Skip to content

RoPA - Records of Processing Activities

The RoPA (Records of Processing Activities, Article 30 of the GDPR) lists what the organisation does with personal data.

Each activity

  • Name of the activity (e.g. Customer management, Newsletter).
  • Purpose and Legal basis.
  • Categories of data subjects and of data.
  • Recipients and any transfers.
  • Retention period.

Step by step

  1. GDPR → RoPA tab.
  2. + Activity → fill in the fields.
  3. Save - it enters the compliance report.

Why it is mandatory

The RoPA is the map of data processing. It is the first document a supervisory authority asks for in an audit.

➡️ Next: Data breaches · back to GDPR.