Skip to main content
PRACTICE GUIDE · DATA PROTECTION

Records of Processing Activities in Excel

Almost every set of records of processing activities begins as a spreadsheet. We show at which point that path tips over, which five problems arise from it and how the same process runs digitally.

How it works today in most organizations

The starting point is always the same. Someone downloads a template – from the supervisory authority, from a professional association or from a seminar –, renames it to "Records_Company.xlsx" and starts filling it in. HR, accounting, marketing, IT: for every department a row appears in which purpose, legal basis, data categories, recipients and retention periods sit next to one another.

That is a perfectly sensible start. A spreadsheet is available immediately, anyone can operate it, and for the first twenty processing activities it is entirely sufficient. The problems do not arise while it is being set up – they arise in operation.

Because after the first version the actual process begins: the departments contribute by email, usually as a filled-in Word template or as an answer in running text. One person transfers that into the spreadsheet. A new system is introduced, a service provider is replaced, a department is restructured. The file sits on a network drive, is sent around as a copy for review, comes back with comments – and at some point "Records_Company_final.xlsx", "Records_Company_final_v2.xlsx" and "Records_Audit_Version.xlsx" exist side by side.

The moment it becomes apparent

This rarely shows up in day-to-day work. It shows up in three situations: when the supervisory authority asks, when a customer wants to see the records as part of a supplier review, or when the person in charge leaves the organization. In all three cases the question is not "Do you have records?" but "Which version was in effect on March 14 – and who approved it?"

An Excel file has no answer to that question. Not because it was poorly maintained, but because structurally it knows nothing about version, responsibility and approval.

The analysis

Five Problems Every Records Spreadsheet Creates

They occur regardless of the care with which the spreadsheet is kept – they are properties of the tool, not of the person.

View processing activities in preeco

No proof of the version in effect

Art. 30 GDPR requires records that can be presented to the supervisory authority. Without versioning and approval, there is no way to show which content was in effect at which point in time.

Mandatory information is never demanded

An empty cell looks like a filled one. Missing details on third-country transfers, categories of recipients or retention periods only surface once someone deliberately looks for them.

Interrelations exist only as free text

Systems, technical and organizational measures and data processing agreements sit as text in a cell. If a service provider changes, every affected row has to be found one by one.

Collaboration ends with passing the file around

As soon as two people or several legal entities are involved, competing versions circulate. Who last changed which row is recorded nowhere.

Currency depends on a single person

There is no cycle, no reminder and no follow-up. The records age exactly as fast as the organization changes – only nobody notices.

The target process in six steps

Records that hold up differ from a spreadsheet not through more content, but through a defined workflow. These six steps describe it – regardless of the tool you work with.

1. Take stock instead of starting over. The existing Excel or Word version is the basis. It is imported and mapped to the structured fields instead of being retyped. Everything that is already documented is preserved.

2. Record systems centrally, once. Every data processing system is created once – with provider, data categories and the associated protective measures. Processing activities then reference it instead of repeating the details. A change of provider thus becomes a change in one place.

3. Enforce mandatory information. Data capture follows a structured form that guides you through all the information required by Art. 30(1) GDPR: purpose, data subjects, data categories, recipients, third-country transfers, retention periods and protective measures. Empty mandatory fields are visible, not invisible.

4. Assign responsibility per processing activity. Every processing activity is given a person responsible for its substance. Follow-up questions go to that person, not to "data protection". Maintenance thereby moves to where the knowledge sits.

5. Approve and freeze. Approval creates an unchangeable version. In preeco | data protection the system automatically generates a PDF revision in the process; two versions can be compared in color, and stored SHA-256 checksums make the integrity of a revision verifiable. That is exactly what answers the question about the version from March 14.

6. A cycle instead of an occasion. Updates are scheduled – annually, upon material changes or when a new system is introduced. Reminders and tasks prompt the responsible person, without anyone keeping a list in their head.

What the supervisory authority actually wants to see

In practice, a supervisory authority rarely asks about the records alone. It asks about a specific processing activity – applicant management or the newsletter, for instance – and expects coherent evidence for it: the processing activity itself, the system in use, the technical and organizational measures taken, the data processing agreement with the service provider and the retention period.

In a spreadsheet these five pieces of information sit in five different places: a row in the records, a row in the system list, a section in the document on technical and organizational measures, a PDF in the contract folder and an entry in the deletion concept. Bringing them together is the actual work – and the reason why an inquiry from an authority ties up several days in many organizations. If the objects are permanently linked to one another, however, the answer is an export.

Before and after in direct comparison

Criterion Before: Excel spreadsheet After: structured records
Maintenance effort Contributions by email, manual transfer by one person Departments maintain their own processing activities directly
Currency Depends on whether someone thinks of the file Reminders and tasks on a fixed cycle
Completeness Empty cells go unnoticed Form guides through all information required by Art. 30 GDPR
Verifiability No provable version, no approval PDF revision per approval, version comparison, checksum
Interrelations Systems, protective measures and agreements as free text Permanent link between processing activity, system, measure and contract
Collaboration Competing file versions in circulation One version, roles and permissions, activity log
Information for authorities An export from yesterday, prepared by hand Processing dossier and status report at the push of a button
Continuity risk Knowledge sits with a single person Process and history sit in the system

In practice

This Is What It Looks Like in preeco | data protection

The three building blocks that carry the process described here.

What the switch means in practice

The most common objection to switching is that the records would then have to be written all over again. That is not the case. The existing version is imported, the content is mapped to the structured fields, and the only additions are what was missing from the spreadsheet anyway. Those gaps are precisely the real gain: they become visible before a supervisory authority makes them visible.

Realistically, the switch takes a few days at a mid-sized organization with 30 to 60 processing activities – and the larger part of that is not down to the technology but to clarifying the substance: who is responsible for which processing activity, which system is actually behind it, and which retention period really applies.

Three mistakes that make the switch unnecessarily hard

Trying to migrate everything at once. Start with the processing activities that actually get reviewed – HR, recruiting, customer data, newsletter, video surveillance. The long remainder follows in the regular cycle.

Skipping the system list. Anyone who keeps writing systems as free text into the processing activity rebuilds the Excel logic in the new tool. Central system management is the point at which the maintenance effort actually drops.

Leaving the departments out. Records maintained solely by the data protection officer stay just as fragile as before – only in a different interface. Only distributed responsibility makes the process independent of individual people.

How to tell that it is time

Records in Excel are not a mistake. They only turn into a risk once at least one of these points applies:

  • More than one person is supposed to work on them.
  • You cannot prove the version that was in effect on a given date.
  • There are several legal entities, locations or tenants.
  • The last complete update is more than twelve months ago.
  • Customers or auditors ask you for the records on a regular basis.

If none of these apply, the spreadsheet is fine. If two or more apply, it is already working against you.

FAQ

Frequently Asked Questions About Records of Processing Activities

Yes. The GDPR does not prescribe a particular tool – Art. 30(3) GDPR merely requires written form, which includes electronic form. An Excel spreadsheet meets that formal requirement. It meets the practical requirements for completeness, currency and verifiability only as long as the records stay small and are kept by a single person.

No. Existing records can be imported into preeco | data protection as XLSX or DOCX; the content is mapped to the structured fields. The only additions are what is missing.

The GDPR does not name a fixed cycle, but it does require records to be current. In practice an annual review has proven itself, supplemented by updates prompted by new systems, new service providers or material changes to processes.

Through approved revisions. In preeco | data protection every approval automatically generates a PDF revision. Two revisions can be compared in color, and stored SHA-256 checksums make the integrity verifiable. Comparison and integrity check are available for revisions created from the introduction of this feature onward.

The departments in substance, data protection in method. The knowledge about a processing activity sits in the department that carries it out. Once every processing activity has a responsible person and follow-up questions go there, the effort for the data protection officer drops considerably.

Go Through Your Records With Us

Bring your existing spreadsheet. In 30 minutes we show how the import runs and where the gaps are.