The record of processing activities is the first document the Data Protection Authority asks for at an inspection or after a complaint, and the document most SMEs do not have. Not out of unwillingness, but because nobody knows what goes in it. For the workplace it is simpler than it seems: every Canvos module is one processing activity with a fixed purpose, fixed categories of data, one processor in Europe and a retention period you set in the retention policy. This guide walks through the columns of the record, gives the entries per Canvos module, and provides a template as PDF that you complete with the activities outside the workplace, such as customer administration, accounting and HR.
Step by stepSix steps
1. Who is controller and who is processor 2. One row per Canvos module 3. Legal basis and purpose 4. Recipients, processors and transfers 5. Retention periods: from the retention policy 6. Technical and organisational measures
Who is controller and who is processor
Your organisation decides purpose and means and is therefore the controller. Canvos processes the data on your instructions and is the processor, with a data processing agreement that fixes instructions, security, sub-processors and the location of the data. At the top of the record you note the name and contact details of your organisation and, if you have one, of the data protection officer. For the workplace you note Canvos as processor established in Belgium, processing on infrastructure in the European Union.
One row per Canvos module
Every module is a processing activity with a clear purpose:
- Email: business communication with customers, suppliers and colleagues. Data: name, email address, content of messages and attachments. Data subjects: customers, suppliers, employees, contacts.
- Files and documents: storage and collaboration. Data: whatever the documents contain, from quotes to HR files; the data classification labels help you name the sensitive categories.
- Calendar: scheduling appointments. Data: name, email address, time, subject, possibly location.
- Contacts: address book. Data: name, function, organisation, email, phone.
- Chat and video meetings: internal and external communication. Data: name, messages, shared files; no recording of meetings unless you make one yourself.
- Vault: passwords and secrets of the organisation, encrypted; personal data limited to usernames.
- User management and logs: security and accountability. Data: username, IP address, country, device, time, policy actions. Legal basis: legitimate interest (security) and legal obligation (NIS2).
- Backups: business continuity. An encrypted copy of the above, with its own retention period.
Legal basis and purpose
For mail, files, calendar and contacts the legal basis is usually the performance of a contract with the customer or the employment contract with the employee, supplemented by legal obligations (accounting law, social legislation) and legitimate interest (normal business operations). For logs and security it is legitimate interest and, for NIS2 entities, legal obligation. Note the concrete purpose per row in one sentence; 'communication' is too vague, 'exchanging quotes and invoices with customers' is good.
Recipients, processors and transfers
In the recipients column you note who sees the data: your employees according to their role, and Canvos as processor. Sub-processors are the European hosting party Canvos runs on; the list is in the data processing agreement. Transfer outside the EU: none. That is the big difference with a US cloud workplace, where you have to explain per processing activity on which basis data goes to the US and which supplementary measures you took. In Canvos you fill that column with 'not applicable' and refer to the location of the infrastructure.
Retention periods: from the retention policy
The GDPR asks per activity for a retention period or the criterion for it. In Canvos you set those under Retention policy: email for example seven years (accounting retention duty), recycle bin thirty days, file versions ninety days, audit log two years, backups thirty daily and twelve weekly copies. Copy those values literally into the record. That way the record is not a promise but a description of what the system does, and at an inspection the Governance Center shows that retention is actually executed and logged.
Technical and organisational measures
Article 30 asks for a general description of the security measures. For the workplace: encryption in transit (TLS) and of backups (AES-256), two-factor authentication, roles and rights per group, data classification with labels and DLP on national register numbers and IBANs, sharing policy with password and expiry, login log with detection of suspicious sign-ins, hashed and anchored evidence chain, retention executed automatically, daily encrypted backups with your own key, hosting in the EU by a Belgian processor. Add your organisational measures: policy, training, procedure when an employee leaves, incident plan. The compliance score and the report in the Governance Center are the accompanying evidence.
FAQFrequently asked questions
Does my organisation have to keep a record?
Yes, unless you have fewer than 250 employees and the processing is occasional, involves no risk and concerns no special categories. In practice almost every organisation with staff or customers falls under the obligation, because staff and customer data are processed structurally.
Is the template legal advice?
No. It is a practical completion for the workplace, based on Article 30 GDPR and the guidance of the Data Protection Authority. Have the record reviewed by your DPO or legal adviser, certainly for special categories of data such as health or criminal data.
How often must I update the record?
At every new processing activity, new processor or changed retention period, and at least yearly. If you change the retention policy in Canvos, update the record too; the Governance Center logs the change with a date.
Where is the data processing agreement with Canvos?
It is part of your customer agreement and describes instructions, security, sub-processors, location of the data, assistance with data breaches and what happens at the end of the agreement. Request the current version through your contact person.