What Is a Record of Processing Activities (ROPA)?
A ROPA gives an organisation a practical map of its personal-data processing and supports UK GDPR accountability, risk management and day-to-day decision-making.
Did you know? The small-organisation exemption from Article 30 record keeping is limited. It may not apply where processing is regular, involves special category or criminal offence information, or is likely to create a risk to people’s rights and freedoms.
A record of processing activities, usually called a ROPA, is an internal record of how an organisation uses personal information. It provides a structured view of the purposes, people, information, recipients, transfers, retention and security measures involved in each processing activity.
Why does a ROPA matter?
A ROPA helps an organisation understand what it is doing with personal information and demonstrate accountability. It can also reveal gaps between actual practice and privacy notices, contracts, retention schedules or security controls. Without a reliable record, it is difficult to answer basic questions during an audit, data breach, rights request or new project.
Who must keep a ROPA?
Article 30 of the UK GDPR contains record-keeping duties for controllers and processors. There is a limited exemption for some organisations with fewer than 250 employees, but it does not apply where processing is likely to risk people’s rights and freedoms, is not occasional, or includes special category or criminal offence information. Many organisations therefore find that at least part of their processing must be recorded, and maintaining a fuller record is often valuable for accountability.
What should a controller’s ROPA contain?
- the organisation’s name and contact details, and those of any joint controller, representative or DPO where applicable;
- the purposes of the processing;
- the categories of people and personal information involved;
- the categories of recipients;
- details of international transfers and the relevant safeguards;
- the envisaged retention or deletion periods; and
- a general description of relevant technical and organisational security measures.
What should a processor record?
A processor’s record should identify the controllers it acts for, the categories of processing carried out for each controller, relevant international transfers and a general description of security measures. Processor records should be consistent with the written contracts governing the work.
Start with data mapping
A ROPA is only as accurate as the information behind it. Speak to the people who operate the processes, review systems and suppliers, and trace how information enters, moves through and leaves the organisation. Record real activities rather than copying broad statements from a template.
How detailed should each entry be?
The entry should be specific enough for someone unfamiliar with the activity to understand its purpose and main risks. Grouping genuinely similar activities can be sensible, but labels such as “business administration” or “HR” may be too broad if they hide materially different purposes, data or recipients.
Link the ROPA to other compliance records
The ROPA becomes more useful when it connects to lawful-basis decisions, legitimate interests assessments, DPIAs, processor contracts, privacy notices, retention schedules and data-transfer assessments. Those links make inconsistencies easier to find and future reviews more efficient.
How often should it be updated?
Assign clear ownership and review the record regularly. Update it when a new service, supplier, system, dataset, purpose, recipient or international transfer is introduced, or when an existing activity ends. Periodic sign-off by process owners can help keep the record accurate.
The ICO’s accountability framework explains the expected record-keeping controls.
Need to build or refresh your ROPA?
WDPS can carry out data mapping, structure the record, check Article 30 coverage and align it with privacy notices, retention, contracts and lawful-basis decisions.
View our ROPA service →
Frequently asked questions
Is a data map the same as a ROPA?
Not exactly. Data mapping is the process of discovering how information flows. The ROPA is the structured record of processing activities built from that evidence.
Can we keep the ROPA in a spreadsheet?
Yes. The law does not require a particular software product. The important points are that the record contains the required information, is in writing, is accessible and remains accurate.
Does every supplier need a separate ROPA entry?
Not necessarily. The structure should reflect the organisation’s processing activities, but recipients and processors must be recorded clearly enough to understand the flow of information and the safeguards involved.
Who should own the ROPA?
A central data protection lead can coordinate it, but operational owners should verify the entries for their processes. Clear responsibilities and regular review are essential.
Written by Clara Westbrook, solicitor and founder.
Speak to our team
Explore More Data Protection & Privacy Services
Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]





