GDPR records of processing 2026: SME template and CNIL fines
GDPR records of processing 2026 for French SMEs: mandatory article 30 content, CNIL template, HR data processing, processor obligations under article 28, CNIL fine levels and the most common mistakes uncovered in CNIL audits of small and mid-sized businesses.
Expert note: This article was written by our chartered accountancy firm. Information is current as of 2026. For a personalised review of your situation, contact us.
Updated 24 May 2026.
Article 30 of the General Data Protection Regulation (GDPR, EU Regulation 2016/679) requires almost every organisation that processes personal data — including very small businesses and SMEs — to maintain a record of processing activities. Since the GDPR entered into force on 25 May 2018, the record has become the central document in any compliance file, systematically examined by the CNIL whenever it conducts an inspection.
On the ground, however, the record remains one of the most neglected compliance tasks among French SMEs, often sitting behind cookie banners and privacy notices in the queue. The risk is no longer theoretical: the CNIL issued several six-figure sanctions in 2023 and 2024 where an absent or deficient record formed part of the findings.
This article sets out, drawing on official sources, what a GDPR record must contain in 2026, who must keep one, how to organise it, and which pitfalls the CNIL most commonly identifies in SME audits.
1. Who is in scope in 2026? The myth of the "fewer than 250 employees" exemption#
Article 30(5) GDPR provides a conditional exemption requiring four cumulative conditions:
- fewer than 250 employees;
- AND the processing is occasional (not regular);
- AND it is not likely to result in a risk to the rights and freedoms of data subjects;
- AND it relates to neither special-category data nor data relating to criminal convictions.
All four conditions must be met simultaneously. Yet as soon as a business handles:
- payroll for its staff (regular processing, HR data);
- a recurring customer or prospect database (regular processing);
- CCTV footage (often special-category data: union presence, inferable health information);
- employee connection or productivity monitoring (high-risk processing);
the exemption no longer applies. In practice, virtually every active French SME must keep a record. The CNIL states this unambiguously in its SME model.
2. Article 30 GDPR: mandatory content#
Article 30 sets out two parallel records depending on the role the organisation plays.
2.1 The controller record (article 30(1))#
For each processing activity, the record must include:
| Field | Expected content |
|---|---|
| Identification | Name and contact details of the controller, representative (if any), DPO |
| Purpose | Reason for the processing (e.g. payroll management, commercial prospecting) |
| Categories of data subjects | Employees, customers, prospects, suppliers, website visitors, etc. |
| Categories of data | Identity, contact, financial, HR, health, biometric, etc. |
| Recipients | Internal (departments), external (URSSAF, bank, processors) |
| Transfers outside the EU | Country, safeguards (Binding Corporate Rules, Standard Contractual Clauses, etc.) |
| Retention period | Active-use period + archiving period |
| Security measures | Encryption, access control, backups, pseudonymisation |
2.2 The processor record (article 30(2))#
For each category of processing carried out on behalf of a controller, the processor must record:
- its own identification plus that of the client controllers;
- the categories of processing activities carried out;
- transfers outside the EU;
- security measures.
A chartered accountancy firm is typically both at once: controller for its own HR management, processor when it runs payroll or manages accounting for client businesses.
3. The CNIL 2026 template: structure, fields and good practice#
The CNIL makes available a model record for SMEs in tabular format, with column-by-column guidance. A few concrete operating principles:
- One record, several sheets. One sheet per processing activity (payroll, recruitment, customer management, prospecting, CCTV, etc.). Do not confuse a processing activity with a software tool.
- Medium granularity. Too granular becomes unmanageable; too broad becomes imprecise. Aim for one sheet per business purpose, not per tool.
- Version control. Every update should be dated. CNIL inspectors appreciate clear traceability over time.
- Internal confidentiality. The record is an internal document, held on a secure medium. There is no obligation to publish it.
- Link with the DPIA. High-risk processing activities identified in the record trigger a Data Protection Impact Assessment (DPIA) under article 35 GDPR.
Our read. For an SME with 30 to 80 employees, expect 8 to 15 processing sheets. Fewer suggests under-mapping; more often signals excessive granularity that makes updates unmanageable.
4. What to do with HR processing (payroll, leave, BDESE)?#
HR processing lies at the heart of an SME's record and concentrates the most CNIL audit scrutiny:
| HR processing | Legal basis | Recommended retention period |
|---|---|---|
| Payroll and payslips | Legal obligation (French Labour Code) | 50 years (article L.3243-4 Labour Code, employer copy) |
| Candidate management | Legitimate interest | 2 years after last contact (unless deletion is requested) |
| Working time records | Legal obligation | 5 years (article L.3171-3 Labour Code) |
| CCTV | Legitimate interest (under conditions) | 30 days (CNIL recommendation) |
| Economic, social and environmental database (BDESE) | Legal obligation | Lifetime of the BDESE |
Legal bases must be documented in the record. The classic mistake is invoking employee "consent" for processing that actually rests on a legal obligation or legitimate interest. Under EDPB guidance, consent given by an employee to an employer is generally considered flawed because of the power imbalance inherent in the employment relationship.
5. Processor cascade: article 28 and the DPA#
Article 28 GDPR requires a written contract (Data Processing Agreement, DPA) between the controller and each processor, covering:
- the subject matter and duration of the processing;
- its nature and purpose;
- the categories of data and data subjects;
- the controller's obligations and rights;
- the processor's confidentiality commitment for itself and its staff;
- prior authorisation before engaging any sub-processor;
- assistance with data subject rights and security obligations;
- return or deletion of data at the end of the service.
In practice, an accounting firm signs a DPA with every software vendor (Pennylane, Cegid, Silae, etc.) and with every client whose payroll it processes. The CNIL published model contract clauses in 2022 and 2024.
6. CNIL sanctions 2024-2026: trend and fine levels#
GDPR sets two tiers of administrative fines (article 83):
| Type of breach | Fine ceiling |
|---|---|
| Administrative obligations (record art. 30, DPIA art. 35, breach notification art. 33-34) | €10 million or 2 % of worldwide annual turnover of the preceding financial year, whichever is higher |
| Substantive obligations (data subject rights, third-country transfers, legal basis, etc.) | €20 million or 4 % of worldwide annual turnover, whichever is higher |
Sanctions published by the CNIL in 2024-2025 show:
- an increasing number of sanctions directed at SMEs and start-ups, alongside the traditional large-group cases;
- fine amounts ranging from a few thousand euros for isolated breaches to several million euros for systemic failures;
- heightened attention to data security (encryption, access management) and excessive retention periods.
An absent or deficient record is almost never the sole finding, but it accompanies virtually every significant sanction — a reliable indicator that the overall compliance framework has broken down.
7. Our read: five SME mistakes observed in practice#
Expert view from compliance mandates observed in 2024-2026.
- "Copy-pasted generic template" with no adaptation to the actual business. CNIL inspectors immediately spot stereotypical sheets that do not describe the real processing chain.
- Conflating purpose with tool. The processing activity is not "Pennylane" or "Cegid" — it is "accounting management" or "payroll production". The tool belongs in the recipients/processors column.
- Poorly documented legal bases, particularly for HR processing where consent is invoked despite legal obligation or legitimate interest being the correct basis.
- No annual review. The record ages fast: new processing activities go unregistered, obsolete ones remain listed.
- Missing processor record. A firm that keeps only a controller record and omits its processor record exposes itself to a standalone finding.
8. FAQ#
Does an SME with fewer than 10 employees need a GDPR record?#
Almost always, yes. The article 30(5) exemption requires processing to be simultaneously occasional, free of risk to data subjects, and unrelated to special-category or criminal data. As soon as payroll or a recurring customer database is processed, the exemption falls away.
What is the difference between a controller record and a processor record?#
The controller record covers processing activities the organisation decides to carry out for its own purposes (article 30(1)). The processor record covers processing carried out on behalf of third parties (article 30(2)). The same organisation can be both at once.
Does the record need to be published or shared?#
No. It is an internal document, held in written form including electronic form (article 30(3)). There is no obligation to publish it or share it proactively. It must, however, be produced to the CNIL on request during an audit.
Is a Data Protection Officer (DPO) mandatory?#
Not always. Article 37 GDPR makes DPO designation mandatory for public authorities, organisations whose core activities involve large-scale systematic monitoring, and those processing special-category or criminal data at scale. For most SMEs outside healthcare or tracking platforms, designation is voluntary but recommended by the CNIL. Pooling a DPO across several businesses in the same group remains possible.
What is the maximum fine for a missing record?#
For an article 30 breach alone: up to €10 million or 2 % of worldwide annual turnover (article 83(4) GDPR). For substantive breaches: up to €20 million or 4 % of worldwide annual turnover (article 83(5)). Fines actually issued by the CNIL have generally remained well below these ceilings, but the trend in 2024-2026 is clearly upward.
In practice: structuring your GDPR record#
Frequently asked questions
Does a business with fewer than 10 employees need to keep a GDPR record?
Almost always, yes. Article 30(5) GDPR provides an exemption only when the organisation has fewer than 250 employees AND processing is occasional (not regular) AND poses no risk to data subjects AND does not involve special-category or criminal data. All four conditions must be met. As soon as an SME processes payroll, maintains a recurring customer database, or operates CCTV, the exemption falls away. The CNIL recommends that all controllers, including very small businesses, maintain a record — if only for internal governance and accountability purposes.
What is the difference between a controller record and a processor record?
The controller record (article 30(1) GDPR) covers processing activities the organisation decides to carry out for its own purposes — payroll, customer management, prospecting. The processor record (article 30(2) GDPR) covers processing carried out on behalf of third-party controllers, acting on their instructions. An organisation can be both simultaneously: a chartered accountancy firm, for example, is a controller for its own HR data and a processor when it handles clients' payroll.
Does the GDPR record need to be published or shared with third parties?
No. The record is an internal document, kept in written form including electronic form under article 30(3) GDPR. There is no obligation to publish it or share it proactively. It must, however, be made available to the CNIL on request during a formal inspection. Publication may be useful for transparency towards data subjects or business partners but remains optional.
Is appointing a Data Protection Officer (DPO) mandatory?
Not always. Article 37 GDPR makes DPO designation mandatory in three situations: (1) public authorities, (2) core activities that involve large-scale regular and systematic monitoring of data subjects, (3) large-scale processing of special-category or criminal data. For most SMEs outside healthcare or tracking platforms, designation is voluntary but recommended by the CNIL. Pooling a DPO across several businesses in the same network or group is permitted.
What is the maximum fine for failing to keep a GDPR record?
A failure to maintain the record required by article 30 GDPR constitutes a breach of administrative obligations sanctionable under article 83(4): an administrative fine of up to €10 million, or up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher. For substantive breaches — data subject rights, third-country transfers, legal basis — the ceiling rises to €20 million or 4 % of worldwide turnover under article 83(5). Fines actually issued by the CNIL have generally remained well below these ceilings, but the trajectory in 2024-2026 is clearly upward.

Article written by Samuel HAYOT
Chartered Accountant, registered with the Institute of Chartered Accountants. Certified Pennylane trainer.
Regulated French accounting and audit firm based in Paris 8, built to support companies across France with a digital and decision-oriented approach.
Sources
Official and operational sources cited for this page.
- CNIL — Modèle de registre des activités de traitement (PME)
- EUR-Lex — Règlement (UE) 2016/679 (RGPD), article 30
- Légifrance — Loi 78-17 du 6 janvier 1978 modifiée (Informatique et Libertés)
- CNIL — Sanctions prononcées (base publique)
- CNIL — Article 28 RGPD et contrats sous-traitant (DPA)
- Éditions Francis Lefebvre — Mémento Social (RGPD/RH)
This topic is part of our service French payroll outsourcing | DSN, payslips, HR
Need a quote or personalised advice?
Our accountancy firm supports you through all your steps. Get a free quote to review your situation and receive a bespoke fee proposal, or contact us directly.