Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
FAQs
- Are records of processing activities mandatory for all Australian businesses?
- What is the difference between a privacy policy and a record of processing activities?
- Should small businesses keep these records even if they are exempt from parts of the Privacy Act?
- Do employee records need to be included?
- What is the biggest practical risk of not having these records?
- Key Takeaways
Many Australian businesses collect personal information every day but cannot clearly explain what they collect, why they collect it, who can access it, or where it goes next. That becomes a problem when you are updating your privacy policy, answering a customer complaint, reviewing a supplier agreement, or dealing with a data breach. Common mistakes include assuming your privacy policy is enough, keeping data maps only in one person’s head, and forgetting about routine sharing with software providers, payroll platforms, marketing tools, or overseas service providers.
A record of processing activities helps fix that. It is a practical internal document that lists how your business handles personal information across sales, HR, marketing, operations, and technology. For Australian businesses, it can be one of the most useful privacy governance tools you maintain. This guide explains what records of processing activities are, what to include, when you are likely to need them, and the common gaps that cause trouble before you sign contracts, launch new systems, or respond to privacy questions.
Overview
Records of processing activities are internal privacy records that show what personal information your business handles, why it handles that information, where it comes from, who it is shared with, and how it is protected. Australian law does not use the same terminology in every context, but keeping these records is a sensible and often necessary step for businesses that want to meet privacy obligations, manage risk, and answer practical questions quickly.
- Identify each business activity that involves personal information, such as customer onboarding, staff recruitment, direct marketing, website analytics, support tickets, and payroll.
- Record the types of personal information collected, the purpose for collection and use, and whether any sensitive information is involved.
- Note where the information comes from, who receives it, whether it goes overseas, and which software or service providers are involved.
- Document retention periods, deletion practices, security controls, and who in the business owns each processing activity.
- Check that the record matches your privacy policy, collection notices, internal procedures, and supplier agreements.
What Records of Processing Activities Means For Australian Businesses
For Australian businesses, a record of processing activities is usually best understood as a working privacy register, not a marketing document or a template filed away and forgotten.
It gives you a central source of truth about how personal information moves through your business. That matters whether you are covered by the Privacy Act 1988 (Cth) because of your turnover, because you operate in a regulated area, or because your contracts and customers expect you to meet higher privacy standards anyway.
In practice, these records help you answer basic but important questions. What information do we collect from customers? Do we store resumes in a shared inbox? Does our CRM send data overseas? Which app has access to mailing list data? How long do we keep support recordings? If a customer asks for access or correction, who handles that request?
Why these records matter even if you are not legally required to use that exact label
Australian privacy compliance often turns on what your business actually does with personal information. A clear internal record helps you line up your legal documents and day to day operations.
That can support several privacy tasks, including:
- drafting or updating a privacy policy
- checking whether your privacy collection notices are accurate
- assessing whether your contracts with service providers deal with privacy properly
- responding to data breach incidents
- answering access or correction requests
- reviewing overseas disclosure arrangements
- showing customers, investors, or enterprise clients that your privacy practices are organised
This is where founders often get caught. They have good intentions and a privacy policy on the website, but no one has documented the actual data flows. Once the business grows, different teams start collecting information in different ways, and the business loses sight of what is happening.
What should go into a record of processing activities
A useful record should be specific enough that someone new to the business could understand the activity without guessing. It should cover each major process separately rather than collapsing everything into one vague line such as “customer data”.
For each processing activity, include:
- the name of the activity, such as customer account creation, employee onboarding, email marketing, or supplier due diligence
- the business team or owner responsible for the activity
- the categories of individuals affected, such as customers, website users, job applicants, employees, contractors, or suppliers
- the categories of personal information involved, such as names, email addresses, phone numbers, payment details, addresses, ID documents, usage data, or health information where relevant
- the purpose for collection, use, and disclosure
- the legal or business basis for handling the information, in plain language, such as fulfilling orders, managing employment, providing support, meeting legal obligations, or sending marketing with consent where needed
- the source of the information, including whether it comes directly from the individual, from a referral partner, from public sources, or from another system
- the internal users or teams with access
- the external recipients, such as cloud providers, payment processors, payroll platforms, marketing platforms, IT support providers, or legal advisers
- whether information is disclosed or stored overseas, and if so, which countries or regions are involved where known
- how long the information is kept and when it is deleted, de-identified, or archived
- the main security controls, such as access permissions, encryption, multi-factor authentication, logging, and backup arrangements
- the key documents linked to the activity, such as privacy notices, consent wording, supplier agreements, HR policies, or incident response procedures
Sensitive information needs extra attention
If your business handles sensitive information, your records should say so clearly. In Australia, sensitive information can include health information, biometric information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, and certain other categories.
The main risk is treating sensitive information as though it were ordinary contact data. If you collect it, your record should explain:
- why it is needed
- how consent is managed where relevant
- who can access it
- what extra controls apply
- whether your privacy documents accurately describe that handling
These records are not the same as a privacy policy
A privacy policy tells the outside world, at a fairly high level, how your business handles personal information. A record of processing activities is an internal operational document. It should be more detailed, more specific, and updated more often.
If the two do not match, that is a warning sign. For example, your website privacy policy might say you use personal information for order fulfilment and marketing, but your internal systems may also use profile data for behavioural analytics, fraud screening, AI tools, or offshore support workflows. If those practices are not documented internally, they are easy to miss in legal review.
When This Issue Comes Up
Most businesses start caring about records of processing activities when something changes, goes wrong, or gets checked by someone outside the business.
You usually do not create these records because you suddenly love documentation. You create them because a customer, client, regulator, buyer, enterprise procurement team, or internal stakeholder needs clear answers, and no one wants to piece them together from inboxes and Slack messages.
Common trigger points for startups and SMEs
These records often become urgent in moments like these:
- before you sign a major customer contract that asks detailed privacy and security questions
- before you onboard a new software platform that will access customer or employee information
- before you launch online and need your privacy policy and collection notices to match your actual data handling
- when you start collecting new information, such as identity verification documents or health details
- when your business begins selling to larger corporate or government customers
- when you expand overseas or use overseas providers for hosting, support, development, or analytics
- when you suffer a data breach or near miss and need to understand what information was affected
- when you are preparing for due diligence for investment, sale, or merger activity
- when staff ask basic questions about retention, deletion, access rights, or where certain data sits
Examples from ordinary business operations
A retail brand selling online may use an ecommerce platform, payment gateway, email marketing tool, customer service platform, website analytics, and a loyalty app. If no one has documented those flows, it is hard to explain overseas disclosure, data retention, or which supplier agreement needs review first.
A health adjacent startup may collect booking details, symptom information, support messages, and practitioner notes. The privacy risk is higher because some of that information may be sensitive, and the business needs a much clearer internal record of purpose, access controls, and retention.
An employer with 20 staff may think privacy records are only about customers, then realise recruitment folders, right to work checks, payroll files, performance records, and contractor onboarding all involve personal information too.
Why timing matters
The best time to prepare records of processing activities is before a problem appears. Once a complaint, breach, or procurement deadline lands, the exercise becomes slower and more expensive.
That is especially true if your business has grown quickly. Startups often add tools and workflows fast, with little formal approval process. Before you spend money on setup for a new system, or before you sign a contract with a software provider, a current processing record makes it easier to check privacy terms, access permissions, and offshore data issues.
Practical Steps And Common Mistakes
The most effective way to build records of processing activities is to map what actually happens in the business, not what you assume happens.
A short workshop with the right people usually reveals far more than a legal or compliance review done in isolation. Sales, HR, marketing, operations, and IT often each hold a different part of the picture.
How to build a useful record
Start by listing your main business functions and systems. Then break those functions into specific personal information activities rather than broad departments.
A practical process usually looks like this:
- List the systems, apps, folders, forms, and inboxes where personal information is collected or stored.
- Identify the business activity attached to each one, such as onboarding customers, running payroll, sending campaigns, or handling support.
- Record what personal information is involved and whether any of it is sensitive information.
- Write down why the information is collected, how it is used, who can access it, and who it is shared with.
- Check whether any supplier stores or accesses the information outside Australia.
- Add retention and deletion rules, even if they are only initial working rules that still need refinement.
- Compare the record against your privacy policy, staff practices, and supplier agreements.
- Assign an owner to keep each part current when systems or processes change.
Questions worth asking internally
Good records come from specific questions. Vague requests for a “data map” usually produce vague answers.
Ask teams things like:
- What personal information do you collect first, and what do you collect later?
- Do you copy data from one system to another manually?
- Which providers can view, store, process, or back up that information?
- Do contractors or overseas team members have access?
- How long do you keep information if a lead never converts, a customer becomes inactive, or a candidate is not hired?
- What happens when someone asks for access, correction, or deletion?
- What information would be exposed if this inbox, drive, or platform were compromised?
Common mistakes Australian businesses make
The first common mistake is treating the exercise as a one off. Records of processing activities only work if they are maintained when your business changes.
The second common mistake is documenting systems but not business purposes. A list of software subscriptions is not enough. You need to know why each process exists and how the personal information is used.
Other frequent problems include:
- forgetting employee, contractor, and job applicant information
- ignoring spreadsheets, shared drives, and ad hoc exports
- missing personal information collected through website forms, chat tools, support platforms, and cookies or analytics technologies
- failing to note routine disclosures to accountants, lawyers, IT providers, couriers, or payment processors
- not identifying overseas access because the service provider is branded locally but hosts or supports offshore
- keeping no retention rules, so information is stored indefinitely
- using copied templates that do not reflect the real business model
- letting one founder or operations manager become the only person who understands the data flows
How these records connect with contracts and privacy documents
Your internal records should line up with your external legal documents. If they do not, update one or both.
For example, if your record shows customer data is shared with a fulfilment partner, CRM, and offshore support provider, your contracts and privacy disclosures should accurately reflect those arrangements. If a supplier handles personal information for you, your contract should usually deal with matters such as confidentiality, permitted use, security expectations, incident notification, subcontracting, and data return or deletion at the end of the relationship.
This is also relevant when negotiating enterprise customer contracts. Larger customers often ask for detail about data handling, retention, overseas disclosure, and incident response. A current processing record makes those negotiations much easier because you are not scrambling to verify facts after the contract arrives.
How often should you review the records?
Review them whenever there is a material change, and also on a regular cycle. For many SMEs, every 6 to 12 months is a sensible baseline.
You should also update the record when:
- you adopt a new platform
- you launch a new product or service
- you begin collecting new categories of personal information
- you enter a new market
- you outsource a function
- you change your security processes or retention rules
- you discover a mismatch between policy and practice
If you are already cleaning up your legal settings, this review can sit alongside related tasks such as checking website terms, customer contracts, employment contracts, contractor agreements, and trade mark strategy. Privacy records rarely exist in isolation. They connect to how the business is structured and documented more broadly.
FAQs
Are records of processing activities mandatory for all Australian businesses?
Not every Australian business is expressly required to keep a document with that exact title. But many businesses need an internal record of personal information handling to meet privacy obligations in practice, answer customer or supplier questions, and manage risk properly.
What is the difference between a privacy policy and a record of processing activities?
A privacy policy is an external document that explains, at a general level, how your business handles personal information. A record of processing activities is an internal operational document that maps specific data handling processes, systems, recipients, retention periods, and security controls.
Should small businesses keep these records even if they are exempt from parts of the Privacy Act?
Often yes. Small businesses still benefit from knowing what information they collect and share, especially if they use multiple software providers, handle sensitive information, sell to enterprise customers, or want to be ready for growth, due diligence, or a security incident.
Do employee records need to be included?
As a practical matter, yes. Even where Australian privacy rules treat employee records differently in some contexts, your business should still document HR and workforce data handling internally so you can manage access, retention, security, and supplier arrangements sensibly.
What is the biggest practical risk of not having these records?
The biggest risk is loss of visibility. That can lead to inaccurate privacy disclosures, poor supplier contracting, slower breach response, avoidable customer complaints, and costly confusion before you sign contracts or implement new systems.
Key Takeaways
- Records of processing activities are internal privacy records that show how personal information moves through your business.
- They should cover the activity, purpose, data types, individuals affected, systems used, recipients, overseas disclosure, retention, and security controls.
- These records help Australian businesses keep privacy policies, collection notices, contracts, and actual practices aligned.
- They become especially important before you sign major customer or supplier contracts, launch new tools, expand operations, or respond to a privacy incident.
- Common mistakes include missing HR data, ignoring informal spreadsheets and exports, overlooking offshore providers, and treating the record as a one off exercise.
- A practical review cycle and clear ownership make the records far more useful than a template completed once and forgotten.
If your business is dealing with records of processing activities and wants help with privacy policies, supplier contracts, data handling reviews, and overseas disclosure issues, you can reach us on 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.






