WCapsuleM8

Data Processing Record

Free

Build a register of processing activities: purpose, data subjects, data categories, lawful basis, retention, transfers and impact assessments, with a gap list and a printable report. Runs entirely in your browser — nothing is uploaded.

Version 1.0.0 · Updated Aug 20, 2026

Use Data Processing Record now

Runs in your browser · nothing is uploaded

This in-page version cannot save your work between visits — browser storage is switched off inside the sandbox. Download the free file to keep your data on your own computer.

Overview

CM8-166 builds a register of processing activities: a line for every distinct purpose for which your organisation uses personal data, with the categories of people and data involved, the lawful basis claimed, who it is shared with, how long it is kept, whether it leaves the country, and whether an impact assessment was needed and done. It then counts what is missing and prints the lot. Almost every privacy regime expects a register of this kind, and almost nobody has one — rarely through disagreement, usually because nobody has sat down and listed the activities. This tool gives you the list and the arithmetic; the sitting down is still yours. Everything runs inside this single file, with no account, upload or network request — which matters when a register names your systems, providers and weaknesses.

Frequently asked questions

Is the Data Processing Record really free?

Yes. The Data Processing Record is a free download with every feature included — no trial period, no locked features and no account required.

Does my data stay private when I use the Data Processing Record?

Yes. The tool is a single HTML file that runs entirely on your computer and makes no network requests, so nothing you enter is ever uploaded or shared.

Does the Data Processing Record work offline?

Yes. Once downloaded it runs completely offline in any modern browser — no internet connection, installation or plugins needed.

Do I need Excel or any other software to use the Data Processing Record?

No. It replaces the spreadsheet template entirely: open the file in your browser (Chrome, Edge, Firefox or Safari) on Windows, Mac, Linux or a tablet, and start working.

How to use Data Processing Record

The complete in-tool guidance, reproduced here so you can read it before you download.

What this tool does

CM8-166 builds a register of processing activities: a line for every distinct purpose for which your organisation uses personal data, with the categories of people and data involved, the lawful basis claimed, who it is shared with, how long it is kept, whether it leaves the country, and whether an impact assessment was needed and done. It then counts what is missing and prints the lot.

Almost every privacy regime expects a register of this kind, and almost nobody has one — rarely through disagreement, usually because nobody has sat down and listed the activities. This tool gives you the list and the arithmetic; the sitting down is still yours. Everything runs inside this single file, with no account, upload or network request — which matters when a register names your systems, providers and weaknesses.

What counts as one activity

Record one entry per purpose, not per system and not per data field. "Payroll and pension administration" is one activity even though it touches four systems. "The HR system" is not an activity at all — it is a container holding three or four purposes with different lawful bases and retention periods.

The test is simple: if you would give two different answers to "why do you hold this?", they are two activities. If the honest answer to "how long do you keep it?" differs, they are two activities. A first register of twenty to forty lines is normal for a small organisation; if you have four, you have not finished looking.

What each field means

  • Categories of data subject — whose data it is. Children, patients and members are listed separately because most regimes treat them as needing more care.
  • Categories of personal data — pick the main one for grouping and charting, then list everything else in the free-text field beneath, so the charts stay readable while the register still holds the full list.
  • Source — where it came from. Data you did not get from the person usually carries an extra duty to tell them you hold it.
  • Recipients — name them. "Third parties" is not a recipient. Include suppliers acting purely on your instructions, and say which is which.
  • Security measures — what actually protects it: access control, encryption, backup, and how it is destroyed when the retention period ends. Deletion is a security measure.
  • Owner — a role rather than a person where you can, so the register does not go stale when somebody leaves.

Lawful basis

Every activity needs a basis, and the tool flags any line where one has not been recorded. Read this next sentence twice: recording a lawful basis does not make it valid. The field records a claim, and whether the claim holds depends on facts this tool has no access to. Two bases cause most of the trouble:

  • Consent has conditions attached almost everywhere it appears — generally it must be freely given, specific, informed, unambiguous and as easy to withdraw as to give, and you usually have to show when and how it was obtained. This tool cannot test any of that. It only knows you selected the word. Consent also fails where there is an imbalance of power, which is why relying on it for employee data is usually a mistake.
  • Legitimate interests is not a free pass. It normally requires a written balancing assessment: what the interest is, whether the processing is necessary, and whether the effect on the person outweighs it. The tool flags the activity when this basis is used and the assessment box is unticked; it cannot tell whether the assessment reached a defensible conclusion.

Special category data generally needs a second, separate condition on top of the ordinary basis. The tool does not model that second condition — record it in the purpose field.

Special category data

Tick the box and pick the type where the activity involves data treated as more sensitive: health, biometric, genetic, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation, or criminal matters. Exactly which categories are special, and what extra conditions apply, vary by country — the list here is the common core, and "other data treated as sensitive where you operate" covers local additions.

The tool refuses the two contradictions that make a register untrustworthy: the box ticked with no type, and a type selected with the box unticked.

Sending data abroad

Tick the transfer box if data goes to, or can be accessed from, another country — including remote support access and a supplier's overseas team — then record the safeguard you rely on. The tool flags any transfer where the safeguard is "none recorded".

The safeguard list is deliberately generic. Which options are available to you, what they must contain, and whether a further assessment of the destination is required, differ by country. The tool records your answer; it does not validate it.

Retention periods

Enter the period in months, so a five-year and a ninety-day period compare on one scale. Leave it blank if it genuinely has not been decided — the tool then lists it as a gap, which is the honest outcome.

Retention periods are set by law and by purpose, not by preference. Some records carry a minimum period imposed by employment, tax, safety or sector rules; others must go once the purpose is finished, whatever anybody would prefer. "We might need it one day" is not a retention period, and neither is the storage capacity of the system.

Average retention = sum of the recorded periods ÷ number of activities with a period recorded

The average ignores activities with no period recorded — averaging them in as zero would reward not deciding. Because one long period drags the mean upwards, the tile also shows the median, the middle recorded value. When the mean sits far above the median, one or two long-retention activities are doing all the work. The schedule marks anything longer than the threshold on the Settings tab, so a long period has to be justified rather than inherited.

Impact assessments

Two checkboxes: whether an assessment is required, and whether it has been done. Where required is ticked and done is not, the activity appears in the gap list and picks up risk points.

An impact assessment is a process, not a checkbox. Ticking "done" here records that something happened. A real assessment describes the processing, tests whether it is necessary and proportionate, identifies the risks to the people affected, records the measures that reduce those risks, and is revisited when the processing changes. Where residual risk stays high, some regimes require you to consult the supervisory authority before starting.

Deciding whether one is required is your judgement, not the tool's. Large-scale use of sensitive data, systematic monitoring, and profiling with significant effects are the usual triggers, but the formal criteria differ by country.

How the risk score is built

The score is a ranking device with four inputs, each weighted on the Settings tab:

Risk score = (special category data ? wspecial : 0) + (sent outside the country ? wtransfer : 0) + (assessment required and not done ? wassessment : 0) + (basis is consent ? wconsent : 0)

With the default weights of 3, 2, 3 and 1 the highest possible score is 9, and anything at or above 5 is drawn in red. Change the weights if they do not match how your organisation thinks; the tool has no opinion about the right numbers.

Be clear about what this is. It ranks the lines in your register against each other so you know where to start. It does not measure risk to the people whose data it is: it does not know how many records are involved, how good your security is, or what would happen if the data were lost.

Reviews and overdue

Every activity carries a next review date, which is also the date the filters and the monthly chart use.

Days to review = review date − today · Overdue = days to review < 0 and the status is not "retired"

Retired activities are excluded from the overdue count because the processing has stopped — but they stay in the register, and they still appear in the gap list, because the data may still exist. The warning window on the Settings tab controls how far ahead a review is flagged as approaching. Spread the review dates: a register where every line falls due in the same month gets rubber-stamped once a year rather than reviewed.

The gap list

An activity appears in the compliance gap table when any of these is true:

  • no lawful basis has been recorded;
  • an impact assessment is marked as required but not done;
  • the basis is legitimate interests and no balancing assessment has been recorded;
  • data is sent outside the country with no safeguard recorded;
  • no retention period has been decided.

These are gaps in the record. Closing them makes the register complete; it does not make the processing lawful, and an activity with no gaps can still be one you should not be doing at all.

What this tool cannot do

It does not check anything against any law, and it does not know which regime applies to you. It cannot tell whether a basis is available, whether consent was validly obtained, whether a retention period is defensible, whether a transfer safeguard is the right one, or whether an assessment was competent. It does not notify anybody, register anything, or respond to a request from a person about their own data.

What it does is stop the register living in somebody's head, in three spreadsheets, or nowhere.

Printing and sharing

Print Report produces a report from whatever the current filter shows: header, headline figures, the four charts, the gap list, the retention schedule, the full register and your closing notes. Print to PDF to keep a dated copy.

The scope line under the title states the filter in force. Clear the filters before issuing anything described as the complete register — a filtered print is a partial record, and it will not look like one.

Saving your work

Activities, settings and the report header are written to this browser's local storage as you type, and the toolbar shows the time of the last save. That storage belongs to one browser on one computer: another browser, a private window, a second machine or a tool that clears site data will not have it.

Treat Export .json as the real save — one file containing everything, which Import .json restores anywhere. Export CSV gives you the register for spreadsheet work and includes every filtered record, not only those drawn on screen. Reset asks twice, then erases everything this tool has stored. There is no undo.

Accuracy & disclaimer

This tool records what you enter and calculates from it. Every figure it produces depends on entries it cannot verify. It is a record-keeping and calculation aid, not legal advice, not a compliance assessment and not a submission to anybody.

What must be recorded, which lawful bases exist, what makes consent valid, which data is special, how long records must be kept and what a transfer abroad requires all differ by country and by sector, and they change. Establish what applies to you, and take advice where the answer matters.

Where this fits

Part of Privacy & Data Protection in Governance, Risk & Compliance.

Log personal data breaches against the clock: hours from awareness to containment and to report, a likelihood-and-severity risk rating, deadline tracking and a printable register. Runs entirely in your browser. Nothing is uploaded.

DownloadView

Work through a data protection impact assessment: screen whether one is needed, score each risk before and after controls, track who owns what, and print the assessment as a document. Runs entirely in your browser. Nothing is uploaded.

Download Runs in browserView

Record every gift and hospitality item given or received, test each one against your own approval and prohibition thresholds, and catch the cumulative annual total from a single counterparty that item-by-item checks always miss. Runs entirely in your browser — nothing is uploaded.

DownloadView

Keep a project and business risk register — strategic, financial, operational and compliance risks scored on a 5×5 grid, inherent and residual, with the four responses and a board-ready report. Not a workplace safety assessment. Nothing is uploaded.

Download Runs in browserView

Plan the year's internal audits — one row per planned audit, with risk-based frequency, auditor independence, planned against actual dates, deferral reasons and a coverage check that shows which high-risk processes are under-audited; for conducting the audits themselves use the internal audit checkl

Download Runs in browserView

Track internal audit findings from report to closure — owners, due dates, extensions, overdue ageing and closure statistics, with a report ready for an audit committee. Runs entirely in your browser. Nothing is uploaded.

DownloadView