Updated: August 2026
Under GDPR, most businesses must keep clear Records of Processing Activities (ROPA). Many companies mistakenly assume this applies only to large organisations. This article explains who needs a ROPA, what to include, and why regular updates matter.
• Almost All Companies Must Maintain a ROPA: Most companies, regardless of size, need a ROPA, as exemptions rarely apply due to the regular processing of personal or special categories of data.
• ROPA Ensures GDPR Compliance and Transparency: A detailed ROPA helps organisations demonstrate compliance, facilitates transparency, and provides essential support during audits and data protection impact assessments (DPIAs).
• Regular Updates are Crucial: A ROPA must be continuously updated to reflect changes in data processing activities, ensuring accuracy, effective risk management, and prompt responses to the data subject and supervisory authority inquiries.
The obligation to create and maintain Records of Processing Activities [ROPA] applies to most controllers and processors, and – for non-EU companies – their EU Representatives. Article 30 of the GDPR regulates the legal provisions on the register of processing activities.
A widespread misconception about ROPAs is that this duty applies only to large companies. While according to Article 30 of the GDPR, companies with more than 250 employees must indeed always keep a ROPA, those with fewer than 250 employees are exempt from holding a record if one of these factors applies:
• The processing is not likely to pose a risk to the rights and freedoms of the data subject.
Companies can assess likely risk for data subjects by considering the nature, scope, context, and purposes of processing, as well as the likelihood and severity of risks. Examples include geolocation systems and video surveillance.
• If no special categories of data are processed.
Special categories of data include, for instance, data concerning criminal records, religious affiliations, and health data of employees. Most companies process sick certificates and other employee information that falls under this category.
• If the processing is done only occasionally.
Data processing can be occasional if it plays a subordinate role in the activity and occurs only briefly or once. For example, a company might inform clients of a change of address when relocating. By contrast, daily company activities, such as customer management or salary management, are not occasional.
In practice, this exemption is rarely applicable; most companies, regardless of whether they employ more than 250 people, must keep a ROPA. As in almost every organisation, some processing takes place on a structural basis. Also, companies may process special categories of data, especially in the context of human resources.
For accountability and transparency, controllers must maintain structured data protection documentation. It not only ensures transparency of data processing but also enables the data protection officer (DPO), EU representative and supervisory authorities to perform their duties well. In a nutshell, a ROPA shows whether a company is GDPR compliant, pursuant to Art. 5(2) GDPR. Furthermore, a ROPA is crucial for preparing data protection impact assessments (DPIAs). By maintaining a processing directory, your company not only achieves transparency regarding the processing of personal data but is also legally protected in the event of an audit by the data protection supervisory authorities.
While building a complete list of processing activities is often complicated and time-consuming, creating and maintaining a ROPA can be beneficial for several reasons. It enables prompt, accurate responses to data subject requests by keeping information readily available, while also establishing an efficient data-erasure schedule to avoid unnecessary bulk storage of personal data. It allows a company to identify future possible risks and take steps to mitigate them.
By definition, a ROPA records an organisation’s processing activities involving personal data. Pursuant to Art. 30 (3) GDPR, it must be in written or electronic text form.
“Processing” is any activity performed on personal data (collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction). Thus, not only the active collection of data but also the mere storage of data on a server is considered processing. In practice, each business process will be a separate processing activity.
1. Each controller and, where applicable, the controller’s representative shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information: (a) the name and contact details of the controller and, where applicable, the joint controller, the controller’s representative and the data protection officer;
(b) the purposes of the processing;
(c) a description of the categories of data subjects and of the categories of personal data;
(d) the categories of recipients to whom the personal data have been or will be disclosed, including recipients in third countries or international organisations;
(e) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;
(f) where possible, the envisaged time limits for erasure of the different categories of data;
(g) where possible, a general description of the technical and organisational security measures referred to in Article 32(1).
2. Each processor and, where applicable, the processor’s representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing:
(a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller’s or the processor’s representative, and the data protection officer;
(b) the categories of processing carried out on behalf of each controller;
(c) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;
(d) where possible, a general description of the technical and organisational security measures referred to in Article 32(1).
As controllers or processors, companies must create and maintain a ROPA and keep an overview of all processing activities they operate.
If you are not an EU company and need to appoint an EU representative, the EU Representative will help you with regard to their obligations under the GDPR. The EU representative acts as a middleman between supervisory authorities and data subjects. At the same time, the company outside the EU plays an active role in creating and maintaining records of processing activities and making these records available to the supervisory authorities upon request.
First, determine and gather all details by conducting an audit to clarify what personal data is processed. To do so, meet directly with key departments (such as HR, Marketing, Customer Support, etc.) to better understand how they use data and document the required details. Other departments hold necessary, specific information about processing activities; for example, IT holds information about technical security measures. In contrast, the legal department tracks data-sharing arrangements.
Second, you can find other relevant information in your existing GDPR documentation.
You should be able to answer these questions about each personal data processing activity:
1. How do you process personal data?
2. Why do you use personal data?
3. Who do you hold information about?
4. What information do you hold about them?
5. Who do you share it with? Do you use any external contractors? Are any of them outside the EU?
6. For how long do you store it?
7. How do you keep it safe?
You must document your processing activities in writing, in paper or electronic form. Due to the obligation to maintain a ROPA, meaning to add, remove and amend it as necessary, an electronic form is suggested. Moreover, document in a granular and logical way, as you may have separate retention periods for different categories of data.
Update the record regularly, according to the functional and practical evolution of data processing. In practice, add any changes to the processing conditions for each processing activity to the record (new data collected, retention period, new processing recipient, etc.).
Businesses often underestimate the importance of maintaining accurate ROPA records. One frequent mistake is assuming the obligation applies exclusively to large enterprises, causing smaller firms to overlook their responsibilities. Companies also often document activities too vaguely or incompletely, omitting details on data categories, recipients, or storage durations.
Another oversight is neglecting regular updates, which can lead to outdated or incorrect records. To reduce compliance risk, ensure your ROPA clearly reflects all data processing and stays up to date as business activities change.
In conclusion, the ROPA is a practical control tool for GDPR compliance. An accurate, up-to-date ROPA is not just a legal requirement; it’s a best practice for any business that handles personal data. Clear data records help businesses stay transparent, protect customer information, and handle audits or data requests more easily.
With regular ROPA reviews and updates, companies reduce compliance risks and commit to responsible data management.
A Record of Processing Activities is a written or electronic record of an organisation’s data processing activities, required under Article 30 of GDPR. It documents what personal data a company processes, why, who it shares it with, and how long it keeps it.
Companies with more than 250 employees always need one. Smaller companies are exempt only if their processing poses no likely risk to data subjects’ rights and freedoms, involves no special category data (such as health or criminal record data), and is purely occasional rather than part of regular business activity. In practice, this exemption rarely applies, since most companies process some data on a structural basis or handle special category data through HR alone.
For controllers, that’s the controller’s contact details, the purposes of processing, categories of data subjects and personal data, recipients of the data, any international transfers and their safeguards, envisaged erasure timeframes, and a description of technical and organisational security measures. Processors keep a similar record covering the categories of processing carried out on behalf of each controller.
Assuming the requirement only applies to large companies, which leads smaller businesses to skip it entirely. Other frequent issues are documenting activities too vaguely, leaving out details like data categories or storage periods, and failing to update the record as processing activities change.