Understanding ROPA: Records of Processing Activities under the GDPR

A ROPA, or Record of Processing Activities, is a record of how an organization collects, uses, stores, shares, and otherwise processes personal data.

Under Article 30 of the GDPR, controllers and processors may be required to maintain one. Think of it as an internal overview of your data processing: what personal data you handle, why you use it, who has access to it, where it goes, and how long you keep it.

A ROPA helps you understand what’s happening with personal data across your organization and demonstrate that you have appropriate processes in place.

What does ROPA mean?

ROPA stands for Record of Processing Activities, sometimes written as RoPA.

Rather than simply listing the personal data your organization holds, a ROPA documents the activities involving that data.

Your processing activities might include:

– managing customer accounts

– sending marketing emails

– recruiting employees

– processing payroll

– providing customer support

– analyzing website usage

Each activity can involve different personal data, purposes, recipients, retention periods, and security measures.

Together, those entries create a structured record of how personal data is processed across your organization.

What is a ROPA under the GDPR?

ROPA requirements come from Article 30 of the GDPR, which requires certain controllers and processors to maintain records of their processing activities.

This supports one of the GDPR’s central principles: accountability. Organizations should not only comply with data protection requirements but also demonstrate how they do so.

Your ROPA helps create that evidence and can also make other privacy work easier. A clear record of your processing activities can help you:

  • identify data that is no longer needed
  • review how long personal data is retained
  • understand which third parties receive data
  • identify international data transfers
  • keep privacy information accurate
  • spot processing that may require a Data Protection Impact Assessment (DPIA)

If a supervisory authority asks to see your records, Article 30 requires you to make them available.

Who needs to keep a ROPA?

Article 30 sets record-keeping requirements for both data controllers and data processors.

A controller determines why and how personal data is processed, while a processor processes it on the controller’s behalf. If you’re unsure which applies to your business, see our guide to data controllers vs data processors.

Do businesses with fewer than 250 employees need a ROPA?

Not always, but the exemption is narrower than it sounds.

Under the GDPR rules currently in force, organizations employing fewer than 250 people may be exempt from the Article 30 record-keeping requirement unless their processing:

  • is likely to result in a risk to people’s rights and freedoms
  • is not occasional
  • includes special categories of personal data, or
  • includes personal data relating to criminal convictions and offenses.

That “not occasional” condition is particularly important. A smaller business that routinely processes personal data cannot assume it is automatically exempt simply because it has fewer than 250 employees.

Are the ROPA rules changing?

Changes have been proposed, but the existing Article 30 requirements still apply.

The European Commission has proposed expanding the exemption to organizations with fewer than 750 employees, with record-keeping required when processing is likely to pose a high risk to individuals’ rights and freedoms. The proposal forms part of a wider EU simplification initiative and, as of September 2026, has not replaced the current rules.

For now, organizations should continue to work from the Article 30 requirements currently in force.

What information should a ROPA include?

ROPA requirements for controllers

Under Article 30(1), a controller’s Record of Processing Activities should include:

– where possible, a general description of the technical and organizational security measures in place

– the name and contact details of the controller and, where applicable, joint controller, representative, and Data Protection Officer (DPO)

– the purposes of processing

– the categories of people whose data is processed

– the categories of personal data processed

– the categories of recipients the data has been or will be disclosed to

– relevant transfers to third countries or international organizations and, where required, documentation of appropriate safeguards

– where possible, expected time limits for deleting different categories of data

What your ROPA needs to contain depends on whether you are acting as a controller or a processor.

Article 30 does not prescribe one particular layout. Your record can be organized in the way that makes the most sense for your organization, as long as it contains the required information and is maintained in writing, including electronically.

Organizations often record additional information, such as the lawful basis for each activity. iubenda’s Register of Data Processing Activities lets you track processing activities alongside details such as their legal bases, retention policies, parties involved, and other relevant information.

ROPA requirements for processors

Processors maintain a slightly different record.

Under Article 30(2), it should include:

  • the name and contact details of the processor and each controller it acts for and, where applicable, their representatives and Data Protection Officer (DPO)
  • the categories of processing carried out for each controller
  • relevant transfers to third countries or international organizations and applicable safeguards
  • where possible, a general description of technical and organizational security measures

The difference reflects the roles each party plays under the GDPR. A controller determines the purposes and means of processing, while a processor handles personal data on the controller’s behalf.

What does a ROPA look like? A simple example

A ROPA is usually structured around individual processing activities.

Imagine your business sends marketing emails to customers who have signed up to receive them. One entry could look something like this:

ROPA fieldExample
Processing activityEmail marketing
PurposeSending marketing communications
Data subjectsCustomers and subscribers
Personal dataName, email address, marketing preferences
RecipientsEmail marketing provider
RetentionAccording to the organization’s retention policy
Security measuresAccess controls and other appropriate safeguards

Another entry might cover employee payroll. Another could cover recruitment, customer support, account management, or website analytics.

The aim isn’t to create a single, comprehensive description of everything your company does. It’s about breaking down your process into identifiable activities and documenting the relevant information for each.

How do you create a ROPA?

Creating a ROPA usually starts with understanding where personal data exists across your organization and how it is used.

1. Identify your processing activities

Look across the business rather than focusing only on your website.

Marketing, HR, sales, finance, IT, operations, and customer support may all process personal data in different ways.

2. Map the personal data involved

For each activity, establish:

  • what personal data is used
  • where it comes from
  • where it is stored
  • who can access it
  • which systems or vendors receive it
  • where it is transferred

This is why GDPR data mapping and ROPA creation are closely connected. A data map can help uncover the information you need to build an accurate record of processing activities.

3. Document why the data is processed

Identify the purpose of each processing activity.

“Customer management,” for example, is more useful than simply writing “business purposes.” Your ROPA should make it easy to understand what the processing actually involves.

4. Record recipients, transfers, and retention periods

Identify internal and external recipients of personal data, relevant international transfers, and the retention periods for different categories of data.

5. Add the relevant security information

Where possible, include a general description of the technical and organizational measures used to protect the data.

6. Keep the ROPA updated

A ROPA should reflect what your organization is actually doing with personal data, not what it was doing when the document was first created.

How often should you update your ROPA?

The GDPR does not impose a fixed schedule, such as “once a year.”

Instead, your ROPA should remain accurate and up to date as your processing changes.

That means reviewing it when, for example, you:

– introduce a new product or service

– start collecting a new type of personal data

– add or change a vendor

– use personal data for a new purpose

– change your retention periods

– begin transferring data to another country

– stop a processing activity

Periodic reviews are also useful for catching changes in activities that have not been formally documented.

ROPA vs data mapping: what’s the difference?

Data mapping and a ROPA are closely related, but they are not the same thing.

Data mapping helps you understand how personal data moves through your organization.

A ROPA documents the processing activities involving that data and the information required under Article 30.

For example, data mapping might show that an email address passes from a signup form into your CRM and then into an email marketing platform.

That information can then help you document the corresponding marketing activity in your ROPA.

Essentially, data mapping can help you build and maintain your Record of Processing Activities, but the two are not automatically interchangeable.

ROPA vs privacy policy: what’s the difference?

A ROPA is also not the same as a privacy policy.

A ROPA is an internal record of processing activities. A privacy policy or privacy notice communicates relevant information about how your organization processes personal data to the people whose data you handle.

They can contain some overlapping information, including:

– purposes of processing

– categories of personal data

– recipients

– retention information

– international transfers

However, they serve different purposes. Maintaining an accurate record of what your organization actually does with personal data can make it easier to keep your privacy information consistent with those practices.

ROPA vs DPIA: what’s the difference?

Another acronym you’re likely to encounter alongside ROPA is DPIA, or Data Protection Impact Assessment.

They address different parts of GDPR accountability.

A ROPA documents your processing activities.

A DPIA assesses the risks associated with processing that is likely to result in a high risk to people’s rights and freedoms and helps identify measures to reduce those risks.

You may therefore record an activity in your ROPA and separately determine whether it requires a DPIA.

For example, introducing technology that processes sensitive personal data at scale may need more than an entry in your ROPA. You may also need to assess the risks involved before proceeding.

See our guide to data protection impact assessments for more on when a DPIA may be required.

No. A ROPA records processing activities across your organization, while a consent record provides evidence of a particular individual’s consent when consent is the legal basis relied upon.

For example, proof of consent may include information about who consented, when they did so, what they agreed to, and what information they were shown at the time.

These records serve different purposes, even though both can form part of your wider GDPR documentation.

Read more about what should be included in your consent records.

Make your Record of Processing Activities easier to manage

Your processing activities will change over time. New tools, vendors, teams, and data uses can all affect what needs to be recorded.

iubenda’s Register of Data Processing Activities helps you keep that information organized in one place, making it easier to update your records and track what’s happening across your business.

Explore iubenda’s Register of Data Processing Activities and book a demo to get started.

Follow us on: