Skip to content
Clarium
Back to blog
RoPArecord of processing activitiesGDPRArticle 30complianceframework

Record of Processing Activities (RoPA): The Framework

18 August 2026Will Wilson

A Record of Processing Activities (RoPA) is your organisation's register of everything it does with personal data: what you collect, why, whose data it is, who receives it, where it travels and when it gets deleted. It is the operating map of your processing, and it is the first document a regulator asks for when an investigation opens.

This is the framework page for the RoPA — the single definition that the rest of the blog links to instead of re-explaining the register each time.

The RoPA is the Article 30 record

The RoPA is not a separate obligation from Article 30; it is the Article 30 record. Article 30 of the UK and EU GDPR makes keeping the register mandatory for the large majority of controllers and processors, and it is the document you hand to the ICO, the CNIL or Jersey's JOIC on request.

Every entry records a single processing activity against the Article 30 fields: the purpose, the categories of data subjects and personal data, the recipients, any third-country transfers and the safeguards relied on, the retention periods, and the security measures.

What each entry records

In plain terms, each row answers seven questions:

  1. Who is responsible — your entity and privacy contact, plus any joint controller, EU representative or DPO.
  2. Why you process the data — a real purpose, written the way the business would describe it.
  3. Whose data it is — distinct groups named: employees, customers, website visitors.
  4. What data it is — specific categories, not a vague bucket.
  5. Who receives it — internal teams and external recipients, including processors.
  6. Where it travels — any third-country transfer and the safeguard that covers it.
  7. When it leaves, and how it is protected — retention periods and security measures.

Who needs one

Controllers keep the full Article 30(1) record; processors keep a narrower one under Article 30(2). The 250-employee exemption only applies where processing is occasional, involves no special category data and is low-risk — which is rarely true for an organisation that pays staff or holds customer accounts.

The RoPA feeds the whole programme

The register is what a DPIA reads its processing description from, what a DSAR searches against, and what a breach response scopes against. Keep the register current and every downstream obligation gets faster; let it rot and each one becomes an archaeology project.

For a deeper practical walkthrough, see our guide to what a RoPA is and how to build one.

Ready to simplify your GDPR compliance?

Try Clarium free — no credit card required.

Start Free Trial