Guide

Records of Processing Activities (ROPA): What Article 30 Requires

Article 30 requires many organizations to maintain a written record of their data processing activities. Here's what has to be in it, who's exempt, and how to build one without overcomplicating it.

Published June 22, 2026·Last updated August 18, 2026

A Record of Processing Activities, usually shortened to ROPA, is one of the more concrete, document-it-and-you’re-done GDPR requirements. It’s also one people either skip entirely (not realizing it applies to them) or overbuild into an unnecessarily complicated spreadsheet. Here’s what Article 30 actually asks for.

What a ROPA is

It’s a written record, Article 30 doesn’t mandate a specific format, so a well-organized spreadsheet is genuinely fine, documenting each category of processing activity your organization carries out. Think of it as the formalized output of the data inventory step that shows up across nearly every GDPR checklist, including our own compliance checklist.

What has to be in it, for controllers

For each processing activity, Article 30 requires recording:

  • Your organization’s name and contact details (and your DPO’s, if you have one, see our piece on whether you need a DPO)
  • The purposes of the processing
  • Categories of individuals and categories of personal data involved
  • Categories of recipients the data is or will be disclosed to
  • Details of any transfers to third countries, including the safeguards used (see our piece on international transfers after Schrems II)
  • Retention timeframes, where possible
  • A general description of the technical and organizational security measures in place

Processors (vendors processing data on someone else’s behalf) have a parallel but slightly different set of recordkeeping obligations under Article 30(2).

Who’s actually required to keep one

Article 30 includes an exemption for organizations with fewer than 250 employees, but the exemption is narrower than it sounds. It doesn’t apply if your processing:

  • Is likely to result in a risk to individuals’ rights and freedoms (not just occasional, low-risk processing)
  • Is not occasional
  • Includes special category data or data relating to criminal convictions

In practice, this means most businesses that run regular marketing, analytics, or customer data processing, which describes the overwhelming majority of websites, end up needing a ROPA anyway, even under 250 employees, because that kind of processing isn’t “occasional.”

Our recommendation

CookieYes

The tracking and cookie side of your ROPA, what's collected, what it's used for, where it goes, starts with an accurate inventory. CookieYes's scan gives you that starting point instead of reconstructing it from memory.

Try CookieYes

How to build one without overcomplicating it

  1. List your processing activities by purpose, not by individual tool, “customer order fulfillment,” “email marketing,” “website analytics,” “employee HR records”, each as its own row or section.
  2. For each one, fill in the Article 30 fields listed above. Most of this information already exists somewhere (your privacy policy, your vendor contracts, your data processing agreements) , a ROPA is largely about consolidating it into one place, not generating new information.
  3. Keep it current. A ROPA that reflects your setup from two years ago isn’t meeting the accountability principle in any meaningful sense, treat updates to it the same way you’d treat updates to your privacy policy, triggered by any new tool or vendor.
  4. Don’t wait for a regulator to ask for it. Supervisory authorities can request your ROPA at any time, and “we’ll build one if asked” defeats the purpose, the requirement is to maintain it proactively.

The bottom line

A ROPA is one of the least legally ambiguous GDPR requirements, there’s a defined list of fields, and the main work is just filling them in accurately and keeping them updated. If you’ve already done a data inventory as part of general GDPR housekeeping, you’re most of the way to a ROPA already.

This guide is educational and not legal advice. Whether the small-organization exemption applies to your specific processing is fact-specific. Consult a privacy attorney to confirm your obligations.