EU Privacy Law EU/EEA

Records of Processing Activities (ROPA): GDPR Template and Best Practices

What GDPR Article 30 records must contain for controllers and processors, who the under-250 exemption really covers, and how to keep a ROPA current.

Regulation

GDPR, Article 30

Max Penalty

EUR 10 million or 2% of global annual turnover for record-keeping failures

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • Article 30 requires controllers and processors to maintain written records of their processing activities and produce them to the supervisory authority on request.
  • Controller records need seven elements per processing activity, from purposes and data categories to transfers and retention; processor records need five.
  • The under-250-employee exemption is narrower than it looks: it disappears if processing is non-occasional, risky, or involves special category data, which excludes most real businesses.
  • The ROPA is the backbone document: DSARs, DPIAs, breach scoping, and vendor management all depend on it being accurate.
  • Regulators use the ROPA as the first document request in almost every investigation.

The records of processing activities requirement in Article 30 is the GDPR’s inventory obligation: a living register of what personal data you process, why, where it goes, and how long you keep it. It is also the first document a supervisory authority requests, because an absent or stale ROPA signals that the rest of the program is guesswork.

RegulationGDPR, Article 30
Max penaltyEUR 10M or 2% of global turnover (Art. 83(4))
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

The required fields

For controllers, each processing activity needs: controller identity and contacts (with DPO and Article 27 representative where relevant), the purposes, categories of data subjects and of personal data, categories of recipients including those in third countries, transfer destinations and safeguards, envisaged retention periods, and a general description of Article 32 security measures.

Processor records are shorter: processor and controller identities, categories of processing performed for each controller, transfers, and security measures.

A useful template adds working columns beyond the legal minimum: lawful basis per purpose, the source system, the internal owner, and whether a DPIA exists. Those extras turn the ROPA from a compliance artifact into the operating map for DSARs and breach response.

The exemption that mostly is not one

Article 30(5) exempts organizations under 250 employees, unless the processing is likely to result in a risk to individuals, is not occasional, or includes special category or criminal conviction data. Employee payroll is regular. Customer records are regular. Marketing is regular. The EDPB’s position paper on Article 30(5) confirms the exemption only lifts the duty for the genuinely occasional activities, so a small company still records its routine processing. Treat the exemption as removing edge cases, not the obligation.

Building and maintaining it

  1. Inventory by interviewing system owners, not just IT: HR, marketing, finance, and product each run processing the others cannot see.
  2. Record per purpose, not per system. One CRM typically supports several distinct processing activities with different bases and retention.
  3. Reconcile against reality. Compare the ROPA’s website-related entries against what your site actually does; embedded tags added by marketing rarely make it into the register. A free scan gives you the actual third-party list to reconcile against.
  4. Wire updates into change management: new vendors, new forms, and new tools enter the ROPA at approval time.
  5. Review quarterly and version the document, so you can show the authority the record as it stood at any date.

The ROPA feeds directly into your privacy notice, DPIA triggers, and vendor contracts. Our controller-processor guide covers the contractual layer that the recipient categories in your ROPA imply.

Frequently Asked Questions

What must a controller's ROPA contain?

Per Article 30(1): the controller's name and contacts (plus DPO and representative where applicable), purposes of processing, categories of data subjects and personal data, categories of recipients, third-country transfers with safeguards, envisaged retention periods, and a general description of security measures.

Do companies under 250 employees need a ROPA?

Usually yes in practice. The Article 30(5) exemption fails if processing is likely to risk individuals' rights, is not occasional, or includes special category or criminal data. Payroll and CRM alone are 'not occasional,' so the exemption rarely applies fully.

Do processors need their own records?

Yes. Article 30(2) requires processors to record all categories of processing carried out for each controller, transfer details, and security measures. Cloud vendors and agencies are routinely asked for these in audits.

What format does a ROPA need to be in?

Written form, including electronic (Article 30(3)). A spreadsheet is acceptable; larger organizations use dedicated tools. What matters is that it is current, complete, and producible on request.

How often should we update the ROPA?

Whenever processing changes: new vendor, new purpose, new data category, new transfer. A quarterly review cycle with system owners is a common baseline, plus a trigger in procurement so new tools enter the record at onboarding.

Regulatory Crosswalk

UK GDPRLGPDISO/IEC 27701

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.