18-07-2025 – The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) recently issued a Joint Opinion on the European Commission’s proposal to reduce record-keeping obligations for small mid-cap enterprises (SMCs) under the General Data Protection Regulation (GDPR). The Commission’s proposed changes are part of the Omnibus IV Simplification Package, a larger project to extend exemptions for SMCs, promoting economic growth in the EU. In this blog, we discuss the Commission’s proposal, the Joint Opinion, and the likely impact on businesses.
Current ROPA requirements
Under Article 30 of the GDPR, both the controller and processor must maintain a record of processing activities (ROPA), unless these organizations have fewer than 250 employees. However, small organizations must still conduct a ROPA for processing activities that are i) likely to result in a risk to the rights and freedoms of data subjects, ii) not occasional, or iii) include special categories of data or data related to criminal convictions.
These broad exemptions mean that in practice, nearly every company (regardless of size) needs to set up a ROPA. The Working Party 29 (currently known as the EDPB) only considers a processing activity occasional if it is not carried out regularly and occurs outside the regular course of business or activity of the controller or processing. Any organization employing personnel likely engages in non-occasional data processing though their HR or pay-related activities, according to the Irish Data Protection Commission, and will at least need to include these activities in a ROPA.
Proposed changes
In the proposed amendment to Article 30 of the GDPR, however, organizations with fewer than 750 employees would only need to maintain a ROPA when their processing is likely to result in a high risk to data subjects’ rights and freedoms. The Commission utilizes the definition of high risk contained in Article 35 of the GDPR (on Data Protection Impact Assessments). In particular, processing activities should be included in a ROPA if they i) systematically and extensively evaluate personal aspects of an individual, such as profiling; ii) process sensitive data on a large scale; or iii) systematically monitor public areas on a large scale.
Yet as the EDPB notes, the Article 35 definition of “high risk” also excludes many processing activities, such as those that are non-occasional but do not involve sensitive data or systemic monitoring (for example, an online magazine using a mailing list to send a generic daily digest to its subscribers). By no longer requiring all non-occasional processing activities to be added to a ROPA, the proposal may significantly reduce the amount of processing activities recorded by small organizations.
Moreover, the proposal consolidates the requirements for two separate obligations: when processing is likely to result in a high risk, organizations should now both conduct an DPIA and add the processing activity to a ROPA. Organizations can likely comply with the new requirements by adding a DPIA to their processing register, since the information required by clause 1 and 2 in Article 30 GDPR is often already listed in the DPIA.
Reasoning
The reduction of record-keeping obligations for SMCs is part of the Omnibus simplification packages, a broader series of proposals to reduce the complexity of EU legislation for businesses and extend proportionality in EU regulations to small and medium-sized enterprises (SMEs). The Commission recognizes that current ROPA requirements place the same burden on SMCs and large enterprises, while they do not have access to the same legal resources.
EDPB-EDPS response
The EDPB and EDPS Joint Opinion recommend clarification on three points. First, the Commission should clarify whether only processing activities ‘likely to result in a high risk' should be included in a ROPA, or whether a ROPA including all activities is mandatory when at least one of these processing activities is likely to result in a high risk.
Second, the opinion notes the significance of removing two major categories of processing activities—non-occasional processing and processing of special categories of personal data or personal data relating to criminal convictions and offences. The processing of such data may be one of the factors that leads to the likelihood of a high risk.
Lastly, the EDPB and EDPS recommend clarifying the scope of the amendment. The Commission definitions of SMEs and SMCs both include caps on annual turnover and balance sheets. However, the text of the amendment only refers to “an enterprise […] employing fewer than 750 persons.” Thus, there is some uncertainty about whether the new exemption would apply to an organization employing fewer than 750 employees, but with a high annual turnover or balance sheet.
Implications
Records of processing remain a useful tool for compliance with a range of GDPR requirements. To assess whether their data processing meets the GDPR definition of high-risk activity, companies will still need to assess the full range of their processing activities, possibly through a pre-DPIA or DPIA checklist. Moreover, the proposal does not affect other GDPR requirements that mandate a complete knowledge of data processing activities, such as the requirement to establish a legal basis and purpose for the processing of personal data and to inform data subjects about each processing activity. Companies should also be aware that the Commission’s proposal has not yet passed through the complete EU legislative procedure. Approval from both the European Parliament and the Council may take around 18 months. Setting up a ROPA will therefore remain mandatory for most organizations in the foreseeable future.
Conclusion
Despite proposed changes to the GDPR, it remains imperative that companies understand the full range of their data processing activities in order to assess their obligations. At Considerati, we specialize in helping companies gain insight into their processing activities and guiding them through evolving legislation. If your organization is seeking clarity on compliance support, we are ready to assist you and invite you to contact our team for a consultation.
Considerati's legal experts are ready to help your organisation comply with the new rules coming into force on 1 July 2026. Reach out to us for tailored advice or practical training.
Contact
Recente blogs
The right of access is one of the fundamental rights in the General Data Protection Regulation (GDPR). In this blog, we outline the main pitfalls from…