# Records of processing activities 30(2) — GDPR — provision context

> Focused context for a single provision (30(2)), curated from overview.legal on 2026-08-22. Canonical: https://overview.legal/laws/gdpr/art-30#par-2
> Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

Part of **Records of processing activities** (GDPR, full article: https://overview.legal/laws/gdpr/art-30).

## Provision text

### 30(2)

Each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing:

a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's representative, and the data protection officer;
b) the categories of processing carried out on behalf of each controller;
c) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;
d) where possible, a general description of the technical and organisational security measures referred to in Article 32(1).

## Topics on this provision

- **Representatives** — https://overview.legal/topics/representatives
  Representatives of controllers not established in the EU
- **Processors** — https://overview.legal/topics/processors
  Entities that process data on behalf of controllers
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

## Cited by (exact-provision citations)

- **Guidelines 07/2020 on the concepts of controller and processor in the GDPR** (guidance) — https://overview.legal/posts/38069
- **Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)** (guidance) — https://overview.legal/posts/38074
- **Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)** (guidance) — https://overview.legal/posts/125849
- **Opinion 17/2020 on the draft Standard Contractual Clauses submitted by the SI SA (Article 28(8) GDPR)** (guidance) — https://overview.legal/posts/126161
- **EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)** (guidance) — https://overview.legal/posts/126050
- **EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)** §202 (guidance, EDPB) — https://overview.legal/posts/126050

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-30#par-2 · 2026-08-22
