The Record of Processing
The document a regulator asks for first, which most small employers believe they are exempt from and almost none actually are.
RECORD OF PROCESSING ACTIVITIES
One row per activity, not per system
- ActivityRecruitment: applications and assessmentName it by what you do, not by the product you do it in
- Categories of personApplicants, including unsuccessful onesThe unsuccessful group is the one most often omitted
- Categories of dataContact details, CV content, interview notes, right-to-work evidenceInterview notes count and are routinely forgotten
- PurposeAssessing suitability for a specific roleOne purpose per row. Two purposes means two rows
- Lawful basisLegitimate interests; legal obligation for right-to-workDifferent parts of one activity can rest on different bases
- RecipientsApplicant tracking supplier, background check providerNamed, including processors
- RetentionSix months after the decisionState the trigger, not only the period
- TransfersSupplier hosting outside the jurisdictionThe row most often blank and most often asked about
- SecurityAccess limited to the hiring panelOne line is sufficient
An enquiry opens with a request for this. It establishes within a minute whether the organisation knows what it does with people's information, and nothing else in the file recovers a bad first answer.
The practical lesson in “The Record of Processing” is that a record is useful only when its purpose, owner and lifecycle are clear. For teams researching how to calculate idle time, this implementation resource can add time and project context, provided collection is proportionate, access is limited and every consequential inference receives human review.
What it is, and what it is not
A list of the processing activities carried out, with the same facts recorded about each.
For a separate benchmark relevant to “The Record of Processing”, consult the Verizon Data Breach Investigations Report. Use it to test purpose, data flow, retention, access and response procedures rather than substituting a generic checklist for the organisation’s actual records.
Not a system inventory. A payroll system may appear in three activities and one activity may span four systems. The unit is what you do, not what you do it with.
Not a policy either. It is a factual record, and it should read like one.
Why employers believe they are exempt
There is a small-organisation exemption in most versions of this requirement, and it is considerably narrower than it reads.
It falls away where processing is regular rather than occasional, where it could risk people's rights, or where special category data is involved. Employment processing is regular by definition, and it nearly always includes health information.
Which means virtually every employer with staff is within scope. The belief otherwise is the commonest single gap in this subject.
What makes one useful rather than merely present
Written by activity, in one line per field, in language somebody could answer a question from.
Maintained when something changes rather than reviewed annually, because the version that matters is the one describing what you do now.
And short. A record listing nine activities in a page is worth more than a forty-page document assembled once by a consultant and opened never.
Starting from nothing
List the activities first: recruitment, payroll, performance, absence, access, monitoring, suppliers, leavers. Most employers have between eight and fifteen.
Then fill the same eight fields for each, which takes about twenty minutes per activity with somebody who knows the operation.
Two days of work, once, and the single most useful document in the whole subject exists.
Where the rows come from
List the activities before filling any fields: recruitment, payroll, performance, absence, access, monitoring, suppliers, leavers. Most employers have between eight and fifteen, and naming them is the part that requires knowing the operation rather than the law.
What a regulator reads it against
The privacy notice. An activity in the record that does not appear in the notice means people were not told about something you do, which is a more serious finding than a gap in either document alone.
Two days of work, once: list the activities, then fill eight fields for each with somebody who knows the operation. After that it is maintained rather than built, and the single most useful document in the subject exists.
The unit is the activity
Not the system. A payroll system may appear in three activities and one activity may span four systems. Getting this wrong produces a record that describes your software estate rather than what you do with people's information.
Maintaining it afterwards
Updated when something changes rather than reviewed annually, because the version that matters is the one describing what you do now. A new system, a new supplier, a new activity — each is a line, added that week.