The classic trap
Recital 82 sheds light on Article 30: the record of processing activities is not a decorative document, it is the first item requested by the CNPD during an inspection. In practice, sanctioned organisations are not those without a register, but those with an Excel file built 18 months ago, never updated, where half of the real processing activities (new SaaS tools, new HR flows, new marketing campaigns) are missing. The CNPD and CNIL consider this gap between the declared register and operational reality as direct evidence of a failure of Article 5(2) accountability.
Why the Excel register is dead
The spirit of recital 82 is that the register must actually serve to monitor processing operations. A register that does not reflect reality serves neither the authority nor the controller. The most frequent pitfalls:
- The register lists 25 processing activities while the company uses 80 SaaS applications all handling personal data.
- Retention periods are generic ('legal duration') with no effective purge policy behind them.
- Listed processors no longer match real invoices (old vendors gone, new ones onboarded without a DPA).
- Transfers outside the EU are not tracked even though M365, Salesforce, HubSpot and Zoom send data daily to the United States.
- No timestamp or versioning: impossible to prove to the CNPD that the register was up to date at the time of an incident.
How Luxgap automates this risk
Our Luxgap Records Sentinel replaces the declarative Excel register with a living register continuously fed by your real systems. The tool connects to your Active Directory, M365, Odoo, Sage BOB 50, Workday LU, Salesforce, AWS and Microsoft Defender for Cloud Apps, then automatically rebuilds the processing map from observed flows, consumed applications and detected vendor contracts. The DPO no longer fills in forms: they validate or reject the fact sheets generated by the AI agent.
- Automatically detects each new processing activity as soon as a SaaS application appears in authentication logs or an HR flow is created in Workday.
- Classifies data categories using the EDPB grid and proposes the most likely Article 6 legal basis, for DPO validation.
- Monitors in real time the transfers outside the EU detected on network traffic and triggers an instant Teams alert whenever a new flow to a third country appears.
- Generates the Article 30 register in CNPD-compliant format, exportable as a timestamped, cryptographically sealed PDF, admissible during an inspection.
- Compares each month the declared register against the observed register and produces a gap report exposing forgotten processing activities.
- Archives every successive version to demonstrate, at the date of an incident, the exact state of the register.
Available as part of a Luxgap DPO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real systems, with a free 48h blind audit revealing the gap between your current register and the reality of your processing activities.