Search
ALF – Legal services in Africa
  • Home
  • Contrats
  • OFFERS
  • Contents
    • Newsletter ⭐️
    • Newsletter ⭐️
    • Legal articles
      • Fundraising
      • Shareholders’ agreement
      • Fintech
      • Personal data
      • Intellectual Property
    • Free Guides
      • Guide Dépôt marque Tunisie
      • Guide Dépôt marque Maroc
  • We are ALF
    • Mission and Values
    • Trainers
    • Gallery
  • Contact
  • English
    • Français (French)
  • Home
  • Contrats
  • OFFERS
  • Contents
    • Newsletter ⭐️
    • Newsletter ⭐️
    • Legal articles
      • Fundraising
      • Shareholders’ agreement
      • Fintech
      • Personal data
      • Intellectual Property
    • Free Guides
      • Guide Dépôt marque Tunisie
      • Guide Dépôt marque Maroc
  • We are ALF
    • Mission and Values
    • Trainers
    • Gallery
  • Contact
  • English
    • Français (French)
ALF - Legal services in Africa > Articles > Personal data > How to draw up registers of processing activities with regard to the RGPD?

How to draw up registers of processing activities with regard to the RGPD?

  • 23 January 2024
  • Posted by: Kelly HAZAN
  • Category: Personal data
No Comments

STARTUPS, LEARN HOW TO CREATE YOUR RGPD-COMPLIANT REGISTERS OF PROCESSING ACTIVITIES!

Keeping a register of processing activities is mandatory if your startup processes personal data (as controller and processor) with regard to European regulations (RGPD). What are the obligations imposed by Article 30 of the RGPD? How to keep records of personal data processing?

If you don’t know how to answer these questions, this article will help you understand how to create your treatment registers.

1. WHAT ARE THE RGPD OBLIGATIONS?

Unlike in many African countries (e.g. Morocco with the CNDP), it is no longer necessary to carry out prior formalities (requests for authorization or declaration of processing) with personal data protection supervisory authorities within the European Union.

On the other hand, in application of theaccountability principle, startups must implement internal mechanisms and procedures enabling them to demonstrate compliance with data protection rules at any time in the event of an audit.

One of the obligations linked to the principle ofaccountability is the obligation to keep a register of processing activities, whether the startup is acting as data controller or data processor.

2. WHAT ARE THE PREREQUISITES FOR DRAWING UP THIS REGISTER OF PROCESSING ACTIVITIES?

The following are the essential steps to be taken when drawing up data processing registers:

1. Identify the personal data processing carried out by the startup. This mapping of processing operations is carried out via an audit and inventory of the various purposes for which personal data is processed within the startup. To carry out this mapping, it is necessary to :

  1. Raise the awareness of the startup’s employees on the subject of personal data protection;
  2. Integrate all current projects into process mapping;
  3. Distinguish between professions/departments concerned by the processing of personal data;
  4. Ask the right questions to detect all the processes carried out by the startup. In this respect, it is advisable to target the information requested from employees according to the elements required to establish your processing registers.

2. Identify the qualification within the meaning of the RGPD of the startup for each processing purpose to find out whether it should be quality of “Data controller” or subcontractor(data processor) or even jointcontroller (joint controllers).

Pursuant to Article 4 of the RGPD:

  • The data controller is ” the person who determines the purposes and means of processing “.
  • The processor is ” the natural or legal person, public authority, department or other body that processes personal data on behalf of the controller.”

Indeed, depending on its qualification under the RGPD, if the startup acts as a controller and processor, it will have to keep two separate registers of processing activities.

3. WHAT DOES YOUR DATA PROCESSING REGISTER CONTAIN?

Depending on your qualification, your data processing register must contain the following information:

Data controller Subcontractor
Information Name and contact details of the controller and, where applicable, of the joint controller, the controller’s representative and its DPO Name and contact details of the processor(s) and of each controller for whom the processor is acting and, where applicable, of its DPO and representatives
Purposes of processing< Categories of processing carried out on behalf of each controller
Categories of people concerned< Data transfers outside the EEA – identifying the third countries concerned
Categories of personal data General description of “as far as possible” technical and organizational security measures
Categories of recipients, including those outside the EEA
Data transfers outside the EEA – identifying the third countries concerned
Duration of data deletion
General description of “as far as possible” technical and organizational security measures

4. OUR TIPS FOR DRAWING UP TREATMENT REGISTERS
We recommend :

  • Indicate only the information strictly required by the RGPD.
  • Use a format adapted to the startup (Excel, Word or startup-specific software).
  • Use a format that enables rapid export or printing in the event of a request from the supervisory authority.
  • Restrict access to registers to those who need to have access in order to carry out their duties.
  • Keep registers up to date in the event of changes in the processing of personal data or at least every 6 months

In practice, your records should reflect what is actually and effectively implemented in your start-up.

4. WHY KEEP RECORDS OF PROCESSING ACTIVITIES?

Practical benefits: the data processing register is a management tool that gives you an overview of all personal data processing carried out within your startup. It enables you to comply with theaccountability principle by demonstrating your compliance with the RGPD.

This also allows you to meet other RGPD obligations, for example:

  • identify any “sensitive” processing operations requiring an impact analysis;
  • ensure that retention periods are proportionate to the purposes for which personal data is processed;
  • implement security measures adapted to the processing and categories of personal data.

Avoid financial penalties of up to 2% of the startup’s annual worldwide sales or a €10 million fine (whichever is greater).

More articles →

References:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC
  • Guidelines, recommendations and best practices published by the European Data Protection Committee (EDPS);
  • Guidelines of the Article 29 Working Party (G29) approved by the EDPS ;
  • Guidelines from European data protection authorities (e.g. France’s Commission Nationale de l’Informatique et des libertés (CNIL), the UK’s Information Commissioner’s Office (ICO), Spain’s Agencia de Protection de Datos (APD), etc.).


    Form : I would like to be assisted in my personal data protection compliance project

    En remplissant ce formulaire de contact, African Legal Factory recueille et traite vos données à caractère personnel en tant que responsable de traitement afin de répondre à toutes vos interrogations. Vous disposez sur vos données d’un droit d’accès, de rectification, d’opposition, à l’effacement, à la limitation, à la portabilité et de donner des directives sur le sort de vos données après votre décès. Pour plus d’information relative au traitement de vos données personnelles veuillez consulter notre Politique de Confidentialité. [Privacy Policy]

    Leave a Reply Cancel reply

    RECEIVE OUR BEST DEALS AND AFRICAN TECH & LEGAL NEWS

    Please wait...

    Links

    • Training
    • About ALF
    • Support for fixed costs
    • PERSONAL DATA PROTECTION POLICY
    • CGUV

    Contact

    • +33.06.68.32.83.14
    • formation@africanlegalfactory.com
    © 2023 African Legal Factory, tous droit réservés. powered by Mavouna Avocats
    Nous utilisons des cookies pour vous garantir la meilleure expérience sur notre site web. Si vous continuez à utiliser ce site, nous supposerons que vous en êtes satisfait.
    Paramètres des cookiesREFUSERACCEPTER TOUT
    Manage consent

    Aperçu de la confidentialité

    Ce site web utilise des cookies pour améliorer votre expérience lorsque vous naviguez sur le site. Parmi ceux-ci, les cookies qui sont catégorisés comme nécessaires sont stockés sur votre navigateur car ils sont essentiels pour le fonctionnement des fonctionnalités de base du site web. Nous utilisons également des cookies tiers qui nous aident à analyser et à comprendre comment vous utilisez ce site web. Ces cookies ne seront stockés dans votre navigateur qu'avec votre consentement. Vous avez également la possibilité de refuser ces cookies. Mais la désactivation de certains de ces cookies peut affecter votre expérience de navigation.
    Required
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure the basic functionality and security features of the website, anonymously.
    CookieDurationDescription
    __stripe_midStripe sets this cookie to process payments.
    __stripe_sidStripe sets this cookie to process payments.
    _abckThis cookie is used to detect and defend against replay attempts. This cookie manages interaction with online robots and takes appropriate action.
    ak_bmscThis cookie is used by Akamai to optimize site security by distinguishing between humans and robots.
    bm_szThis cookie is set by the Akamai Bot Manager provider. This cookie is used to manage interaction with online bots. It also contributes to fraud prevention.
    cookielawinfo-checkbox-analyticsDefined by the GDPR Cookie Consent plugin, this cookie is used to record user consent for cookies in the "Analytics" category .
    cookielawinfo-checkbox-functionalDefined by the GDPR Cookie Consent plugin, this cookie is used to store user consent for cookies in the "Functional" category.
    cookielawinfo-checkbox-indispensableThe cookie is set by the GDPR cookie consent plugin to record the user's consent for cookies in the "Indispensable" category.
    cookielawinfo-checkbox-necessaryDefined by the GDPR Cookie Consent plugin, this cookie is used to record the user's consent for cookies in the "Necessary" category .
    cookielawinfo-checkbox-othersDefined by the GDPR Cookie Consent plugin, this cookie is used to store user consent for cookies in the "Other" category.
    CookieLawInfoConsentSaves the state of the default button for the corresponding category and the state of the CCAC. It only works in coordination with the primary cookie.
    redux_blastThis cookie is necessary for the operation of certain WordPress theme elements that make the website appear in the most optimal way for the visitor's device.
    Analytical
    Analytical cookies are used to understand how visitors interact with the website. These cookies provide information on visitor numbers, bounce rates, traffic sources, etc.
    CookieDurationDescription
    _gaThe _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also tracks site usage for the site analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors.
    _ga_5BN1MYEN2YThis cookie is set by Google Analytics.
    _gat_gtag_UA_157972103_1Defined by Google to distinguish users.
    _gidInstalled by Google Analytics, the _gid cookie stores information about how visitors use a website, while creating an analytical report of site performance. The data collected includes the number of visitors, where they come from and the pages they visit anonymously.
    CONSENTYouTube sets this cookie via embedded youtube-videos and registers anonymous statistical data.
    last_pys_landing_pageAnonymous cookie used to facilitate the "PixelYourSite" plugin that manages our analytics services.
    last_pysTrafficSourceAnonymous cookie used to facilitate the "PixelYourSite" plugin that manages our analytics services.
    pys_first_visitAnonymous cookie used to facilitate the "PixelYourSite" plugin that manages our analytics services.
    pys_landing_pageAnonymous cookie used to facilitate the "PixelYourSite" plugin that manages our analytics services.
    pys_session_limitAnonymous cookie used to facilitate the "PixelYourSite" plugin that manages our analytics services.
    pys_start_sessionAnonymous cookie used to facilitate the "PixelYourSite" plugin that manages our analytics services.
    Functional
    Functional cookies enable certain functionalities to be performed, such as sharing website content on social media platforms, collecting comments and other third-party functionalities.
    CookieDurationDescription
    _mcidThis is a Mailchimp functionality cookie used to evaluate UI/UX interaction with its platform.
    bm_svThis cookie is required for Akamai's cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor's browser. User bandwidth results are stored in this cookie to ensure that the bandwidth test is not repeated for the same user multiple times for the Akamai cache function.
    cookies.jsNo description available.
    mThis cookie is set by stripe.
    mailchimp_landing_siteThis cookie is set by MailChimp to record the page the user visited for the first time.
    pysTrafficSourceAnonymous cookie used to facilitate the "PixelYourSite" plugin that manages our analytics services.
    stm_lms_courses_watchedNo description
    wmc_current_currencysave currency settings.
    wp_woocommerce_session_b80c8f798ec84ed7476594d4acafc57cContains a unique code for each customer, so you know where to find the basket data in the database for each customer.
    Advertising
    Advertising cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors on websites and collect information to provide personalized ads.
    CookieDurationDescription
    NIDThe NID cookie, set by Google, is used for advertising purposes; it limits the number of times the user sees an ad, mutes unwanted ads and measures ad effectiveness.
    SAVE & ACCEPT
    Powered by CookieYes Logo