WCapsuleM8

Data Processing Record

Free

Build a register of processing activities: purpose, data subjects, data categories, lawful basis, retention, transfers and impact assessments, with a gap list and a printable report. Runs entirely in your browser — nothing is uploaded.

Version 1.0.0 · Updated Aug 5, 2026

Overview

CM8-166 builds a register of processing activities: a line for every distinct purpose for which your organisation uses personal data, with the categories of people and data involved, the lawful basis claimed, who it is shared with, how long it is kept, whether it leaves the country, and whether an impact assessment was needed and done. It then counts what is missing and prints the lot. Almost every privacy regime expects a register of this kind, and almost nobody has one. The reason is rarely disagreement — it is that nobody has sat down and listed the activities. This tool gives you the list and the arithmetic; the sitting down is still yours.

How to use Data Processing Record

The complete in-tool guidance, reproduced here so you can read it before you download.

What this tool does

CM8-166 builds a register of processing activities: a line for every distinct purpose for which your organisation uses personal data, with the categories of people and data involved, the lawful basis claimed, who it is shared with, how long it is kept, whether it leaves the country, and whether an impact assessment was needed and done. It then counts what is missing and prints the lot.

Almost every privacy regime expects a register of this kind, and almost nobody has one. The reason is rarely disagreement — it is that nobody has sat down and listed the activities. This tool gives you the list and the arithmetic; the sitting down is still yours.

Everything runs inside this single file. No account, no upload, no network request. That matters here, because a register naming systems, providers, retention periods and weaknesses is a map of where your personal data lives.

What counts as one activity

Record one entry per purpose, not per system and not per data field. "Payroll and pension administration" is one activity even though it touches four systems. "The HR system" is not an activity at all — it is a container, and it probably holds three or four purposes that have different lawful bases and different retention periods.

The test is simple: if you would give two different answers to "why do you hold this?", they are two activities. If the honest answer to "how long do you keep it?" differs, they are two activities.

A first register of twenty to forty lines is normal for a small organisation. If you have four, you have not finished looking. Ask each area what they hold that they did not create themselves.

What each field means

  • Categories of data subject — whose data it is. Children, patients and members are listed separately because most regimes treat them as needing more care.
  • Categories of personal data — pick the main one for grouping and charting, then list everything else in the free-text field beneath. The tool groups on one category so the charts stay readable; the register still holds the full list.
  • Source — where it came from. Data you did not get from the person usually carries an extra duty to tell them you hold it.
  • Recipients — name them. "Third parties" is not a recipient. Include suppliers acting purely on your instructions, and say which is which.
  • Security measures — what actually protects it: access control, encryption, backup, and how it is destroyed when the retention period ends. Deletion is a security measure.
  • Owner — record a role rather than a person where you can. People leave; the register should not go stale when they do.

Lawful basis

Every activity needs a basis, and the tool flags any line where one has not been recorded. Read this next sentence twice: recording a lawful basis does not make it valid. The field records a claim. Whether the claim holds depends on facts this tool has no access to.

Two bases cause most of the trouble:

  • Consent has conditions attached almost everywhere it appears — it generally has to be freely given, specific, informed, unambiguous and as easy to withdraw as to give, and you usually have to be able to show when and how it was obtained. This tool cannot test any of that. It only knows you selected the word. Consent also fails badly where there is an imbalance of power, which is why relying on it for employee data is usually a mistake.
  • Legitimate interests is not a free pass. It normally requires a written balancing assessment: what the interest is, whether the processing is necessary to achieve it, and whether the effect on the person is outweighed. The tool has a checkbox for whether that assessment exists and flags the activity when the basis is legitimate interests and the box is unticked. It cannot tell whether the assessment reached a defensible conclusion.

Special category data generally needs a second, separate condition on top of the ordinary basis. This tool does not model that second condition — record it in the purpose or notes field.

Special category data

Tick the box and pick the type where the activity involves data that is treated as more sensitive: health, biometric, genetic, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation, or criminal matters. Exactly which categories are special, and what extra conditions apply, vary by country — the list here is the common core, and "other data treated as sensitive where you operate" is there for local additions.

The tool refuses the two contradictions that make a register untrustworthy: the box ticked with no type, and a type selected with the box unticked.

Sending data abroad

Tick the transfer box if data goes to, or can be accessed from, another country — including remote support access and a supplier's overseas team. Then record the safeguard you rely on. The tool flags any transfer where the safeguard is "none recorded".

The safeguard list is deliberately generic: contractual terms, a formal recognition that the destination offers comparable protection, binding internal rules across a group, explicit consent, or one-off necessity. Which of these are available to you, what they must contain, and whether a further assessment of the destination is required, differ by country. The tool records your answer; it does not validate it.

Retention periods

Enter the period in months, so that a five-year and a ninety-day period can be compared on one scale. Leave it blank if it genuinely has not been decided — the tool then lists it as a gap, which is the honest outcome.

Retention periods are set by law and by purpose, not by preference. Some records have a minimum period imposed by employment, tax, health and safety or sector rules. Others must go once the purpose is finished, whatever anybody would prefer. "We might need it one day" is not a retention period, and neither is the storage capacity of the system.

Average retention = sum of the recorded periods ÷ number of activities with a period recorded

The average deliberately ignores activities with no period recorded — averaging them in as zero would reward not deciding. Because one very long period drags the mean upwards, the tile also shows the median, which is the middle value of the recorded periods. When the mean is far above the median, one or two long-retention activities are doing all the work and the mean is not a useful summary.

The retention schedule marks anything longer than the threshold on the Settings tab, so a long period has to be justified by somebody rather than inherited.

Impact assessments

Two checkboxes: whether an assessment is required, and whether it has been done. Where required is ticked and done is not, the activity appears in the gap list and picks up risk points.

An impact assessment is a process, not a checkbox. Ticking "done" here records that something happened. A real assessment describes the processing, tests whether it is necessary and proportionate, identifies the risks to the people affected, records the measures that reduce those risks, and is revisited when the processing changes. Where the residual risk stays high, some regimes require you to consult the supervisory authority before starting.

Deciding whether one is required is also your judgement, not the tool's. Large-scale use of sensitive data, systematic monitoring, profiling with significant effects, and new technologies applied to people are the usual triggers, but the formal criteria differ by country.

How the risk score is built

The score is a ranking device with four inputs, each weighted on the Settings tab:

Risk score = (special category data ? wspecial : 0) + (sent outside the country ? wtransfer : 0) + (assessment required and not done ? wassessment : 0) + (basis is consent ? wconsent : 0)

With the default weights of 3, 2, 3 and 1, the highest possible score is 9 and anything at or above 5 is drawn in red. Change the weights if they do not match how your organisation thinks; the tool has no opinion about the right numbers.

Be clear about what this is. It ranks the lines in your register against each other so you know where to start. It does not measure risk to the people whose data it is, it does not know how many records are involved, how good your security is, or what would happen if the data were lost. An activity scoring zero can still be the one that hurts somebody.

Reviews and overdue

Every activity carries a next review date, which is also the date the filters and the monthly chart use.

Days to review = review date − today · Overdue = days to review < 0 and the status is not "retired"

Retired activities are excluded from the overdue count because the processing has stopped — but they stay in the register, and they still appear in the gap list, because the data may still exist. The warning window on the Settings tab controls how far ahead a review is flagged as approaching.

Spread the review dates. A register where every line falls due in the same month is a register that will be rubber-stamped once a year rather than reviewed.

The gap list

An activity appears in the compliance gap table when any of these is true:

  • no lawful basis has been recorded;
  • an impact assessment is marked as required but not done;
  • the basis is legitimate interests and no balancing assessment has been recorded;
  • data is sent outside the country with no safeguard recorded;
  • no retention period has been decided.

These are gaps in the record. Closing them makes the register complete. It does not make the processing lawful, and an activity with no gaps can still be one you should not be doing at all.

What this tool cannot do

It does not check anything against any law. It does not know which regime applies to you, and there is more than one. It cannot tell whether a basis is available, whether consent was validly obtained, whether a retention period is defensible, whether a transfer safeguard is the right one, or whether an assessment was competent. It does not notify anybody, register anything, or respond to a request from a person about their own data.

What it does is stop the register living in somebody's head, in three spreadsheets, or nowhere.

Printing and sharing

Print Report produces a report from whatever the current filter shows: header, headline figures, the four charts, the gap list, the retention schedule, the full register and your closing notes. Print to PDF to circulate it or to keep a dated copy alongside the version you show an auditor.

The scope line under the title states the filter in force. Clear the filters before issuing anything described as the complete register — a filtered print is a partial record, and it will not look like one.

Saving your work

Activities, settings and the report header are written to this browser's local storage as you type, and the toolbar shows the time of the last save. That storage belongs to one browser on one computer: another browser, a private window, a second machine or a tool that clears site data will not have it.

Treat Export .json as the real save — one file containing everything, which Import .json restores anywhere. Export CSV gives you the register for spreadsheet work and includes every filtered record, not only those drawn on screen. Reset asks twice, then erases everything this tool has stored. There is no undo.

Accuracy & disclaimer

This tool records what you enter and calculates from it. Every figure it produces depends on entries it cannot verify. It is a record-keeping and calculation aid, not legal advice, not a compliance assessment and not a submission to anybody.

What must be recorded, which lawful bases exist, what makes consent valid, which data is special, how long records must be kept and what a transfer outside the country requires all differ by country and by sector, and they change. Establish what applies to you, and take advice where the answer matters.