Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Record of Processing Activities (RoPA) (Art. 30)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 42/54 Part 5 — Operational Obligations & Sanctions Intermediate Reviewed 2026-08-23

Record of Processing Activities (RoPA) (Art. 30)

Article 30 obliges controllers and processors to maintain a written Record of Processing Activities (RoPA). Acting as the master map of organizational data compliance, the register must be kept up to

Open in interactive reader
⚖️ Statutory Cartography 📋 Art. 30 Mandatory Contents

Record of Processing Activities (RoPA) (Art. 30)

⚡ In 30 seconds

Article 30 establishes the primary operational instrument of accountability: the Record of Processing Activities (RoPA). Each controller and processor must maintain a detailed written inventory mapping what data is held, why it is processed, who receives it, where it is transferred, and how it is secured.

Mandatory RoPA Entry (Art. 30.1) Required Specification
1. Governance Details Name and contact details of controller, joint controllers, representative, and DPO.
2. Purposes of Processing Explicit, granular business purposes for each processing pipeline.
3. Categories of Individuals & Data Data subjects (employees, clients) and data fields (financial, contact, health).
4. Recipients Categories of recipients to whom data have been or will be disclosed (processors, partners).
5. International Transfers Identification of third countries or international organizations and transfer safeguards (SCCs).
6. Retention Schedules Envisaged time limits for erasure of the different categories of data.
7. Security Measures General description of Article 32 technical and organisational security measures.
⚡ Key Takeaways
  • Processors maintain their own distinct register (Art. 30.2) tracking processing on behalf of each client.
  • The register must be in written format, including electronic spreadsheet or database software.
  • DPAs systematically request the RoPA as document #1 during any audit or investigation.
⚠️ Common Pitfall

Treating the RoPA as a one-time static document created during initial GDPR rollout and never updating it.

🛠️ In Practice

Schedule a quarterly review between department heads and the DPO to capture newly adopted SaaS applications.

⚖️ Official Sources: Art. 30 GDPR · Recital 82 · EDPB Position on Article 30(5) Derogation ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Mandatory compliance cartography for controllers (Art. 30.1) and processors (Art. 30.2).
  • The SME exemption (< 250 employees) almost never applies in practice if processing is regular or involves sensitive data.
  • Living governance asset: must be continuously updated and produced immediately upon DPA inspection.

⚠ Common pitfall: Assuming that having fewer than 250 employees creates a blanket exemption from maintaining a RoPA.

→ Actionable practice: Centralize processing operations in an auditable digital register recording purposes, data types, recipients, and security measures.

← Data Protection by Design & by Default (Art. 25) Data Protection Impact Assessment (DPIA) (Art. 35) →