Records of processing activities
Article 30 requires organizations to maintain a detailed, written inventory of all personal data processing activities they perform. This record serves as the primary evidence of accountability, providing a comprehensive map of what data is processed, why it is processed, and where it goes.
What it means
The Record of Processing Activities (ROPA) is intended to be the "source of truth" for an organization's data landscape. Rather than listing software tools, it focuses on the *activities*—the specific business purposes that necessitate the use of personal data.
Requirements differ based on your role. Controllers must document the purpose of processing and retention periods, while Processors (those acting on behalf of a controller) focus more on the categories of processing they perform and the identities of the controllers they serve.
While an exemption exists for organizations with fewer than 250 employees, it is narrow. It generally does not apply if the processing is not occasional, involves special categories of data (e.g., health or genetic data), or poses a risk to the rights and freedoms of individuals.
How to meet it
- Conduct a company-wide data discovery exercise to identify every business process that involves personal data.
- Create a centralized register (spreadsheet or GRC tool) containing mandatory fields: purpose of processing, categories of data subjects, and categories of personal data.
- Document the legal basis for each activity identified in the record.
- List all recipients of the data, including third-party vendors, and specify any international transfers along with the safeguards used (e.g., Standard Contractual Clauses).
- Define specific retention periods for every category of data processed to ensure alignment with your data deletion policy.
- Reference the technical and organizational security measures (TOMs) applied to each processing activity to demonstrate protection.
Evidence an auditor asks for
- The completed ROPA document or database export showing all required Article 30 fields.
- Version history or a change log proving the record is reviewed and updated regularly rather than being a static document.
- Cross-references between the ROPA and your external Privacy Notice to ensure what you tell users matches what you actually do.
- Evidence of the discovery process, such as questionnaires sent to department heads or data flow diagrams used to build the register.
Common pitfalls
- Treating the ROPA as a one