EU-wide · Article 30 GDPR

Record of Processing Activities (RoPA): Requirements and Exceptions

Grounded in the primary source (EUR-Lex) · Stand: 08/2026

A Record of Processing Activities (RoPA) is one of the most critical documents an organisation must maintain under the GDPR to demonstrate accountability. Mandated by Article 30, it details exactly what personal data is being processed, why, and by whom. Many DPO exam candidates fall into a common trap: believing that small businesses are automatically exempt from this requirement. In this guide, we clarify what a RoPA must contain, the differences for controllers versus processors, and exactly how the "fewer than 250 employees" exception really works.

Key facts at a glance

Relevant Article
Article 30 of the GDPR
Controller Obligations
Must document purposes, data categories, recipients, transfers, and security measures.
Processor Obligations
Must maintain a RoPA, but focused on activities carried out on behalf of a controller.
The 250 Employees Trap
The exception only applies if processing is occasional, poses no risk to rights, and involves no sensitive/criminal data.

On this page

  1. What is a Record of Processing Activities?
  2. The 250-employee exception trap
  3. Controller vs. Processor requirements
  4. Form and disclosure
  5. FAQ

What is a Record of Processing Activities?

A Record of Processing Activities (RoPA) is a mandatory, written inventory of an organisation's data processing operations, required by Article 30 of the GDPR.The RoPA forms the backbone of the GDPR's accountability principle. By mapping out exactly what data is collected, where it goes, and why it is needed, a RoPA acts as a central control document for data protection compliance. It must be in writing, which explicitly includes electronic form (Article 30(3)).

The 250-employee exception trap

While Article 30(5) provides an exemption for enterprises with fewer than 250 employees, this exemption is immediately nullified if processing is not occasional, poses a risk, or involves sensitive data.This is a classic question in data protection exams. The law states that the obligation to maintain a RoPA does not apply to an enterprise or an organisation employing fewer than 250 persons. However, Article 30(5) then immediately introduces three strict conditions that override the exception. Small organisations must maintain a RoPA if the processing they carry out:

Because almost every business processes employee or customer data on a regular (not occasional) basis, in practice, the majority of small businesses must still maintain a RoPA.

Controller vs. Processor requirements

Both controllers and processors must maintain a RoPA, but Article 30 specifies different content requirements for each role.A controller documents its own processing purposes, whereas a processor documents the categories of activities it performs on behalf of others.

Controller's RoPA (Article 30(1))

The controller's record must contain the following detailed information:

Processor's RoPA (Article 30(2))

The processor's record is slightly narrower and must contain:

Master GDPR Accountability Rules

Practise for your DPO certification with exam questions covering Article 30 exemptions, RoPA content, and the distinction between controllers and processors.

Start freeTry 30 questions free — AI-powered explanations included.

Form and disclosure

Under Article 30(4), the controller or processor must make the RoPA available to the supervisory authority upon request.This makes the RoPA the first document a data protection authority will ask for during an audit or investigation. It is the primary means of demonstrating compliance with the GDPR. According to Article 30(3), the record shall be in writing, including in electronic form.

Frequently asked questions

What is a Record of Processing Activities (RoPA)?

A RoPA is a formal, written document (including electronic form) maintained by an organisation that details its data processing operations. Under Article 30 of the GDPR, it serves as a primary tool to demonstrate compliance and the accountability principle.

Are small businesses with fewer than 250 employees exempt from keeping a RoPA?

Not automatically. While Article 30(5) provides a general exception for organisations with fewer than 250 employees, this exception is severely limited. They must still maintain a RoPA if their processing is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or it includes special categories of data or data relating to criminal convictions.

Do processors need to maintain a RoPA?

Yes, processors also have an obligation to maintain a RoPA under Article 30(2), but their record is generally limited to categories of processing activities carried out on behalf of a controller (along with details of the controller and security measures), rather than the full scope required from controllers.

Does the RoPA need to be shared with the supervisory authority?

Under Article 30(4), the controller or processor must make the record available to the supervisory authority on request.

Primary sources

This guide summarises the GDPR for study and general information. It is not legal advice. For a binding interpretation always consult the official text on EUR-Lex, your competent supervisory authority, or a qualified data protection lawyer.