Ir al contenido
Launch offerOnly until … — after that, prices go back to normal.See pricing

Data protection

Record of processing activities (RAT): what it is and why almost no company escapes it

Author: Tranquilia by GRAC SA4 min read

General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.

Direct answer: the record of processing activities (RAT, from the Spanish registro de actividades de tratamiento) is the document where you write down what personal data you process, what for and for how long. It is required by article 30 of Reglamento (UE) 2016/679 (RGPD, the EU's general data protection regulation). Many people believe that companies with fewer than 250 employees are exempt, but that exception almost never applies: as soon as you process data on a regular basis (your customers, your staff), you are under the obligation again. Tranquilia generates it from a short questionnaire, without you having to draft it from scratch.

Contents

What is the record of processing activities?

It is an inventory. Nothing more, and nothing less. Every time your business uses people's data — the customer list, your employees' payroll, the CVs you receive, the security camera — that is a "processing activity", and the RAT gathers them all in one place.

It is not a complicated legal text: it is an orderly table that answers, for each processing operation, five simple questions: what data, whose, what for, who sees it and how long you keep it.

Why is it obligatory (and the 250-employee trap)?

Article 30 of the RGPD requires you to keep this record. Paragraph 30.5 says that companies with fewer than 250 employees could get out of it... but with three exceptions that switch it back on almost always:

  • When the processing is not occasional (having customers or employees on a continuous basis already counts).
  • When it may involve a risk to people's rights.
  • When it includes special categories of data (health, trade union membership) or data on convictions.

In practice, any business with regular customers or with staff processes data "on a non-occasional basis". That is why the exemption for those with fewer than 250 employees is more theoretical than real: almost all SMEs and self-employed people are still obliged to have the RAT.

What does it have to include?

Art. 30 itself sets the minimum content. For each activity:

  1. The name and contact details of the controller (your company).
  2. The purposes of the processing (why you process that data).
  3. The categories of people and of data affected.
  4. Who the data is disclosed to (gestoría, Hacienda, suppliers).
  5. The time limits envisaged for erasing it.
  6. A general description of the security measures.

What risk do you run if you do not have it?

The AEPD (Agencia Española de Protección de Datos, Spain's data protection authority) is the body that supervises this. Not having the RAT is one of the first things detected in an inspection, because it is the document that summarises everything else: if it does not exist, the assumption is that the rest is not there either.

The RGPD sets the maximum penalties at two levels: up to 10 million euros or 2% of worldwide turnover, and up to 20 million or 4%, depending on the infringement (art. 83 RGPD); the higher figure applies. Those figures are the legal ceiling, not the usual outcome: the penalty is graded according to the seriousness, the size of the business and whether you have cooperated. For an SME, the most frequent thing is not the maximum fine, but the absence of the RAT aggravating another complaint you already had on your hands.

How Tranquilia generates it

Instead of starting from a blank template, you answer a guided questionnaire about your activity and Tranquilia fills in the RAT with the typical processing operations of your trade, already identified. If you are a gestoría (a Spanish firm that handles other businesses' tax, payroll and administrative filings), you generate one for each client company you register. You can try it with up to 2 companies, with no card and no time limit.

Frequently asked questions

Do I have to make a RAT if there are only two of us?

Yes, unless you only process data on a truly occasional basis, which is unusual if you have regular customers or employees. Size alone does not exempt you: what counts is how you process the data, not how many of you there are.

Does the RAT have to be sent to the AEPD?

No. The RAT is not filed or sent to anyone: you keep it and you show it if the AEPD asks you for it. It is an internal document, but an obligatory one.

How often is it updated?

Whenever something real changes: a new processing operation, a new supplier, a change in the time limits. There is no fixed date, but a RAT that has not been touched for years is usually out of date.

Official sources


General information on legislation. It does not replace the advice of a lawyer or the analysis of your specific case. If you have any doubts, consult your gestoría or a legal professional.

Review: Translation of the Spanish original, which prevails in case of divergence.

Get your clients GDPR-compliant in 15 minutes.

Set up my free instance

No card, no sales calls. Two companies free, for as long as you like.

Blog