Records of processing activities is a written description of the processing of personal data by the organization.
This report is mandatory if any of the following occurs:
- the organization has more than 250 employees
- the processing of personal data is not incidental
- the processing of personal data is likely to pose a risk to the data subject's rights and freedoms
- the personal data processed contain special categories of data or personal data relating to criminal convictions and offenses
Records must be kept up to date. They also serve as a first-level way of assessing the lawfulness of processing, so it must be provided to the supervisory authority on request.
In Cyberday, records of processing activities is an own report, which is automatically gathered from the data on documentation sections.