Unlock AI Compliance: Master the new EU AI Act with our comprehensive guide.

Roinn

3 min read

Writen by Zlatko Delev

Posted on: April 15, 2021

How do you document your processing activities?

How should you prepare?

A good way to start is by doing an information audit or data-mapping exercise to clarify what personal data your organisation holds and where. It is important that people across your organisation are engaged in the process; this can help ensure nothing is missed when mapping the data your organisation processes. It is equally important to obtain senior management buy-in so that your documentation exercise is supported and well resourced.

What steps should you take next?

1.Devise a questionnaire

2.Meet directly with key business functions

3.Locate and review policies, procedures, contracts and agreements

How should you document your findings?

The documentation of your processing activities must be in writing; this can be in paper or electronic form. Generally, most organisations will benefit from maintaining their documentation electronically so they can easily add to, remove, and amend it as necessary. Paper documentation may be adequate for very small organisations whose processing activities rarely change.            

However you choose to document your organisation’s processing activities, it is important that you do it in a granular and meaningful way. For instance, you may have several separate retention periods, each specifically relating to different categories of personal data. Equally it is likely that the organisations you share personal data with differ depending on the type of people you hold information on and your purposes for processing the data. The record of your processing activities needs to reflect these differences. A generic list of pieces of information with no meaningful links between them will not meet the UK GDPR’s documentation requirements. 

What should you document first?

  • Controllers – it makes sense for controllers to begin with a business function – e.g. HR, Sales, Customer Services. Although the UK GDPR does not require you to document this information, focusing on each function of your business, one at a time, will help to give your record of processing activities a logical structure. Each business function is likely to have several different purposes for processing personal data, each purpose will involve several different categories of individuals, and in turn those categories of individuals will have their own categories of personal data and so on.
  • Processors – although you have less information to document as a processor, it still helps to adopt a ‘broad to narrow’ approach. Start with the controller you are processing personal data for. There may be several different categories of processing you carry out for each controller, and in turn different types of international transfers, security measures and so on.

Do you need to update your record of processing activities?

Keeping a record of your processing activities is not a one-off exercise; the information you document must reflect the current situation as regards the processing of personal data. So you should treat the record as a living document that you update as and when necessary. This means you should conduct regular reviews of the information you process to ensure your documentation remains accurate and up to date.

Déan Teagmháil Linn

Tá súil agam go mbeidh sé seo úsáideach duit. Má theastaíonn Ionadaí AE uait, má tá aon cheist GDPR agat, nó má fuair tú iarratas SAR nó Rialálaí agus má theastaíonn cabhair uait, déan teagmháil linn ag am ar bith. Táimid i gcónaí sásta cabhrú ...
Foireann áitiúil GDPR.

Déan Teagmháil Linn

Recent blogs

The Future of Finance: Adapting to AI and Data Privacy Laws

The rapidly evolving landscape of financial technology is witnessing a significant transformation w

Navigating the Contradictions: Automated Decision-Making and Regulatory Legislation in AI Systems

The Dilemma of Automated Decision-Making At the heart of AI systems lies the promise of aut

How to Implement the New AI Law in Your Company

The implementation of the AI Act marks a significant stride towards responsible and fair use of art

Faigh Do Chuntas Anois

Socraigh i gceann cúpla nóiméad. Cuir isteach sonraí do chuideachta agus roghnaigh na seirbhísí a theastaíonn uait.

Cruthaigh Cuntas

Téigh i dteagmháil

Níl tú cinnte cén rogha atá le roghnú? Glaoigh, ríomhphost, comhrá a dhéanamh linn
am ar bith.

Déan Teagmháil Linn
06 EOLAS GDPR

Fan Suas chun Dáta

Fág do chuid sonraí anseo agus seolfaimid nuashonruithe agus faisnéis chugat maidir le gach gné den GDPR agus d'Ionadaí an AE. Ní bheidh muid bombard tú le ríomhphoist agus beidh tú in ann a insint dúinn chun stop a chur ag am ar bith.

Tá Ainm Iomlán ag teastáil!

Tá Ríomhphost Gnó ag teastáil!

Tá cuideachta ag teastáil!

Glac leis na Téarmaí agus Coinníollacha agus an Polasaí Príobháideachais