GDPR Role & Retention Mapper

Determine controller vs processor role, log processing activities, set retention periods, pick an Article 6 basis and export an Article 30 record.

Advertisement

GDPR Role & Retention Mapper — Build an Article 30 Record

Two questions decide most of your GDPR obligations, and most organisations answer both by guessing. Are you a controller, a processor, or a joint controller for a given activity? And how long are you actually allowed to keep each category of data? This tool works through both, then assembles the answers into a Record of Processing Activities in the shape Article 30 describes, exportable as a PDF you can put in front of a supervisory authority, a customer’s procurement team, or your own board.

It has seven sections — role determination, processing activities, retention calculator, legal basis, cross-border transfers, DPIA checker and export — and everything runs in your browser. It is built for the person who has been made the accidental data protection lead: an operations manager, a founder, an IT director at a company that just signed its first European customer.

Section by Section

  • Role determination. Four questions about who decides the purposes and the means of processing, and whether you act on someone else’s documented instructions. The result is Controller, Processor or Joint Controller with a confidence indicator and the specific obligations attached to that role.
  • Processing activities. Add up to 20 activities, each with the categories of personal data involved (name, email, phone, address, date of birth, financial, health, biometric, criminal, political or religious, genetic, children’s data), the categories of data subject (employees, customers, prospects, patients, students, website visitors), the purpose, the recipients and the volume band. Special category data is flagged automatically.
  • Retention calculator. A starting schedule across ten common record types, each editable, showing the period, the basis for the period and the caveats.
  • Legal basis. All six Article 6(1) bases side by side with what each is genuinely suited to, plus the Article 9 escalation where special category data is involved.
  • Cross-border transfers. Add destination countries, see whether an adequacy decision applies, and record the safeguard relied on where it does not.
  • DPIA checker. Evaluates your recorded activities against the high-risk indicators and tells you whether a Data Protection Impact Assessment is likely required.
  • Export. A single PDF containing the role determination, the Article 30 register, the retention schedule, the legal basis analysis, the transfer register and the DPIA assessment.

Controller, Processor or Joint Controller

The distinction is not about size or contract value; it is about who determines the purposes and means of the processing. A controller decides why and broadly how data is processed. A processor processes on the controller’s behalf, on documented instructions. Joint controllers jointly determine purposes and means, and Article 26 requires them to set out their respective responsibilities in a transparent arrangement, the essence of which must be made available to data subjects.

Getting it wrong is expensive in both directions: a company that believes it is a processor but in fact decides purposes carries controller obligations it has not prepared for.

RoleCore obligations
ControllerEstablish a lawful basis for each activity; maintain Article 30(1) records; conduct DPIAs where Article 35 requires; notify the supervisory authority within 72 hours of becoming aware of a breach (Article 33); respond to data subject rights requests; contract processors under Article 28
ProcessorAct only on documented controller instructions; maintain Article 30(2) records; implement appropriate technical and organisational measures under Article 32; assist the controller with rights requests and breach handling; engage sub-processors only with the controller’s authorisation; notify the controller of a breach without undue delay
Joint controllerEstablish a transparent Article 26 arrangement allocating responsibilities; provide a contact point for data subjects; make the essence of the arrangement available; each party remains individually liable to data subjects

What Article 30 Actually Requires

The exported record is structured around the statutory list, which is worth knowing because auditors check against it directly. A controller’s record must contain the name and contact details of the controller and, where applicable, the joint controller, the controller’s representative and the data protection officer; the purposes of processing; a description of the categories of data subjects and of personal data; the categories of recipients, including those in third countries; documentation of transfers to third countries and, for transfers under Article 49(1) second subparagraph, the suitable safeguards; where possible, the envisaged time limits for erasure of the different categories; and, where possible, a general description of the technical and organisational security measures.

A processor’s record under Article 30(2) is shorter: the identity and contact details of the processor and of each controller it acts for, the categories of processing carried out for each controller, third-country transfers and safeguards, and a general description of security measures.

Article 30(5) exempts organisations with fewer than 250 employees — but the exemption falls away if the processing is likely to result in a risk to the rights and freedoms of data subjects, if it is not occasional, or if it includes special categories of data or data relating to criminal convictions and offences. In practice, routine customer or employee processing is not occasional, so most small organisations are back inside the requirement. Records must be in writing, including electronic form, and made available to the supervisory authority on request.

Choosing a Legal Basis

Every processing activity needs one of the six bases in Article 6(1), chosen before processing begins and documented. You cannot switch bases later to rescue an activity a data subject has objected to.

  • Consent, Article 6(1)(a) — freely given, specific, informed and unambiguous, and withdrawable as easily as it was given. Suited to marketing and optional collection; poorly suited to anything the user cannot realistically refuse, which is why it is a weak basis in an employment context.
  • Contract, Article 6(1)(b) — necessary for performance of a contract with the data subject, or pre-contractual steps at their request. Order fulfilment, account management, service delivery.
  • Legal obligation, Article 6(1)(c) — required by Union or member state law. Tax records, statutory employment records, regulatory reporting.
  • Vital interests, Article 6(1)(d) — protecting someone’s life. Genuine medical emergencies, not general health services.
  • Public task, Article 6(1)(e) — public interest or official authority.
  • Legitimate interests, Article 6(1)(f) — requires a documented balancing test weighing your interest against the data subject’s rights, and is not available to public authorities acting in the performance of their tasks. Fraud prevention and network security are the classic examples.

Special category data needs both an Article 6 basis and a separate condition under Article 9(2), such as explicit consent, an employment or social security law obligation, or substantial public interest with a basis in law. The tool flags this automatically when you select health, biometric, genetic, criminal or political and religious data in an activity.

Retention, Transfers and DPIAs

Retention. The GDPR publishes no table of periods. Article 5(1)(e) requires storage limitation — data kept in identifiable form no longer than necessary for the purposes — and the actual periods come from national law, sector rules and your own documented justification. The schedule here is a starting point drawn from common practice: employment records held for years after termination under national employment and tax law, transaction records aligned to tax audit windows, CCTV usually measured in weeks unless an incident is preserved, recruitment data for a defined window after rejection. All of these vary by country. Replace the defaults with the periods your own obligations set, and record the reason next to each.

Transfers. Chapter V permits transfers to a third country covered by a Commission adequacy decision under Article 45 without additional safeguards. Where no adequacy decision applies, Article 46 safeguards such as Standard Contractual Clauses or Binding Corporate Rules are needed, with the derogations in Article 49 available only in narrow circumstances. The adequacy list changes — Brazil was added in January 2026 — so verify the current list on the European Commission’s site before relying on it. Adequacy is also sometimes partial: Canada’s covers commercial organisations subject to PIPEDA, and the United States decision covers only organisations certified under the EU–US Data Privacy Framework.

DPIAs. Article 35(1) requires an assessment where processing is likely to result in a high risk to rights and freedoms, particularly using new technologies. Article 35(3) names three cases: systematic and extensive automated evaluation of personal aspects, including profiling, on which decisions producing legal or similarly significant effects are based; large-scale processing of special categories or criminal conviction data; and systematic monitoring of a publicly accessible area on a large scale. Supervisory authorities publish their own lists too. The checker evaluates the triggers it can infer from your activities and explicitly marks the ones — automated decision-making and public-area monitoring — that need your own judgement.

Frequently Asked Questions

Does the exported PDF satisfy Article 30 on its own?

It produces a record in the required structure, populated with what you entered. Whether it satisfies your obligation depends on whether what you entered is complete and accurate — a register that omits half your processing is not a compliant record however well formatted. Treat it as the document you maintain, not a one-off deliverable.

Is this legal advice?

No. It is an informational aid. Role determination in particular is fact-sensitive and has been litigated repeatedly; the tool gives you a reasoned starting position, not a legal conclusion. Have counsel or your DPO confirm anything you intend to rely on.

Can I be a controller for some activities and a processor for others?

Yes, and most organisations are. A SaaS company is typically a processor for customer content and a controller for its own employee and marketing data. Run the role determination separately per activity rather than adopting one label for the whole company.

Do I need a Data Protection Officer?

Article 37 requires one where processing is carried out by a public authority, where core activities require regular and systematic monitoring of data subjects on a large scale, or where core activities consist of large-scale processing of special categories or criminal conviction data.

My company has fewer than 250 employees. Do I still need records?

Almost certainly. The Article 30(5) exemption is narrow and lapses for processing that is not occasional, that risks rights and freedoms, or that involves special categories. Routine payroll and customer processing fails the “occasional” test immediately.

How long should I keep employee records?

There is no single GDPR answer — the period comes from national employment, tax and limitation law in each country you employ people. The defaults in the retention calculator reflect common practice in several jurisdictions; confirm against the law that binds you and record that basis in the schedule.

Is the adequacy country list in the tool current?

It reflects the position at the time it was built and can lag Commission decisions. Always verify the current adequacy list on the European Commission’s data protection pages before relying on it for a live transfer.

Does my data leave my browser?

No. Everything you enter stays in the browser and the PDF is generated locally. Nothing is transmitted to us.

What should I do alongside this?

Check that your public-facing surface matches your register: run the GDPR compliance checker against your live site, and rebuild the notice with the privacy policy generator if the disclosures no longer match reality. To turn the retention schedule into enforceable handling rules, build a classification scheme with the data classification policy architect.

What Is GDPR Role and Retention Mapping

The General Data Protection Regulation (GDPR) requires organizations to define clear data processing roles and implement retention policies that limit how long personal data is stored. Role mapping identifies whether each entity in your data processing chain is a Controller (determines purposes and means of processing), Processor (processes data on behalf of a Controller), or Joint Controller — each role carrying distinct legal obligations.

Retention mapping ensures that personal data is not kept longer than necessary for its stated purpose, a core principle of GDPR known as storage limitation (Article 5(1)(e)). Together, role and retention mapping form the operational backbone of GDPR compliance, answering two critical questions: who is responsible for this data, and how long can we keep it?

GDPR Roles Explained

RoleDefinitionKey ObligationsExample
ControllerDetermines purposes and means of processingLawful basis, data subject rights, breach notification (72h), DPIACompany using CRM to manage customer relationships
ProcessorProcesses personal data on behalf of ControllerFollow Controller instructions, security measures, breach notification to ControllerCloud hosting provider storing customer database
Joint ControllerTwo+ entities jointly determine purposesTransparent arrangement defining responsibilities, single point of contact for data subjectsTwo companies running a joint marketing campaign
Sub-ProcessorProcessor engaged by another ProcessorSame obligations as Processor, Controller must approve engagementCDN provider used by the cloud host

Retention Period Guidelines

Data CategoryTypical RetentionLegal Basis
Customer transaction records6-7 yearsTax and accounting law
Employee recordsDuration of employment + 6 yearsEmployment law, limitation periods
Marketing consent recordsUntil consent is withdrawnGDPR Article 7
Website analytics26 months (GA default)Legitimate interest
CCTV footage30 daysLegitimate interest
Job application data6-12 months after decisionLegitimate interest for legal claims
Medical recordsVaries by jurisdiction (often 10+ years)Legal obligation

Common Use Cases

  • GDPR compliance audit: Map every personal data processing activity to a defined role (Controller/Processor) and documented retention period
  • Data Processing Agreement (DPA) preparation: Identify all Processor relationships that require DPAs under Article 28, and define retention requirements in each agreement
  • Records of Processing Activities (ROPA): Build the Article 30 register by documenting each processing activity with its role classification, purpose, retention period, and legal basis
  • Data minimization implementation: Identify data stores where personal data is retained beyond its stated purpose and implement automated deletion
  • Vendor assessment: Evaluate whether third-party vendors are correctly classified as Processors or Controllers and verify their retention practices align with your policies

Best Practices

  1. Document roles for every data flow — Map each personal data processing activity to a specific role. A single vendor might be a Controller for some data (their own analytics) and a Processor for other data (your customer records).
  2. Set specific retention periods, not indefinite — "As long as necessary" is not a valid retention policy. Define concrete timeframes based on legal requirements, business need, or data subject expectations.
  3. Automate deletion — Manual retention enforcement fails at scale. Implement automated data lifecycle management that flags or deletes data when its retention period expires.
  4. Review retention annually — Business needs and legal requirements change. Review retention schedules at least annually and after any significant change in processing activities.
  5. Include backups in retention scope — Backup copies of personal data are still personal data. Ensure backup retention aligns with your defined periods and that restoration processes account for deletion requests.

Frequently Asked Questions

What is the difference between a controller and processor under GDPR?+

A data controller determines the purposes and means of processing personal data (decides why and how data is processed). A data processor processes data on behalf of the controller (follows the controller's instructions). Joint controllers occur when two or more entities jointly determine processing purposes. Each role has different obligations under GDPR.

What is a Record of Processing Activities (Article 30)?+

Article 30 of GDPR requires controllers and processors to maintain written records of processing activities. Records must include: purposes of processing, categories of data subjects and data, recipients, international transfers, retention periods, and security measures. This tool generates Article 30 compliant records.

How do I determine data retention periods?+

Retention periods depend on: legal requirements (tax records: 7 years, medical records: varies by jurisdiction), contractual obligations, legitimate business need, and data minimization principle. Under GDPR, data must not be kept longer than necessary for its purpose. This tool calculates retention periods based on data type and jurisdiction.

What are the six legal bases for processing under GDPR?+

GDPR Article 6 defines six legal bases: Consent (freely given, specific, informed), Contract (necessary for contract performance), Legal Obligation (required by law), Vital Interests (protecting life), Public Task (official authority or public interest), and Legitimate Interests (balanced against data subject rights). Each processing activity must have a valid legal basis.

What is a Data Protection Impact Assessment (DPIA)?+

A DPIA is required under GDPR Article 35 when processing is likely to result in high risk to individuals. This includes systematic profiling, large-scale processing of special categories, and public area monitoring. The DPIA must describe processing, assess necessity and proportionality, identify risks, and define mitigation measures. This tool includes a DPIA necessity checker.

Related tools

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.