Immagine di copertina articolo: GDPR for APS: the registro dei trattamenti, a 2026 Italian model

Photo:ImagePerson, Wikimedia Commons · CC BY-SA 4.0

← Back to the blog

Running an APS

GDPR for APS: the registro dei trattamenti, a 2026 Italian model

Redazione OnStage 22 min read Part 1 of 5 · GDPR and Privacy

The registro dei trattamenti: why every APS needs one

In February 2026, the Garante per la protezione dei dati personali (Italy's national Data Protection Authority) reiterated the strategic importance of the registro dei trattamenti — the record of processing activities — for small non-profit organisations. An Associazione di Promozione Sociale (APS, an Italian social-promotion association) that handles data belonging to members, donors, volunteers and event participants is required to document how that data is used.

This is not just a bureaucratic formality. The registro dei trattamenti is the foundation of the accountability and transparency that the GDPR (Regulation (EU) 2016/679) requires from every organisation that handles personal data.

A true story: in 2025, a cultural APS in Liguria received a warning from the Garante for failing to keep its registro dei trattamenti up to date. When it was inspected, it did not even know what data it held on its own members, where that data was stored, or for how long. The penalty? A 2,500-euro administrative fine, plus the legal costs of the subsequent clean-up.

Your APS doesn't have to end up like that. This guide explains everything you need: from GDPR Article 30, to the Garante's simplified templates, to a practical template you can start using today.

GDPR Article 30: obligations of the controller and the processor

Article 30 of Regulation (EU) 2016/679 establishes that every organisation that processes personal data must keep a register. It is not optional. It is mandatory.

Who is required to keep one?

Under GDPR Art. 30(5), only organisations that meet all of the following are exempt from the obligation:

1. Have fewer than 250 employees AND
2. The data processing is not occasional AND
3. It is unlikely to pose a risk to the rights of data subjects

In practical terms: almost every APS must keep the register. If your association has even one person managing a newsletter, an online sign-up form, event photos, or member data, you need to document it.

What must the register contain?

Article 30(1) specifies that the register must include, for every processing activity:

1. Name and contact details of the data controller (your APS)
2. Name and contact details of the data processor, if one has been appointed (e.g. whoever maintains the server or manages the database)
3. Categories of data subjects (members, donors, volunteers, event participants)
4. Categories of personal data (names, email addresses, phone numbers, addresses, photos, banking details)
5. Purpose of the processing (managing sign-ups, sending communications, documenting activities)
6. Categories of recipients (other internal departments, public databases, external partners)
7. Retention periods (how many years you keep the data before deleting it)
8. Technical and organisational security measures (passwords, backups, restricted access)
9. International transfers, if applicable

The Italian Garante Privacy's position on APS and small businesses

In 2024-2025, the Garante per la protezione dei dati personali updated its specific guidelines on the registro dei trattamenti. The good news for APS: the Authority recognises that small non-profit organisations struggle to maintain complex documentation.

For this reason, the Garante has made simplified templates (official model forms) available, reducing bureaucratic complexity without compromising compliance.

The Garante's official templates

The Garante has published two "simplified register" templates:

1. Modello per il titolare del trattamento (template for the data controller — your APS)
2. Modello per il responsabile del trattamento (template for the data processor, if you entrust your data to an outside party)

These templates can be downloaded as PDFs from the official website. They are laid out in simple tables that guide you step by step through filling them in, avoiding overly technical bureaucratic language.

A practical template: how to fill in the register for your APS

Here is a simplified version you can adapt to your own organisation:

Section 1: Organisational Information

| Field | APS Example |
|-------|-----------|
| Organisation Name | APS Onstage Botrugno |
| Registered Office Address | Piazza San Pietro 10, Botrugno (LE) |
| Data Officer Email | privacy@onstage.it |
| Appointed officer? | Yes (Mario Rossi) / No |

Section 2: Processing Activities

Activity No. 1: Membership sign-up and database management

| Field | Detail |
|-------|----------|
| Purpose | Managing the membership register, communications, event invitations |
| Legal basis | GDPR Art. 6(1)(a) (consent) and GDPR Art. 6(1)(b) (performance of a contract) |
| Categories of data subjects | Members, supporters, workshop participants |
| Categories of data | First and last name, email, phone number, date of birth, address, banking details (for membership fees) |
| Recipients | APS administrative staff, and possibly an external management platform |
| Retention period | 5 years after the last event/active membership |
| Security measures | Strong passwords, admin-only access, monthly encrypted backups |

Activity No. 2: Newsletter communications

| Field | Detail |
|-------|----------|
| Purpose | Informing subscribers about new events, organisational news, cultural opportunities |
| Legal basis | GDPR Art. 6(1)(a) (explicit consent, double opt-in) |
| Categories of data subjects | Email contacts registered on the platform |
| Categories of data | Email address, newsletter sign-up date, clicked links (tracking) |
| Recipients | Email platform (e.g. MailUp, 4Dem); not shared with third parties |
| Retention period | Until consent is withdrawn or after 2 years of inactivity |
| Security measures | GDPR-compliant platform with TLS encryption, tracked access logs |

Activity No. 3: Photographic documentation of events

| Field | Detail |
|-------|----------|
| Purpose | Documenting activities, social media communication, community relations |
| Legal basis | GDPR Art. 6(1)(a) (prior consent from participants) |
| Categories of data subjects | Workshop, jam session and festival participants |
| Categories of data | Images, biometric data (faces), data belonging to minors |
| Recipients | APS's official social media, media partners, internal archives |
| Retention period | 5 years post-event for archival purposes, after which data on minors is purged |
| Security measures | Restricted-access folders, cloud backups with MFA authentication, archived consent forms |

Accountability obligations: what this means in practice

Accountability is not an empty word under the GDPR. It means demonstrable responsibility: if the Garante asks you to account for how you handle data, you must have the documentation ready.

The registro dei trattamenti is the visible proof of your commitment. Here's what you need to do:

1. Keep the register up to date

Every time something changes (you add a new purpose, switch platforms, or appoint a new data officer), update the register within 30 days. Date every change.

2. Make the register accessible

The register must be kept in written or electronic format. Highly recommended: keep it in a shared spreadsheet (Google Drive, Excel with backups) accessible at least to your DPO (Data Protection Officer) or your privacy contact person.

3. Appoint a privacy officer

If you have more than 5 employees or process sensitive data, appoint an internal officer (they don't need a law degree). This person:
- Monitors GDPR compliance
- Updates the register
- Handles data subject requests
- Notifies the Garante of data breaches

4. Document your decisions

If you decide not to keep certain data, document it. If you decide to delete it earlier than planned for "good reasons", note the reasoning in the register.

The role of the Data Processor (when one is needed)

If you use an external platform to manage data (e.g. newsletter software, cloud management systems), that platform becomes your Data Processor. You must:

1. Verify that it has a GDPR-compliant contract (GDPR Art. 28)
2. Record in your register that you use this provider
3. Include the provider in your accountability chain

Example: if you use MailUp.it or 4Dem.it for your newsletter, both are Italian providers that guarantee GDPR compliance. In your register, note:

> Data Processor: MailUp Srl, Milan. Data Processing Agreement attached, rev. 2026.

Checks and inspections: what would the Garante look for?

When the Garante carries out inspections (following a complaint or as part of a random audit), it looks for:

1. Disorganised or missing registers → Violation of Art. 30, with fines of up to EUR 20 million or 4% of turnover
2. Data held without documentation → No trace of consent, vague legal basis
3. Officers appointed but not tracked → Who has access to the data? How is it monitored?
4. No retention policy → Data kept forever "just in case"

A medium-sized APS (50-100 members) with a well-structured, up-to-date and properly archived register easily passes an inspection. One that "improvises" during the audit, on the other hand, is taking a real risk.

Storing and updating the register in 2026

Where should you store the register?

Option 1: Digital (recommended)
- Google Drive (with offline backup)
- OneDrive/SharePoint
- Private server with encrypted backup
- GDPR-specific management software (e.g. MyDPO, OneTrust — these cost money but include pre-filled templates)

Option 2: Paper + digital backup
- Physical folder with restricted access
- Scanned digital copy
- Annual external backup

How often to update it

- Monthly: Check whether there are new processing activities to document
- Quarterly: Reviewed by the person responsible for privacy
- Annually: A full audit (in April, alongside the APS's financial statements)

What happens if you don't have a register?

If the Garante finds you without a register:

- Violation of GDPR Art. 30(1) = A fine of between 1,000 and 50,000 euros for the APS
- A request for immediate compliance = You have 30-60 days to produce it
- A possible published formal notice = On the Garante's website

This isn't hypothetical: in 2024, the Garante sanctioned more than 300 organisations for violating Art. 30.

Box: Art. 30 Compliance Checklist

Print this out and check off each item:

- [ ] Have you appointed a privacy officer (even an internal one)?
- [ ] Have you identified ALL processing activities (sign-ups, newsletter, photos, donations)?
- [ ] For each activity, have you documented: purpose, legal basis, data processed, recipients, retention period?
- [ ] Have you verified that your providers (platforms, email services) have GDPR Art. 28 contracts?
- [ ] Do you store the register digitally, with backups, accessible for audits?
- [ ] Do you update the register whenever you add a new activity (e.g. a new social media channel)?
- [ ] Do you have a data deletion policy? (E.g. deleting inactive contacts after 5 years)
- [ ] Is the register dated? Can you track when it was drafted and modified?

Useful images and documents

Structure of the GDPR records of processing register
Keeping an up-to-date register is the foundation of accountability under the GDPR

Internal links to the GDPR and privacy for APS series

Read the other articles in the series:
- [Member consent and privacy for APS: a GDPR-compliant sign-up form](/blog/consenso-soci-privacy-aps-modulo-iscrizione-conforme-gdpr)
- [GDPR-compliant newsletters for APS: double opt-in and Italian software](/blog/newsletter-aps-conforme-gdpr-doppio-opt-in-software-italiani)
- [Privacy for minors in APS: managing data and event photos (the age-13 rule)](/blog/privacy-minorenni-aps-gestione-dati-fotografie-eventi-13-anni)
- [Data breaches in APS: what to do in the first 72 hours (notifying the Garante Privacy)](/blog/data-breach-aps-cosa-fare-72-ore-notifica-garante-privacy)

Call to Action

Using the Garante's simplified template won't cost you anything, but it will protect you from inspections and penalties. If your APS doesn't yet have a registro dei trattamenti, download the official template from the Garante this week and fill it in with your organisation's information.

Set aside 2-3 hours for it. It's worth it. A well-kept register is your best legal defence.

Not sure how to classify a particular processing activity? The Garante offers free preliminary advisory services. You can contact the representative for your region through the garanteprivacy.it website.


Disclaimer: This article is up to date as of May 2026 and reflects the official guidelines of the Garante per la protezione dei dati personali. For complex legal matters, consult a certified DPO or a lawyer specialising in privacy law. GDPR penalties and templates may be updated over time: always check the official garanteprivacy.it website before making critical decisions.