Guide

Records of Processing Activities (RoPA): What Article 30 Requires

What a RoPA is, who has to maintain one under GDPR Article 30, and what belongs in it.

7 min read

A Record of Processing Activities, or RoPA, is the inventory GDPR Article 30 expects you to keep: a written account of what personal data you process, why, and how. It is the clearest expression of GDPR's accountability principle, the idea that you must be able to demonstrate compliance, not just assert it. When a regulator asks how you handle personal data, the RoPA is what you show them.

Who Has to Maintain One

Article 30 applies broadly, but there is a partial exemption for organizations under 250 employees. The exemption is narrow: it falls away if your processing is not occasional, is likely to risk people's rights, or involves special-category data. In practice, most companies that process personal data as a routine part of their business should maintain a RoPA regardless of size, because the exemption rarely holds.

What Belongs in a RoPA

A RoPA typically records, for each processing activity:

  • The purpose of the processing.
  • The categories of data subjects and the categories of personal data involved.
  • The categories of recipients the data is shared with.
  • Any international transfers of the data.
  • The retention periods for different categories of data.
  • A general description of the security measures protecting the data.

Controllers and processors keep slightly different versions, but the shape is the same: a living map of your data processing.

Why It Is Hard to Keep Current

A RoPA is only useful if it reflects reality, and reality changes: new tools, new data flows, new vendors. A RoPA maintained by hand in a spreadsheet drifts out of date the moment someone adds a system and forgets to log it. The record is easy to create once and hard to keep true, which is the whole problem.

How Concord Fits

Concord Privacy's data mapping maintains an inventory of the systems and data across your organization, which is the raw material a RoPA is built from. RoPA report generation is available as a paid add-on on top, so the record is produced from your live data map rather than typed up separately and left to go stale.

Get Started

Run Your Privacy Program on One Platform

Concord brings consent, privacy requests, data mapping, and policy management together, so a rights request is a workflow, not a fire drill.