- Tools
- Data protection (GDPR)
Record of processing activities for a law firm
A firm's usual processing activities, pre-filled with their legal basis, recipients, retention period and the source of each rule, to adapt and export.
What the rule says
Rules verified on 07/10/2026
Every law firm keeps a written record of its processing activities: purposes, categories of persons and data, recipients, transfers, retention periods and security measures (GDPR art. 30(1)). The exemption for organisations of fewer than 250 persons does not apply: a firm's processing is not occasional and includes special and criminal data (art. 30(5)).
Belgian law adds a list of the categories of persons with access to health and criminal data, with their duty of confidentiality (Law of 30 July 2018, arts. 9 and 10 §2). Lawyers process criminal data where the defence of their clients requires it (art. 10 §1 2°).
Encrypted vault
Your data stays on this device.
Keep your registers in an encrypted vault in this browser: a firm feature, free with a verified e-mail address. Without it, everything works for this session and every export stays available.
Record of processing activities
8 activities in the record
Each activity with its legal basis and retention period. Describe them below; the document follows.
Client files (advice, litigation, negotiation, mediation)
Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) · Legal obligation (art. 6(1)(c) GDPR)
Opposing parties and third parties in files
Legitimate interest (art. 6(1)(f) GDPR)
Client intake and conflict check
Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) · Legal obligation (art. 6(1)(c) GDPR) · Legitimate interest (art. 6(1)(f) GDPR) · retention to set
Anti-money laundering (AML/CFT)
Legal obligation (art. 6(1)(c) GDPR) · Task in the public interest (art. 6(1)(e) GDPR)
Billing, fee collection and accounting
Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) · Legal obligation (art. 6(1)(c) GDPR)
Staff and payroll (employees, collaborators, trainees)
Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) · Legal obligation (art. 6(1)(c) GDPR)
Website and contact form
Legitimate interest (art. 6(1)(f) GDPR) · Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) · Consent (art. 6(1)(a) GDPR) · retention to set
IT, security logs and e-mail
Legitimate interest (art. 6(1)(f) GDPR) · Legal obligation (art. 6(1)(c) GDPR)
The firm's name is missing. The record names the controller and its contact details (art. 30(1)(a)).
No contact address. Give the e-mail of the firm or of the privacy contact.
The access list is empty. Health and criminal data call for the list of persons with access and their duty of confidentiality (Law of 30 July 2018, arts. 9 and 10 §2).
Retention periods to set. No rule was found for some activities: the firm sets the period and writes it down (art. 5(1)(e)).
Record of processing activities
Art. 30(1) GDPR · controller · Updated on 08/10/2026
1. Controller
- Name
- [to complete]
- Address
- [to complete]
- Enterprise number
- [to complete]
- [to complete]
- Privacy contact
- [to complete]
The firm keeps this record because its processing is not occasional and includes data covered by arts. 9 and 10 GDPR: the exemption for organisations of fewer than 250 persons does not apply (art. 30(5) GDPR).
2. Persons with access to sensitive and criminal data
Categories of persons with access to health and criminal data, with their function and the basis of their duty of confidentiality (Law of 30 July 2018, arts. 9 and 10 §2). The list is kept available to the Belgian DPA.
[to complete]
3. Overview
| No. | Activity | Legal basis (art. 6) | Retention period |
|---|---|---|---|
| 1 | Client files (advice, litigation, negotiation, mediation) | Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) Legal obligation (art. 6(1)(c) GDPR) | 5 years after the end of the mandate (former Civil Code art. 2276bis §1); longer if the lawyer was expressly made depositary of documents or a claim is pending. |
| 2 | Opposing parties and third parties in files | Legitimate interest (art. 6(1)(f) GDPR) | 5 years after the end of the mandate, like the client file (former Civil Code art. 2276bis §1). |
| 3 | Client intake and conflict check | Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) Legal obligation (art. 6(1)(c) GDPR) Legitimate interest (art. 6(1)(f) GDPR) | As long as a conflict can arise: a period for the firm to set. |
| 4 | Anti-money laundering (AML/CFT) | Legal obligation (art. 6(1)(c) GDPR) Task in the public interest (art. 6(1)(e) GDPR) | 10 years from the end of the business relationship or the occasional transaction, then erasure (Law of 18 September 2017, arts. 60 and 62 §1). |
| 5 | Billing, fee collection and accounting | Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) Legal obligation (art. 6(1)(c) GDPR) | Books: 7 years from 1 January after closing (Code of Economic Law art. III.88); supporting documents: 7 years (art. III.86); tax and VAT: 7 years (Law of 18 December 2025, to verify); fee claims: 5 years after the end of the mandate (former Civil Code art. 2276bis §2). |
| 6 | Staff and payroll (employees, collaborators, trainees) | Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) Legal obligation (art. 6(1)(c) GDPR) | Social documents: 5 years (to verify); staff file: at least 1 year after the contract ends (Law of 3 July 1978, art. 15). |
| 7 | Website and contact form | Legitimate interest (art. 6(1)(f) GDPR) Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) Consent (art. 6(1)(a) GDPR) | Messages: until handled, then added to a file or erased; logs: a period for the firm to set. |
| 8 | IT, security logs and e-mail | Legitimate interest (art. 6(1)(f) GDPR) Legal obligation (art. 6(1)(c) GDPR) | Logs: a period for the firm to set; a leaver's mailbox: 1 to 3 months with an automatic reply, then closed. |
4. Processing activities
4.1 Client files (advice, litigation, negotiation, mediation)
- Purposes
- Advising and defending the client; procedural steps; correspondence in the file.
- Legal basis (art. 6)
- Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) Legal obligation (art. 6(1)(c) GDPR)
- Sensitive data (art. 9)
- Establishment, exercise or defence of legal claims (art. 9(2)(f) GDPR)
- Criminal data (Law of 30 July 2018, art. 10)
- By lawyers, insofar as the defence of their clients requires it (Law of 30 July 2018, art. 10 §1 2°)
- Data subjects
- Clients, their staff and their family members. Minors: Yes
- Categories of data
- Identification data, Financial data, Household composition, Profession and employment, Health data, Judicial data, Other (file content)
- Recipients and processors
- Courts and registries, bailiffs, notaries, experts, counsel for the other parties, mediators, translators, legal-expenses insurer (on the client's instruction), co-counsel. Processors: practice management software, e-mail, cloud, archiving, IT support.
- Transfers outside the EEA
- Normally none. Cloud outside the EEA: EU-US Data Privacy Framework or standard contractual clauses.
- Retention period
- 5 years after the end of the mandate (former Civil Code art. 2276bis §1); longer if the lawyer was expressly made depositary of documents or a claim is pending.
- Measures specific to the activity
- Access per matter; pseudonymise before any use of an AI tool (OVB and OBFG guidelines).
- Notes
- Criminal and health data used only for the client's defence, with a list of the persons who have access to them (Law of 30 July 2018, arts. 9 and 10 §2).
4.2 Opposing parties and third parties in files
- Purposes
- Defending the client's interests in the file: identifying the parties, corresponding, conducting the proceedings.
- Legal basis (art. 6)
- Legitimate interest (art. 6(1)(f) GDPR)
- Sensitive data (art. 9)
- Establishment, exercise or defence of legal claims (art. 9(2)(f) GDPR)
- Criminal data (Law of 30 July 2018, art. 10)
- By lawyers, insofar as the defence of their clients requires it (Law of 30 July 2018, art. 10 §1 2°)
- Data subjects
- Opposing parties, witnesses, experts, judges, court staff, fellow lawyers, police. Minors: Yes
- Categories of data
- Identification data, Financial data, Household composition, Health data, Judicial data, Other (file content)
- Recipients and processors
- As for client files.
- Transfers outside the EEA
- As for client files.
- Retention period
- 5 years after the end of the mandate, like the client file (former Civil Code art. 2276bis §1).
- Measures specific to the activity
- As for client files.
- Notes
- No individual notice where professional secrecy or the law requires it (GDPR art. 14(5)(c) and (d)); a notice published on the website informs these persons (art. 14(5)(b)). The OVB's reading, for the lawyer to assess.
4.3 Client intake and conflict check
- Purposes
- Identifying the client and the request; checking for conflicts of interest; preparing the engagement letter.
- Legal basis (art. 6)
- Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) Legal obligation (art. 6(1)(c) GDPR) Legitimate interest (art. 6(1)(f) GDPR)
- Sensitive data (art. 9)
- None
- Criminal data (Law of 30 July 2018, art. 10)
- None
- Data subjects
- Prospective clients, clients, opposing parties and related persons. Minors: No
- Categories of data
- Identification data, Other (file content)
- Recipients and processors
- No external recipient.
- Transfers outside the EEA
- None.
- Retention period
- As long as a conflict can arise: a period for the firm to set. (to set or verify)
- Measures specific to the activity
- Conflict register kept on the firm's device.
4.4 Anti-money laundering (AML/CFT)
- Purposes
- Identifying and verifying the client, its agents and beneficial owners; PEP and sanctions screening; risk assessment; analysis of atypical transactions; reporting through the bâtonnier.
- Legal basis (art. 6)
- Legal obligation (art. 6(1)(c) GDPR) Task in the public interest (art. 6(1)(e) GDPR)
- Sensitive data (art. 9)
- Substantial public interest (art. 9(2)(g) GDPR)
- Criminal data (Law of 30 July 2018, art. 10)
- None
- Data subjects
- Clients, agents, beneficial owners. Minors: No
- Categories of data
- Identification data, National register number, Financial data, Profession and employment, Political opinions, Judicial data
- Recipients and processors
- The bâtonnier, who passes reports to the CTIF; the supervisor; the UBO register; screening vendors (processors).
- Transfers outside the EEA
- Check where the screening vendor processes the data.
- Retention period
- 10 years from the end of the business relationship or the occasional transaction, then erasure (Law of 18 September 2017, arts. 60 and 62 §1).
- Measures specific to the activity
- No other purpose, commercial in particular (Law of 18 September 2017, art. 64 §2).
- Notes
- The rights of arts. 12, 13, 15, 16, 19, 21, 22 and 34 GDPR are fully restricted (Law of 18 September 2017, art. 65 §1). Warn new clients before the relationship starts (art. 64 §3). PEP data: basis to assess (reading M).
4.5 Billing, fee collection and accounting
- Purposes
- Invoices, provisions, VAT, bookkeeping, fee recovery.
- Legal basis (art. 6)
- Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) Legal obligation (art. 6(1)(c) GDPR)
- Sensitive data (art. 9)
- None
- Criminal data (Law of 30 July 2018, art. 10)
- None
- Data subjects
- Clients and third-party payers. Minors: No
- Categories of data
- Identification data, Financial data
- Recipients and processors
- Accountant, bank, tax and VAT authorities.
- Transfers outside the EEA
- None.
- Retention period
- Books: 7 years from 1 January after closing (Code of Economic Law art. III.88); supporting documents: 7 years (art. III.86); tax and VAT: 7 years (Law of 18 December 2025, to verify); fee claims: 5 years after the end of the mandate (former Civil Code art. 2276bis §2).
- Measures specific to the activity
- Keep billing apart from file content; no detail covered by secrecy on invoices.
4.6 Staff and payroll (employees, collaborators, trainees)
- Purposes
- Contracts, pay, social security, well-being at work, training, leaving the firm.
- Legal basis (art. 6)
- Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) Legal obligation (art. 6(1)(c) GDPR)
- Sensitive data (art. 9)
- Employment and social security law (art. 9(2)(b) GDPR)
- Criminal data (Law of 30 July 2018, art. 10)
- None
- Data subjects
- Employees, independent collaborators, trainees, their family members (benefits). Minors: No
- Categories of data
- Identification data, National register number, Financial data, Household composition, Education, Profession and employment, Health data
- Recipients and processors
- Social secretariat (processor for payroll), ONSS/RSZ, tax authority, group insurer, external prevention service.
- Transfers outside the EEA
- None.
- Retention period
- Social documents: 5 years (to verify); staff file: at least 1 year after the contract ends (Law of 3 July 1978, art. 15).
- Measures specific to the activity
- Access to staff files limited.
4.7 Website and contact form
- Purposes
- Informing the public; answering contact requests; security logs; cookies (non-essential ones: consent, Law of 30 July 2018, art. 10/2).
- Legal basis (art. 6)
- Legitimate interest (art. 6(1)(f) GDPR) Performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR) Consent (art. 6(1)(a) GDPR)
- Sensitive data (art. 9)
- None
- Criminal data (Law of 30 July 2018, art. 10)
- None
- Data subjects
- Website visitors, people who get in touch. Minors: No
- Categories of data
- Identification data, Connection data and logs, Other (file content)
- Recipients and processors
- Host, form tool, audience measurement tool.
- Transfers outside the EEA
- Tools based in the United States: DPF or standard contractual clauses.
- Retention period
- Messages: until handled, then added to a file or erased; logs: a period for the firm to set. (to set or verify)
- Measures specific to the activity
- HTTPS; no non-essential cookie before consent; a warning not to send confidential information through the form.
4.8 IT, security logs and e-mail
- Purposes
- Securing the systems (art. 32 GDPR); continuity; mailboxes of staff who leave.
- Legal basis (art. 6)
- Legitimate interest (art. 6(1)(f) GDPR) Legal obligation (art. 6(1)(c) GDPR)
- Sensitive data (art. 9)
- None
- Criminal data (Law of 30 July 2018, art. 10)
- None
- Data subjects
- Staff, correspondents. Minors: No
- Categories of data
- Identification data, Connection data and logs
- Recipients and processors
- IT provider, managed service provider, cloud.
- Transfers outside the EEA
- Check where the provider processes the data.
- Retention period
- Logs: a period for the firm to set; a leaver's mailbox: 1 to 3 months with an automatic reply, then closed.
- Measures specific to the activity
- Logging of access to client files.
5. Security measures common to every activity
- Access limited on a need-to-know basis
- List of persons with access and their duty of confidentiality (Law of 30 July 2018, arts. 9 and 10 §2)
- Encryption at rest and in transit; two-factor authentication on e-mail and cloud
- Licensed, up-to-date software; antivirus and firewall
- Backups (frequency, location, access); physical security of the premises
- Contracts with processors (art. 28 GDPR)
- No private e-mail or cloud for work; Bcc for group mailings
- Yearly review, staff training, incident procedure
Kept in writing, including in electronic form, and made available to the Belgian Data Protection Authority on request (art. 30(3) and (4) GDPR).
Export
Exports carry the Normalex header. With a verified address, they carry your firm's letterhead.
AI tools from your AI register
Each AI tool kept in the AI tools register becomes an activity, with its provider and hosting.
With the vault open, the AI tools kept in the AI tools register can be added here, one activity per tool.
Describe each activity
The texts appear in the document's language. Change what differs in your firm; an unchanged text follows the language chosen.
Sources
Rules verified on 07/10/2026
- Regulation (EU) 2016/679 (GDPR)
- Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data
- Law of 18 September 2017 (anti-money laundering), arts. 60 to 65
- Former Civil Code, art. 2276bis (lawyers keeping files)
- CNC: Code of Economic Law, arts. III.86 and III.88 (accounting records)
- Law of 21 March 2007 on the installation and use of surveillance cameras
- Belgian DPA: model record of processing activities
- OVB, GDPR-wijzer: record of processing activities
- AVOCATS.BE: model record for lawyers (CNIL model, 11/06/2021)
A drafting aid based on the sources cited. To be reviewed and adapted by the lawyer; it is neither advice nor a guarantee of compliance.
How it works
How the tool works
- The firm. Name, address, enterprise number, the data protection contact (a privacy contact or a DPO) and the list of persons with access to health and criminal data, with the basis of their confidentiality.
- The activities. Eight activities are ticked by default: client files, opposing and third parties, intake and conflict checks, anti-money laundering, billing and accounting, staff and payroll, website, IT and e-mail. Nine more are one click away: the firm's own disputes, recruitment, newsletter, CCTV, AI tools, legal aid, other capacities (insolvency trustee, mediator…), suppliers, and the log of requests and breaches.
- The details. Each activity carries its purposes, legal basis (art. 6), the condition of arts. 9 and 10 where it processes sensitive or criminal data, data subjects, categories of data, recipients, transfers, retention period with its source, and security measures. Everything can be edited; a text you leave untouched follows the document's language.
- The document. The record appears as you answer and exports to PDF, Word and a CSV table, in the language you choose.
With a verified address, the record can be kept in an encrypted vault in this browser, and each tool of the AI tools register becomes an activity.
What the rule says
- GDPR art. 30(1): the record names the controller, the purposes, the categories of data subjects and data, the recipients, the transfers, the time limits for erasure and a general description of the security measures.
- GDPR art. 30(5): the exemption for organisations of fewer than 250 persons does not cover processing that is not occasional or that includes art. 9 or 10 data. A law firm therefore always keeps a record.
- Law of 30 July 2018, arts. 9 and 10 §2: for health and criminal data, a list of the categories of persons with access, with their duty of confidentiality. Art. 10 §1 2° lets lawyers process criminal data insofar as the defence of their clients requires it.
- Retention: client file 5 years after the end of the mandate (former Civil Code art. 2276bis); anti-money laundering data 10 years, then erasure (Law of 18 September 2017, arts. 60 and 62); accounting 7 years (Code of Economic Law arts. III.86 and III.88); CCTV images at most 1 month (Camera Law).
Points to watch
- Each preset states how reliable its source is: read in the text, confirmed by two sources, or a firm policy to set. Retention periods without a legal rule (recruitment, logs, contact form) are flagged.
- Health and criminal data in files rest on art. 9(2)(f) GDPR (legal claims) and on art. 10 §1 2° of the Law of 30 July 2018; a new activity with special categories needs a condition of art. 9(2).
- Data subjects' rights are fully restricted for anti-money laundering processing (Law of 18 September 2017, art. 65): the tool says so in that activity.
- Before the first use of a generative AI tool on files, an impact assessment is in practice needed; update the privacy notice as well.
What the tool does not do
- It does not send the record to the Belgian DPA: the authority may ask for it, and you provide it.
- It does not replace the firm's yearly review of its record.
- It sends nothing: the record stays in this tab, or in this browser's encrypted vault if you choose.
Verification
The sources were checked on 7 October 2026. The tool assists the lawyer, who remains responsible for the content of the record.
Updated on 7 October 2026
Frequently asked questions
Must a sole practitioner keep a record of processing?
Yes. The exemption of art. 30(5) GDPR for organisations of fewer than 250 persons does not apply where processing is not occasional or includes sensitive or criminal data. A lawyer's files meet both conditions. The OVB reminds every lawyer that they keep a record.
Does the firm need a data protection officer?
In principle not, for a sole practitioner or a typical small or medium firm: recital 91 GDPR states that the data of an individual lawyer's clients are not processed on a large scale. A large firm processing sensitive data in bulk (criminal law, personal injury, debt collection for hospitals) checks and documents that test. Use the DPO title only if the person meets every condition of arts. 37 to 39; otherwise speak of a privacy contact.
How long is a client file kept?
Five years after the end of the mandate: the former Civil Code (art. 2276bis §1) discharges the lawyer from liability and from keeping the documents after that period, unless the lawyer was expressly made depositary of specific documents. Data gathered for anti-money laundering purposes are kept for 10 years from the end of the business relationship, then erased (Law of 18 September 2017, arts. 60 and 62).
What is the list of persons with access?
For health and criminal data, the Law of 30 July 2018 (arts. 9 and 10 §2) asks for a list of the categories of persons who have access, with their function and the basis of their duty of confidentiality: for example the lawyers (professional secrecy) and the secretariat (employment contract and confidentiality clause). The list is kept available to the Belgian DPA.
How are the firm's AI tools added?
Tick the "AI tools" activity or, with the vault open, add in one click the tools recorded in the AI tools register: each becomes an activity with its provider and hosting. Each new tool also calls for an impact assessment before first use and an update of the privacy notice.
Is my data sent anywhere?
No. The record is built in your browser. Without the vault it stays in the tab's memory; with the vault it is encrypted with your passphrase in this browser. Only the document language appears in the page address.