GDPR
Article 30 vs a vendor register: how SMBs keep a record of processing
A vendor register is not automatically your Article 30 record. Here is how they differ, what an SMB actually needs to keep, and how PrivyLedger helps you maintain a record of processing activities — without pretending it is a certified filing.
Published 2026-08-27
Security questionnaires ask for sub-processors. GDPR Article 30 asks for processing activities. SMBs often answer the first from a spreadsheet and discover, late, that the second is a different shape: why you process, on what basis, which people, which data, who receives it, how long you keep it, and whether it leaves the EEA.
Vendor register vs record of processing
- A vendor register: who holds company or customer data, DPA status, region, risk, owner.
- A record of processing: each activity (support, payroll, product analytics), purpose, legal basis, data categories, data subjects, recipients, retention, transfers.
- The join table is the missing piece: which vendor touches which activity.
What an SMB should actually keep
You do not need a 200-row GRC template. You need named activities, honest purposes, a recorded legal basis, categories and subjects, the vendors on that flow, retention in plain language, and a transfer note when data leaves the EEA. Review dates stop the list going stale. Special-category data and AI tools that may train on inputs deserve a closer look — a DPIA-lite checklist, not a 40-page consultant memo on day one.
How PrivyLedger helps
PrivyLedger already stores vendors, data categories, DPAs, and AI flags. Records adds processing activities on top of that register and links them. When a linked vendor is high or critical, trains on customer data, or the activity flags special-category data or an undocumented transfer, a DPIA-lite draft can open automatically. Exports are Art. 30-shaped markdown packs with a review footer — operational support so you are not starting from a blank page.
This guide describes general practice. It is not legal advice. Your DPO or counsel should review exports before they go to a customer or regulator.
Questions
Is a vendor risk register the same as a GDPR Article 30 record?
No. Article 30 is a record of processing activities: purposes, legal bases, categories of data and subjects, recipients, retention, and transfers. A vendor register answers who holds the data and on what contract. They overlap; they are not the same document.
Do I need OneTrust to keep an Art. 30-shaped record?
Most SMBs need a living inventory they can export, not an enterprise GRC suite. Linking each processing activity to the vendors that touch it is the operational gap a vendor register already has the data for.
Does PrivyLedger produce a certified Article 30 record or a legal DPIA?
No. It helps you maintain a record of processing activities and a DPIA-lite checklist when heuristics fire (high-risk vendors, AI training, special-category data, undocumented transfers). Counsel should review before anything goes to a customer or a regulator.