GDPR: Records of Processing Must Be Backed Up With The Purpose

 
26 April 2019

Defining Data Processing
A German consulting firm indicates that what a "processing activity" entails for the purpose of an Article 30 records of processing is unclear from the GDPR; to comply, document each business process with a level of abstraction that depends on the size of the business (e.g. HR might suffice for small businesses, while medium enterprises might distinguish recruitment, management, etc.).



Background Facts:
  • an overview of what is considered a processing activity within the meaning of the GDPR.


Relevance to Business Activity:
  • defining data processing considerations:
    • introduction:
      • article 30 of the GDPR requires data controllers to maintain a record of their processing activities:
        • it is important to understand what a processing activity is.
      • what constitutes a processing activity is unclear from the GDPR and the analysis of the DPAs:
        • in order to comply with article 30 of the GDPR, organizations must keep a record of the:
          • processing activity;Control and
          • additional information about the processing such as:
            • purpose of processing;Control and
            • the categories of data processed.Control
    • data protection authorities ("DPA") on the subject:
      • the DPA in Baden-Wurttemberg:
        • stated that a processing activity is a special independent business process:
          • it is necessary to set a stringent standard so that each new purpose constitutes a separate processing activity.Control
        • equated processing activity with a business process, assuming a lower level of detail than what processing entails:Control
          • in practice, a business process does not only involve processing.
      • the German Data Protection Conference:
        • defines processing as a business process at an appropriate level of abstraction;Control and
        • acknowledges that the business process can be described at an appropriate level of abstraction.Control
    • conclusion:
      • processing activities depend on the size of the business:
        • the entire human resources administration can be a single processing activity for a small business with few employees;Control but
        • a medium sized business might need a breakdown for recruitment, staff management or termination.Control
      • the processing purpose must be documented with each description of a processing activity such as:
        • personal file management;Control and
        • payroll accounting or working time records.



Comments

Popular posts from this blog

Olivia: The New Tool from Garante Privacy to Help Protect Your Data

Navigating the Future of Recruitment: Understanding ICO recommendations on AI Tools

Italy: Garante's new guidelines on cookies and similar tracking technologies