
Need to Create or Update Your RoPA? You’re in the right place
Understand what personal data your organisation uses, why it uses it, where it goes and how long it should be retained.
If your organisation doesn’t have an up-to-date Record of Processing Activities (RoPA), you’re not alone. Many organisations either don’t have one at all or rely on a template that no longer reflects how personal data is actually used across the business.
RoPA Preparation and Review for UK Organisations
Did you know that if you’re investigated by the ICO a RoPA is the first thing they ask you for.
An incomplete or outdated RoPA can leave your organisation unable to explain what personal data it processes, why it uses that information, who it shares it with or how long it retains it.
We work with the relevant people across your organisation to understand how personal data is actually collected, used, shared, this is done through mapping of your processing activities. Once we understand this we can build the RoPA.

Clara Westbrook
25+ Years PQE
Founder | Qualified Solicitor | Data Protection Specialist
07976 939 016
Audits >
Why an accurate RoPA matters
A Record of Processing Activities supports an organisation’s wider privacy and information-governance framework.
An inaccurate or incomplete RoPA can result in:
- Inconsistent privacy notices: The information given to individuals may not match what happens in practice.
- Undocumented processing: New systems, suppliers, AI tools or business activities may be missing.
- Unclear retention: Personal data may be kept without a properly defined retention period.
- Unidentified risks: Processing requiring a Data Protection Impact Assessment may not be recognised.
- Accountability gaps: The organisation may struggle to demonstrate compliance during an audit or regulatory enquiry.
Article 30 of the UK GDPR requires controllers and processors to maintain specified records of their processing and make those records available to the ICO on request.
Is this service right for your organisation?
Our RoPA preparation and review service is suitable for organisations that:
- do not currently have a RoPA;
- have a RoPA that has not been reviewed recently;
- have introduced new systems, suppliers, services or AI tools;
- have several departments completing records inconsistently;
- are preparing for an audit, procurement exercise or regulatory enquiry; or
- need their RoPA to align with privacy notices, DPIAs and retention arrangements.
You do not need to assemble a perfect set of records before contacting us. We can help identify the information required and agree an approach that reflects the size and complexity of your organisation.
How often should a RoPA be reviewed?
There is no single annual statutory review date. However, a RoPA should remain accurate and should be updated whenever the organisation’s processing activities materially change.
A review may be needed when you introduce new software, appoint a new supplier, start using AI, transfer information internationally, launch a new service or change how long personal data is retained.
The ICO recommends maintaining the record electronically so that it can be amended easily, reviewing it against actual processing activities and clearly assigning responsibility for keeping it up to date.
Our three-step RoPA process
We provide a structured approach that turns information held across different teams into one coherent and maintainable record.
- Discovery and data mapping
We begin by understanding your organisation, its services and the areas in which personal data is processed.
We review any existing RoPA, data map, privacy notices, retention schedules and related documentation. We then work with relevant stakeholders in areas such as HR, finance, marketing, IT and operations.
2. Legal review and preparation
We identify and document the organisation’s processing activities and consider whether the information recorded is complete and consistent.
This includes examining purposes, data categories, individuals affected, lawful bases, recipients, international transfers, retention periods and relevant security arrangements.
3. Validation and handover
We review the completed RoPA with your organisation, resolve outstanding questions and identify any related compliance gaps.
You receive an editable record, together with practical guidance explaining how it should be updated as the organisation changes.
4. Deliverables
At the end of the project, you will receive:
- a completed or updated RoPA in an editable format;
- an identified-gaps and actions summary;
- details of inconsistencies with related documentation;
- recommendations for any required DPIAs or policy updates; and
- practical guidance on maintaining the RoPA.
Costing structure
We offer fixed-fee and day-rate options. The cost will depend on the size of the organisation, the number of processing activities involved, the quality of any existing records and whether stakeholder interviews or data-flow mapping are required.
Service | Fee | VAT |
RoPA Health Check | Review of an existing RoPA for completeness, accuracy and Article 30 alignment | From £375 + VAT |
RoPa Update | Updating an existing record following changes to processing, systems or suppliers | From £375 + VAT |
New RoPA Preperation | End-to-end preparation, including stakeholder discussions and processing-activity mapping | From £375 + VAT |
RoPA Maintenance Support | Periodic reviews and updates as processing activities change | Retainer or agreed day rate |
We will agree the scope and fee with you before work begins. Where the full extent of the work is not yet known, we can complete an initial health check before providing a fixed quotation for the remaining work.
The questions we address when preparing your RoPA
The difficult part is rarely creating the spreadsheet. It is making accurate and consistent decisions about what should be recorded.
- We help organisations determine:
- what constitutes a separate processing activity;
- whether they act as a controller, processor or joint controller;
- which lawful basis supports each activity;
- which special-category condition applies where relevant;
- which suppliers and recipients should be recorded;
- whether international-transfer arrangements are properly documented;
- whether retention periods are clear and defensible; and
- whether particular activities require a DPIA.
- This prevents the RoPA from becoming either so broad that it is of little practical use or so detailed that it cannot realistically be maintained.
Why choose us
Your RoPA should not exist in isolation. It should align with your privacy notices, retention arrangements, DPIAs, supplier records and actual working practices.
We are a solicitor-led organisation with over 25 years’ experience in data protection and privacy law. We’ve handled DSARs involving over 20,000 + documents. Supported organisations in employment disputes, reduced internal review time by a matter of weeks. We support organisations in Woking, Surrey and across the UK with practical data protection advice.
We’ve worked with organisations across multiple sectors including WarnerMedia, Yum! Brands, Burberry, Expedia and Société Générale on DSAR compliance matters and we’re confident we can help you.
Get in touch
If you have any questions about our services call us on +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4pm). If you would like us to call or email you, please leave your details, and we will be in touch.
Westbrook Data Protection Services Limited.
2nd Floor, Midas House, 62 Goldsworth Road
Woking, Surrey GU21 6LQ
View our Privacy Policy here
Explore More Data Protection & Privacy Services
Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]
Stay ahead with expert data protection tips
Get practical advice, legal updates, and exclusive insights.
Frequently Asked Questions
What is a Record of Processing Activities (RoPA)?
A RoPA is a structured record of how an organisation processes personal data, serving as a governance document that helps understand data flows, identify gaps, and demonstrate compliance.
When is a RoPA legally required under UK GDPR?
A RoPA is legally required if your organisation employs 250 or more staff, carries out non-occasional processing, or processes special category or criminal offence data, regardless of size.
What should a RoPA include to be compliant?
A compliant RoPA should document categories of data subjects, purposes of processing, data recipients, international transfers if any, retention periods, and security measures, with the level of detail appropriate to the organisation.
What common issues do organisations face with their RoPA?
Organisations often treat RoPA as a one-off task, leading to records that are outdated, inconsistent with privacy notices, missing lawful bases or retention details, or not reflecting actual processes.
How does a RoPA fit into wider data governance?
A RoPA connects to privacy notices, DPIAs, data retention schedules, breach management, and accountability obligations, serving as a central document that aligns all these elements and highlights any inconsistencies.



