Practical guide · Art. 30 GDPR

Records of processing activities (ROPA): what they are, who must keep them and how to manage them sanely

The record of processing activities is the map of everything an organisation does with personal data — and the first document a supervisory authority asks for in an inspection. Article 30 GDPR sets its content and form; daily practice, especially for those managing multiple clients, decides whether it is a living tool or a forgotten spreadsheet.

What it must contain (Art. 30(1))

  • Purposes of processing
  • Categories of data subjects and data
  • Categories of recipients
  • Non-EU transfers and safeguards
  • Erasure time limits
  • Security measures (general description)

Processors keep a mirror record for the activities carried out on behalf of each controller (Art. 30(2)).

Excel vs dedicated software

ExcelDPO Workspace
Review deadlines with reminders
One register per client, in one place
Linked to DPIAs, breaches and documents
Version history to show in an inspection
Export for the controller or the authority

The register, for every client, with the right deadlines

In DPO Workspace every client has its own Art. 30 register linked to documents, DPIAs and breaches — and every review interval is anchored to a legal reference, not an arbitrary number. Free 30-day trial, no card.

Try it free

Frequently asked questions

Is the ROPA mandatory for small businesses too?

Article 30(5) exempts in theory organisations under 250 employees, but the exceptions (non-occasional processing, special categories, risky processing) cover practically everyone: employees, customers and suppliers are non-occasional processing. In practice, the register is due for almost every business and recommended for all.

What must the controller's record contain?

For each processing activity (Art. 30(1)): purposes; categories of data subjects and data; categories of recipients; any non-EU transfers with safeguards; erasure time limits; a general description of security measures. Plus contact details of the controller, joint controllers, representative and DPO.

Is Excel enough for the ROPA?

Formally yes: the GDPR requires written form, including electronic. In practice Excel holds up while processing activities are few and there is one controller: with several clients, periodic reviews, versions to show in an inspection and links to DPIAs and breaches, the spreadsheet is where compliance gets lost. Dedicated software adds deadlines, history and consistency across documents.

Controller vs processor record: what is the difference?

The controller documents ITS OWN processing (Art. 30(1)); the processor documents the categories of processing carried out ON BEHALF of each controller (Art. 30(2)). One company may need both: controller for its own staff and customers, processor for services delivered to others.

A living register, not a forgotten sheet

Art. 30 registers, DPIAs, breaches, documents and deadlines for every client in one platform.

Start free