Record of Processing Activities (ROPA)
The Article 30 register listing your real data-processing activities, their purposes, people, data, recipients, transfers, and retention.
What it is
A Record of Processing Activities is the internal register required by GDPR Article 30. A controller's record groups processing into activities such as payroll, customer support, or product analytics, then records the purposes, categories of people and data, recipients, international transfers, planned erasure time limits, and a general description of security measures. A processor keeps a different view: the categories of processing it performs for each controller.
Build the ROPA once the data map is credible, and use it as the index for privacy notices, retention rules, vendor reviews, and data subject requests. It must stay current and be available to the supervisory authority on request. The under-250-person exception is narrow and disappears for processing that is not occasional, creates risk, or involves special category or criminal-conviction data.
Gotcha: a ROPA is not a dump of every database column and it is not a policy copied from another company. Organize it around real processing activities and connect each row to owners, systems, vendors, and review dates. A pristine spreadsheet that omits support exports, logs, and the new analytics SDK is evidence that the register is stale, not that the processing is controlled.
Ask AI for it
Build an Airtable-ready GDPR Article 30 ROPA from the product and vendor information below. Create separate controller and processor tables. For each activity include its owner, purpose, lawful basis, categories of people and personal data, recipients, processors, international transfers and safeguards, retention or erasure deadline, security measures, source systems, destination systems, and last review date. In the processor table also name each controller and the categories of processing performed for it. Group rows by business activity rather than database column, mark missing evidence with bracketed TODOs, and return both a human-readable table and CSV column headers that import cleanly into Airtable.