What is a Record of Processing Activities?
A Record of Processing Activities (RoPA) is a mandatory, written inventory of an organisation's data processing operations, required by Article 30 of the GDPR.The RoPA forms the backbone of the GDPR's accountability principle. By mapping out exactly what data is collected, where it goes, and why it is needed, a RoPA acts as a central control document for data protection compliance. It must be in writing, which explicitly includes electronic form (Article 30(3)).
The 250-employee exception trap
While Article 30(5) provides an exemption for enterprises with fewer than 250 employees, this exemption is immediately nullified if processing is not occasional, poses a risk, or involves sensitive data.This is a classic question in data protection exams. The law states that the obligation to maintain a RoPA does not apply to an enterprise or an organisation employing fewer than 250 persons. However, Article 30(5) then immediately introduces three strict conditions that override the exception. Small organisations must maintain a RoPA if the processing they carry out:
- is likely to result in a risk to the rights and freedoms of data subjects;
- is not occasional (e.g., regular payroll processing, customer database management); or
- includes special categories of data (Article 9) or personal data relating to criminal convictions and offences (Article 10).
Because almost every business processes employee or customer data on a regular (not occasional) basis, in practice, the majority of small businesses must still maintain a RoPA.
Controller vs. Processor requirements
Both controllers and processors must maintain a RoPA, but Article 30 specifies different content requirements for each role.A controller documents its own processing purposes, whereas a processor documents the categories of activities it performs on behalf of others.
Controller's RoPA (Article 30(1))
The controller's record must contain the following detailed information:
- The name and contact details of the controller (and any joint controller, representative, and DPO).
- The purposes of the processing.
- A description of the categories of data subjects and of the categories of personal data.
- The categories of recipients to whom the personal data have been or will be disclosed.
- Where applicable, transfers of personal data to a third country, including the identification of that country.
- Where possible, the envisaged time limits for erasure of the different categories of data.
- Where possible, a general description of the technical and organisational security measures.
Processor's RoPA (Article 30(2))
The processor's record is slightly narrower and must contain:
- The name and contact details of the processor(s) and of each controller on behalf of which the processor is acting (and their representatives / DPO).
- The categories of processing carried out on behalf of each controller.
- Where applicable, transfers of personal data to a third country.
- Where possible, a general description of the technical and organisational security measures.
Master GDPR Accountability Rules
Practise for your DPO certification with exam questions covering Article 30 exemptions, RoPA content, and the distinction between controllers and processors.
Start freeTry 30 questions free — AI-powered explanations included.Form and disclosure
Under Article 30(4), the controller or processor must make the RoPA available to the supervisory authority upon request.This makes the RoPA the first document a data protection authority will ask for during an audit or investigation. It is the primary means of demonstrating compliance with the GDPR. According to Article 30(3), the record shall be in writing, including in electronic form.
Frequently asked questions
What is a Record of Processing Activities (RoPA)?
A RoPA is a formal, written document (including electronic form) maintained by an organisation that details its data processing operations. Under Article 30 of the GDPR, it serves as a primary tool to demonstrate compliance and the accountability principle.
Are small businesses with fewer than 250 employees exempt from keeping a RoPA?
Not automatically. While Article 30(5) provides a general exception for organisations with fewer than 250 employees, this exception is severely limited. They must still maintain a RoPA if their processing is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or it includes special categories of data or data relating to criminal convictions.
Do processors need to maintain a RoPA?
Yes, processors also have an obligation to maintain a RoPA under Article 30(2), but their record is generally limited to categories of processing activities carried out on behalf of a controller (along with details of the controller and security measures), rather than the full scope required from controllers.
Does the RoPA need to be shared with the supervisory authority?
Under Article 30(4), the controller or processor must make the record available to the supervisory authority on request.