Record of processing activities (RoPA)

Data protection glossary · 1 minute read

The record of processing activities documents which personal data a company processes and for what purpose.

Significance

It is the central mandatory documentation under Art. 30 GDPR and the first thing examined in any audit by the authorities. An up-to-date record answers the question of which data is held where in the company.

Mandatory content

  • name and contact details of the controller and of the data protection officer
  • purposes of the processing
  • categories of data subjects and of personal data
  • categories of recipients
  • transfers to third countries
  • envisaged time limits for erasure
  • general description of the technical and organisational measures

Processors must also keep their own record. The exemption for companies with fewer than 250 employees hardly applies in practice, because it does not cover processing that is not occasional.

Art. 30(1) GDPR
Record kept by the controller.
Art. 30(2) GDPR
Record kept by the processor.
Art. 30(4) and (5) GDPR
Making the record available to the supervisory authority and exemptions.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.