Auditen
Home / Frameworks / GDPR / Records of processing activities
GDPR · Art. 30

Records of processing activities

Article 30 requires organizations to maintain a detailed, written inventory of all personal data processing activities they perform. This record serves as the primary evidence of accountability, providing a comprehensive map of what data is processed, why it is processed, and where it goes.

What it means

The Record of Processing Activities (ROPA) is intended to be the "source of truth" for an organization's data landscape. Rather than listing software tools, it focuses on the *activities*—the specific business purposes that necessitate the use of personal data.

Requirements differ based on your role. Controllers must document the purpose of processing and retention periods, while Processors (those acting on behalf of a controller) focus more on the categories of processing they perform and the identities of the controllers they serve.

While an exemption exists for organizations with fewer than 250 employees, it is narrow. It generally does not apply if the processing is not occasional, involves special categories of data (e.g., health or genetic data), or poses a risk to the rights and freedoms of individuals.

How to meet it

Evidence an auditor asks for

  • The completed ROPA document or database export showing all required Article 30 fields.
  • Version history or a change log proving the record is reviewed and updated regularly rather than being a static document.
  • Cross-references between the ROPA and your external Privacy Notice to ensure what you tell users matches what you actually do.
  • Evidence of the discovery process, such as questionnaires sent to department heads or data flow diagrams used to build the register.

Common pitfalls

  • Treating the ROPA as a one