Fiche 42/54
Part 5 — Operational Obligations & Sanctions
Intermediate
Reviewed 2026-08-23
Record of Processing Activities (RoPA) (Art. 30)
Record of Processing Activities (RoPA) (Art. 30)
⚡ In 30 seconds
Article 30 establishes the primary operational instrument of accountability: the Record of Processing Activities (RoPA). Each controller and processor must maintain a detailed written inventory mapping what data is held, why it is processed, who receives it, where it is transferred, and how it is secured.
| Mandatory RoPA Entry (Art. 30.1) | Required Specification |
|---|---|
| 1. Governance Details | Name and contact details of controller, joint controllers, representative, and DPO. |
| 2. Purposes of Processing | Explicit, granular business purposes for each processing pipeline. |
| 3. Categories of Individuals & Data | Data subjects (employees, clients) and data fields (financial, contact, health). |
| 4. Recipients | Categories of recipients to whom data have been or will be disclosed (processors, partners). |
| 5. International Transfers | Identification of third countries or international organizations and transfer safeguards (SCCs). |
| 6. Retention Schedules | Envisaged time limits for erasure of the different categories of data. |
| 7. Security Measures | General description of Article 32 technical and organisational security measures. |