the record.
Can I use a ready-made record template from the internet?
You can, but remember that UODO templates are not the only correct patterns. You must adapt the template to the specifics of your business and ensure it contains all elements required by Article 30 GDPR. Just copying a template without analyzing your own processes is not enough.
How often must I update the record of processing activities?
There is no set deadline. The record should be updated whenever you introduce changes in your business related to personal data processing: new system, new provider, new client communication channel. It is also worth reviewing the documentation at least once a year for currency.
What is the penalty for lacking a record when it is required?
The Personal Data Protection Office may impose an administrative penalty. In the case of McDonald's Polska, the penalty totaled over 16 million złotych for irregularities related to data processing entrustment and lack of proper documentation. The penalty amount depends on the scale of the violation.
Can a DPO help assess whether I need to maintain a record?
Yes. The Data Protection Officer will help you assess which processes in your business require an entry in the record. It is worth consulting with a DPO especially in case of doubts that are not clear-cut.