Governance & Operations
What is RoPA (Records of Processing Activities)?
A RoPA (record of processing activities) is the internal inventory GDPR Article 30 requires organizations to maintain, documenting every processing activity — its purposes, data categories, recipients, transfers, retention periods, and security measures.
The RoPA is the accountability principle in table form. For controllers, each entry must record the organization's name and contacts, the purposes of the processing, categories of data subjects and personal data, categories of recipients, any transfers to third countries and their safeguards, envisaged retention periods, and a general description of security measures. Processors keep a parallel, slightly shorter record of processing performed for each controller. Regulators can demand the RoPA on request, and it is routinely the first document asked for in an investigation.
Article 30(5) exempts organizations with fewer than 250 employees — but the exemption collapses if the processing is more than occasional, creates risk to individuals, or touches special-category data. Since customer databases, marketing lists, and website analytics are all continuous rather than occasional, virtually every operating business processing personal data systematically needs the record despite the headcount carve-out.
The useful way to build a RoPA is by activity, not by system: 'order fulfillment,' 'email marketing,' 'fraud screening,' 'website analytics' — each with its data categories, legal basis (recording it here is best practice, feeding privacy-notice and DSAR answers), recipients, retention, and safeguards. Built that way, the RoPA becomes the master index of the privacy program: DSARs consult it to find data, DPIAs cite it, the privacy policy summarizes it.
Its failure mode is staleness. A RoPA drafted for launch and never updated is evidence of a paper program; tying updates to vendor onboarding and data mapping keeps it aligned with reality.
Why it matters for eCommerce
An online store's RoPA is dominated by its SaaS stack: every app with access to customer data is a recipient, and every new integration is a RoPA update. The efficient pattern is generating the record from a live data map rather than maintaining a parallel spreadsheet — when the map knows Klaviyo receives email addresses for marketing, the Article 30 entry writes itself.
Frequently asked questions
- Is a RoPA required for small businesses?
- The under-250-employee exemption in Article 30(5) rarely applies in practice, because it falls away when processing is non-occasional or risky — and customer databases and web analytics are continuous by nature. Assume you need at least a record covering your regular activities.
- What is the difference between a RoPA and a data map?
- The data map is the discovery layer — where personal data actually lives and flows. The RoPA is the formal register Article 30 prescribes, organized by processing activity. A good data map generates and refreshes the RoPA; the RoPA is what you hand the regulator.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Generate RoPA from a live data map