GDPR processing register: fill it in one hour as a small business (template and method)
The GDPR applies to any business that processes personal data — a customer file, a mailbox, a contact form, payslips are enough. The text provides an exemption from the register obligation for organisations under 250 employees, but it does not apply as soon as processing is regular (which is the case for customer and employee management) or concerns sensitive data. In practice, the CNIL recommends that every small business keep a register, and it is the first document requested in case of inspection or complaint. This guide gives the method to produce it in one hour, without a lawyer, and the three documents that go with it.
What a processing register contains
The register is a table where each line is a processing activity: a precise purpose for which you use data. For each activity, Article 30 of the GDPR expects at least:
- The name and contact details of the controller (you), and of the data protection officer if there is one.
- The purpose: "customer relationship management", "payroll and staff administration", "commercial prospecting", "recruitment".
- The categories of persons concerned (customers, prospects, employees, applicants) and the categories of data (identity, contact details, bank details, connection data).
- The recipients: internal departments, processors (host, payroll software, emailing provider), bodies.
- Any transfers outside the European Union, and their safeguard (standard clauses, adequacy decision).
- Retention periods, or the criteria to set them.
- A description of security measures: passwords, backups, encryption, access control.
The one-hour method
- Ten minutes: list your tools that contain people's data (CRM, invoicing, mailbox, website, payroll, cloud, social networks). Each tool reveals one or two processing activities.
- Twenty minutes: for each activity, fill in the register line. A small services business typically has 6 to 10 activities: customers, prospects, suppliers, employees, applicants, website contact, newsletter, accounting, CCTV where relevant.
- Twenty minutes: set the retention periods. Common benchmarks: customer data during the relationship then up to five years after its end (limitation period), accounting documents ten years, unsuccessful applications two years, prospects three years after the last contact. These are reference periods, to adapt to your activity.
- Ten minutes: note the legal basis of each activity (contract, legal obligation, legitimate interest, consent) and date the register. It then lives on: one line added for each new tool.
The three documents that go with the register
- Information to individuals (Articles 13 and 14): a privacy policy on the website, a mention on forms and quotes, a notice for employees. It restates purposes, legal bases, recipients, periods and rights, in plain language.
- The data-processing agreement (Article 28): with each provider that processes data for you. Large vendors supply their own processing annex; for a freelancer or a small agency, you must supply it.
- The data-breach procedure: who to alert, how to assess the risk, and the 72-hour deadline to notify the CNIL when the breach presents a risk to individuals. A two-column table and an incident log are enough.
Do you need a data protection officer?
It is mandatory for public bodies and for companies whose core activity involves regular and systematic large-scale monitoring of individuals or large-scale sensitive data. A small services business, a tradesperson or a shop is generally not required to appoint one; designating an internal referent remains good practice, provided you do not call them "DPO" if they do not have that status declared to the CNIL.
The Chipie Studio GDPR Kit for small businesses contains the obligations memo, the Excel processing register with pre-structured standard lines, the privacy-notice template, the data-processing agreement and the rights-and-breaches procedure, in DOCX, PDF and Markdown. The CNIL publishes a free register template; the kit adds the surrounding documents and guided zones to fill them in consistently with each other. For a health, credit or surveillance activity, have your analysis validated by a professional.
Put it into practice
Kit RGPD TPE/PME
6 documents and 2 tooled spreadsheets for GDPR compliance in a small organisation: obligations memo, 6-sheet Excel processing register, privacy policy, article 28 processor contract, data-subject rights and breaches, 50-point check-list. Status verified on 31/07/2026.