A record of processing activity (ROPA) is a document that organisations are required to maintain under the General Data Protection Regulation (GDPR). It is a detailed inventory of an organisation’s data processing activities, providing insights into the types of personal data processed, the purposes for which it is processed, and the recipients of the data.
What is a Record of Processing Activity?
A record of processing activity is a document that records all of the processing of personal data that your organisation undertakes. It is central to GDPR compliance because it is the single, central repository of all of the ways your organisation uses data about people.
It will therefore cover anything to do with employees, customers, suppliers and other stakeholders who have a relationship with you.
Statutory Requirement for a ROPA
A record of processing activity is a statutory requirement for larger organisations. Article 30 of the GDPR mandates it, and in the UK your ROPA must be made available to the authorities on request. Article 30 also sets out the types of information it should contain. Therefore a record of processing activity is not something useful – it is a must do for GDPR compliance.
Exceptions to the Law
Organisations that employ fewer than 250 people do not need to keep a record of processing activities unless they process details of:
-
special category data such as health, gender or political views (see more about special category data here).
-
details of criminal convictions
In addition frequent or regular data processing does mean a ROPA is still needed no matter how large the organisation. Finally a ROPA is still required if the processing poses risks to people’s rights and freedoms.
Therefore small businesses do not get a blanket exception to having a ROPA.
Sign Up Here:
The record of processing activities serves several key purposes for organisations: Transparency: It enables organisations to demonstrate their compliance with the GDPR’s transparency obligations by providing clear information about their data processing activities. Data Minimisation: It helps organisations ensure that they are only collecting and processing the personal data that is necessary for the specific purposes for which it is intended. Risk Assessment: It provides a foundation for organisations to conduct data protection impact assessments (DPIAs) by identifying potential data protection risks related to their processing activities. Audit Capability: It facilitates internal audits and external audits, allowing organisations to demonstrate their compliance with data protection requirements. Data Subject Requests: It enables organisations to effectively respond to subject access requests (SARs) by providing easy access to information about the personal data being processed. The record of processing activities should include the following information: Best practice for a record of processing activities means also including where possible: details of any controller-processor contracts or data sharing agreements any data privacy impact assessments done to mitigate the risks of data processing records of consent given by data subjects for the processing of their data a link to your publicly available privacy statement to ensure the two documents are consistent The record of processing activities should be updated regularly as the organisation’s data processing activities change. This could be quarterly, annually, or more frequently depending on the frequency of changes and the sensitivity of the data being processed. We can help you with your GDPR compliance by: delivering training to you and your team, giving you the skills and confidence to meet your statutory duties providing data protection officer services auditing and reviewing your ROPA, policy documents, and other GDPR requirements Get in touch to find out more. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
Purpose of a Record of Processing Activity
Content of a Record of Processing Activity
Other Things to Consider
Updating your Record of Processing Activity
Need Help with GDPR Compliance?

- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: