What it must contain (Art. 30(1))
- Purposes of processing
- Categories of data subjects and data
- Categories of recipients
- Non-EU transfers and safeguards
- Erasure time limits
- Security measures (general description)
Processors keep a mirror record for the activities carried out on behalf of each controller (Art. 30(2)).
Excel vs dedicated software
The register, for every client, with the right deadlines
In DPO Workspace every client has its own Art. 30 register linked to documents, DPIAs and breaches — and every review interval is anchored to a legal reference, not an arbitrary number. Free 30-day trial, no card.
Try it freeFrequently asked questions
Is the ROPA mandatory for small businesses too?
Article 30(5) exempts in theory organisations under 250 employees, but the exceptions (non-occasional processing, special categories, risky processing) cover practically everyone: employees, customers and suppliers are non-occasional processing. In practice, the register is due for almost every business and recommended for all.
What must the controller's record contain?
For each processing activity (Art. 30(1)): purposes; categories of data subjects and data; categories of recipients; any non-EU transfers with safeguards; erasure time limits; a general description of security measures. Plus contact details of the controller, joint controllers, representative and DPO.
Is Excel enough for the ROPA?
Formally yes: the GDPR requires written form, including electronic. In practice Excel holds up while processing activities are few and there is one controller: with several clients, periodic reviews, versions to show in an inspection and links to DPIAs and breaches, the spreadsheet is where compliance gets lost. Dedicated software adds deadlines, history and consistency across documents.
Controller vs processor record: what is the difference?
The controller documents ITS OWN processing (Art. 30(1)); the processor documents the categories of processing carried out ON BEHALF of each controller (Art. 30(2)). One company may need both: controller for its own staff and customers, processor for services delivered to others.
A living register, not a forgotten sheet
Art. 30 registers, DPIAs, breaches, documents and deadlines for every client in one platform.
Start free