Record of Processing Activities (ROPA)
GDPR Art.30 record – the mandatory inventory of every processing
activity. Art.30(1) prescribes exactly which fields a controller's
record must contain; regulators ask for this document on request.
| Field | Value |
|---|
| Doc ID | DOC-GDPR-NNN |
| Controller | [legal entity] |
| DPO / contact | @name |
| Last reviewed | YYYY-MM-DD |
| Review cycle | [quarterly / on change] |
| Classification | Internal – contains processing map |
Controller details
| Field | Value |
|---|
| Name | [legal entity + address] |
| Representative (if non-EU) | [Art.27 rep] |
| DPO | [name / contact, if appointed] |
Processing activities
One row per activity – Art.30(1) requires all columns present:
| # | Activity | Purpose | Data subjects | Data categories | Recipients | Third-country transfer | Retention | TOMs ref |
|---|
| PA-01 | e.g. account management | service delivery | customers | name, email, prefs | internal, [processor] | [SCCs / none] | [period] | TOM-NN |
| PA-02 | | | | | | | | |
Lawful basis per activity
| # | Lawful basis (Art.6) | Special category basis (Art.9) | Notes |
|---|
| PA-01 | contract / consent / legitimate interest | | |
| | | |
Special category processing
| Activity | Special data | Art.9 condition | DPIA ref |
|---|
| | | |
Data sharing & transfers
| Recipient | Role (proc/joint/ind.) | Mechanism | Location |
|---|
| [processor] | processor | DPA + SCC | [country] |
Processors' records (Art.30(2))
Processors keep their own record of processing on your behalf –
verify they maintain one; list the responsible contracts here.
| Processor | Service | DPA signed | Their ROPA verified |
|---|
| | YYYY-MM-DD | [ ] |
Maintenance