Record keeping: what you should keep about your website and data
The records that make a business defensible: processing activities, consents, agreements, incidents, decisions and the website's own history.
The short answer
The accountability principle requires you to be able to demonstrate compliance, not merely to comply, which makes records the evidence that protects a business when something is questioned. For a small business six records cover almost everything. A record of processing activities: what personal data you process, why, on what basis, who receives it, where it goes and how long you keep it. Consent records: who agreed to what, in what wording, when. Processor agreements with your suppliers, with versions and dates. An incident register, including breaches you decided not to notify and why. A decisions log for the significant choices, retention periods, legal bases, risk assessments, with reasons. And the website’s own history: the repository, deployments, test results, asset licences and previous versions of the legal pages. Keeping them current matters more than making them comprehensive; a register written once and never revisited is evidence of drift rather than of control. Retention applies to records too, with statutory periods for tax and contracts and deletion for anything without a purpose.
The six records
| Record | Contents | Kept where | Review |
|---|---|---|---|
| Processing activities | Purposes, categories of data and people, bases, recipients, transfers, retention, security summary | One document, versioned | Annually and on change |
| Consents | Person, purpose, wording shown, timestamp, method, confirmation | In the system that collected it, exportable | Continuous |
| Processor agreements | Signed agreements, versions, sub-processor lists, locations | With the supplier list | Annually and at renewal |
| Incidents | Facts, effects, assessment, decision to notify or not with reasons, actions | Incident register | After each; reviewed annually |
| Decisions | Retention periods, legal bases, risk assessments, transfer assessments, with reasoning and dates | Decisions log | When decisions change |
| Website history | Repository, deployment record, test results, asset licences, legal page versions | The repository | Continuous |
Making it manageable
- Start with the record of processing; everything else derives from it.
- Keep it in one document in a place the business controls, not in a consultant’s file.
- Link, do not duplicate: point to the supplier agreements and the test results rather than copying them.
- Add a date and an owner to every record.
- Set annual review in the calendar, plus triggers on new tools, services or suppliers.
- Keep the website’s history in the repository, which does it automatically once content and configuration live there.
- Apply retention to records too, with statutory periods for tax and contracts.
- Delete what has no purpose, including old exports, backups of departed systems and duplicate customer lists.
The website’s own history
Keeping content, configuration and code in a repository gives you most of this record for nothing: every change, who made it, when and why, with the ability to show the site as it was on any past date. That is useful well beyond compliance, in disputes about what was published, in demonstrating when a legal page changed, and in a partner change. It is one more reason to keep the site in version control rather than on a server.
What this means for you
Keep six records current: processing activities, consents, processor agreements, incidents, decisions, and the website’s own history in a repository. Date them, own them, review annually and on change, link rather than duplicate, and apply retention to the records themselves. Accountability is the ability to demonstrate, and these six are what demonstrating looks like for a small business. This is general information rather than legal advice.
Frequently asked questions
Do small businesses have to keep a record of processing activities?
The exemption for organisations under 250 employees is narrow: it does not apply where processing is likely to result in a risk to people, is not occasional, or includes special categories or criminal data. A business with a customer database, a newsletter and a website is processing regularly, so in practice the record is expected. It is also the document from which your privacy statement, your supplier list and your retention schedule are all derived, so it is worth having regardless.
What should we keep about the website itself?
The repository with its full history, the record of what was deployed when, the decisions about structure and technology with their reasons, the accessibility and security test results, the licences for assets, the supplier agreements, and previous versions of the legal pages. Together those answer the questions that come up in a partner change, an audit, a client questionnaire or a dispute.
How long should records be kept?
Tax and accounting records for the statutory period, which in the Netherlands is seven years for most business administration and longer for property-related records. Contracts for the limitation period relevant to claims. Consent records for as long as you rely on the consent plus a reasonable margin. Incident records for a period you define. And anything without a purpose or a legal basis should be deleted, because keeping it creates risk without benefit.
Sources
- EUR-Lex: Regulation (EU) 2016/679, Articles 5(2) and 30 (accessed 2026-09-14)
- Belastingdienst: Hoe lang moet u uw administratie bewaren (accessed 2026-09-12)