The records of processing activities requirement in Article 30 is the GDPR’s inventory obligation: a living register of what personal data you process, why, where it goes, and how long you keep it. It is also the first document a supervisory authority requests, because an absent or stale ROPA signals that the rest of the program is guesswork.
| Regulation | GDPR, Article 30 |
|---|---|
| Max penalty | EUR 10M or 2% of global turnover (Art. 83(4)) |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
The required fields
For controllers, each processing activity needs: controller identity and contacts (with DPO and Article 27 representative where relevant), the purposes, categories of data subjects and of personal data, categories of recipients including those in third countries, transfer destinations and safeguards, envisaged retention periods, and a general description of Article 32 security measures.
Processor records are shorter: processor and controller identities, categories of processing performed for each controller, transfers, and security measures.
A useful template adds working columns beyond the legal minimum: lawful basis per purpose, the source system, the internal owner, and whether a DPIA exists. Those extras turn the ROPA from a compliance artifact into the operating map for DSARs and breach response.
The exemption that mostly is not one
Article 30(5) exempts organizations under 250 employees, unless the processing is likely to result in a risk to individuals, is not occasional, or includes special category or criminal conviction data. Employee payroll is regular. Customer records are regular. Marketing is regular. The EDPB’s position paper on Article 30(5) confirms the exemption only lifts the duty for the genuinely occasional activities, so a small company still records its routine processing. Treat the exemption as removing edge cases, not the obligation.
Building and maintaining it
- Inventory by interviewing system owners, not just IT: HR, marketing, finance, and product each run processing the others cannot see.
- Record per purpose, not per system. One CRM typically supports several distinct processing activities with different bases and retention.
- Reconcile against reality. Compare the ROPA’s website-related entries against what your site actually does; embedded tags added by marketing rarely make it into the register. A free scan gives you the actual third-party list to reconcile against.
- Wire updates into change management: new vendors, new forms, and new tools enter the ROPA at approval time.
- Review quarterly and version the document, so you can show the authority the record as it stood at any date.
The ROPA feeds directly into your privacy notice, DPIA triggers, and vendor contracts. Our controller-processor guide covers the contractual layer that the recipient categories in your ROPA imply.