← Back to Compliance
GDPR

GDPR — Article 30

GDPR Art. 30 requires controllers and processors to maintain records of all processing activities. AI tool usage involving personal data — sending customer records, employee data, or user information to external AI models — is a processing activity that must be documented.

Records of processing activities · Applies to all EU data controllers

Art. 30(1) Records of processing — controller obligations

Controllers must maintain records including purposes of processing, categories of data subjects and personal data, recipients of personal data (including third parties), and retention periods. AI model providers receiving personal data are recipients under Art. 30.

Automatically generates Art. 30 records for AI tool processing activities — capturing data categories detected, AI provider recipients, timestamps, and retention metadata. Exportable as structured compliance reports for DPO review or regulatory submission.

Document your AI processing activities for GDPR

See how Svalin automatically generates the records your DPO needs.

Request a Demo