Skip to content
Legiscope
Menu
Data Privacy

ROPA Template: Records of Processing Activities (GDPR Article 30)

Free ROPA template for GDPR Article 30. Mandatory fields, controller vs processor versions, sample entries for HR, marketing, and customer service.

Definition. A Record of Processing Activities (ROPA) is the central inventory required by GDPR Article 30. It documents every processing activity an organization conducts: purposes, data categories, recipients, transfers, retention, security. Both controllers (Article 30(1)) and processors (Article 30(2)) must maintain a ROPA. The ROPA is the first document a supervisory authority requests in any inspection — it is the foundation of demonstrating accountability under Article 5(2).

A ROPA template accelerates GDPR compliance dramatically. Rather than building from scratch, this guide provides ready-to-use templates for both controller and processor versions, sample entries for the most common processing activities (HR, marketing, customer service, IT), and the practical workflow to maintain the ROPA over time.

Key takeaways

  • Article 30 GDPR requires every controller and processor to maintain a ROPA.
  • Companies under 250 employees are exempt only if processing is occasional, doesn’t involve special categories, and doesn’t pose a risk to data subjects (rare in practice).
  • The controller ROPA has 8 mandatory fields, the processor ROPA has 5.
  • A complete ROPA is the first document requested in any DPA inspection.
  • Most CNIL sanctions in 2024-2025 cited ROPA gaps as an aggravating factor.

1. When is a ROPA mandatory?

Article 30(1) requires a controller ROPA. Article 30(2) requires a processor ROPA. Article 30(5) provides an exemption for organizations under 250 employees — but only if all three conditions are met:

  • Processing is occasional
  • Does not include special categories of data (Article 9) or criminal data
  • Is unlikely to result in a risk to the rights and freedoms of data subjects

In practice, virtually no organization meets all three conditions. Any company with employees has HR data (regular processing). Any company with customers has CRM data. Treat the ROPA as mandatory for everyone.

2. Controller ROPA — mandatory fields (Article 30(1))

For each processing activity, document:

# Field Example
1 Name and contact details of the controller “Acme SAS, 12 rue X, 75001 Paris, dpo@acme.com
2 Joint controller(s) where applicable “[Marketing Partner] for joint advertising campaigns”
3 DPO contact (if designated) “Jean Dupont, dpo@acme.com
4 Purposes of the processing “Manage customer accounts and orders”
5 Categories of data subjects and personal data “Customers; identification, contact, order history, payment method”
6 Categories of recipients “Internal: customer support, finance. External: payment processor (Stripe), shipping provider (DHL)”
7 Transfers to third countries (with safeguards) “Stripe Inc, USA — EU-US Data Privacy Framework certification”
8 Retention periods “Customer accounts: 3 years post last interaction. Order data: 10 years (commercial law)”
9 General description of TOMs (Article 32) “TLS 1.3 in transit, AES-256 at rest, MFA on admin access, ISO 27001 certified”

3. Processor ROPA — mandatory fields (Article 30(2))

# Field Example
1 Name and contact details of processor (and each controller served) “ProcessorCo for ClientA, ClientB, ClientC”
2 DPO contact (if designated)
3 Categories of processing carried out on behalf of each controller “Hosting and processing of CRM data”
4 Transfers to third countries with safeguards
5 General description of TOMs

4. Sample controller ROPA entry — HR

Processing activity: Employee personnel files

Controller: Acme SAS (12 rue X, 75001 Paris)
Joint controllers: None
DPO: dpo@acme.com

Purposes:
- Employment contract execution
- Payroll management
- Performance evaluations
- Compliance with social security and tax obligations

Lawful basis: Article 6(1)(b) (contract execution) + Article 6(1)(c)
              (legal obligation for payroll/tax)

Data subjects: Current employees (87), former employees (152)
Data categories:
- Identity: name, address, date of birth, nationality, photo
- Contact: personal email, phone
- Employment: contract, salary, position, evaluations, training
- Banking: IBAN for payroll
- Family: dependents (for benefits/tax purposes only)

Recipients:
- Internal: HR, Finance, direct managers (for evaluations)
- External: Payroll provider (PayrollCo, FR), Social security (URSSAF),
  Tax authority (DGFiP), Pension provider (XYZ)

International transfers: None

Retention:
- Active employees: duration of employment
- Former employees: 5 years post-departure (labor law prescription)
- Pay slips: 5 years (employer copy)
- Tax documents: 6 years (tax obligations)

Security measures (TOMs):
- Access restricted to HR + direct managers via role-based access
- HR system: TLS 1.3, AES-256 at rest
- MFA mandatory for HR system access
- Annual security awareness training for HR staff
- Backup: daily, retained 90 days, encrypted

DPIA conducted: No (standard HR processing per CNIL guidance)

5. Sample controller ROPA entry — marketing

Processing activity: Email marketing to opted-in subscribers

Controller: Acme SAS
DPO: dpo@acme.com

Purposes: Send marketing emails about products, events, content

Lawful basis: Article 6(1)(a) (consent) — explicit opt-in via signup form

Data subjects: Newsletter subscribers (12,500)
Data categories: Email address, first name, opt-in date and source,
                 click/open behavior

Recipients:
- Internal: Marketing team
- External: Email service provider (Mailchimp, USA — EU-US DPF certified)

International transfers: USA via Mailchimp DPF

Retention:
- Active: as long as consent maintained
- After unsubscribe: 24 months (proof of consent for liability period)

Security:
- TLS 1.3 to ESP
- Mailchimp SOC 2 Type II + ISO 27001
- API key rotation quarterly

DPIA: No

6. Sample controller ROPA entry — analytics

Processing activity: Website analytics

Controller: Acme SAS
DPO: dpo@acme.com

Purposes: Understand site usage, improve content and user flows

Lawful basis: Article 6(1)(a) (consent via cookie banner)

Data subjects: Site visitors (~100,000/month)
Data categories: Pseudonymized event data (page views, clicks, time
                 on site), browser/device info, truncated IP

Recipients:
- Internal: Marketing team for reports
- External: Google LLC (Google Analytics 4)

International transfers: USA — Google LLC has Swiss-US DPF certification.
                         Standard Contractual Clauses signed as fallback.
                         TIA conducted: Sep 2025, low-risk given pseudonymization.

Retention: 14 months (GA4 default)

Security:
- HTTPS for all data transmission
- IP anonymization enabled in GA4
- No PII passed to GA4

DPIA: Yes (December 2024) — see DPIA-2024-003

7. Maintenance workflow

A ROPA is not a one-time document. Maintenance:

Quarterly (15-30 min)

  • Review changes in vendor list (new sub-processors)
  • Confirm retention periods still applied
  • Check transfer mechanisms still valid (DPF certifications, SCCs)

Annually (4-8 hours)

  • Full review of every entry
  • Update word counts and data subject volumes
  • Re-confirm lawful basis and DPIA status
  • Add new processing activities introduced during the year
  • Archive obsolete entries

Triggered review (when…)

  • New processing activity introduced
  • New vendor added
  • Major regulation update (e.g., new EDPB guidelines)
  • DPA inspection notification

8. Common ROPA failures (from CNIL inspections)

  1. Missing entries for marketing tools (analytics, A/B testing, heatmaps) added without privacy review
  2. Generic security descriptions (“appropriate technical measures”) without specifics
  3. Incorrect lawful basis (consent invoked when contract or legitimate interest applies)
  4. Out-of-date retention periods not aligned with actual deletion
  5. Sub-processors not listed — only top-level vendor named
  6. No documented review process — entries not updated for 18+ months
  7. No DPIA cross-reference for high-risk processing
  8. Missing international transfer details — country named but not safeguard mechanism

9. ROPA in spreadsheet vs. dedicated tool

For organizations with <30 processing activities and <10 vendors, a spreadsheet works. Beyond that:

  • Spreadsheets become unwieldy for cross-referencing (sub-processors, DPIAs, lawful bases)
  • No automation of vendor data refresh
  • No alerts on stale entries
  • No multi-language support if FR + EN ROPA needed
  • No audit trail of changes

10. The “first document the regulator asks for”

Every CNIL inspection begins with a request for the ROPA. The CNIL inspector then samples 5-10 entries and asks for supporting documentation: signed DPAs, DPIAs, consent proof, retention deletion logs.

If the ROPA is incomplete or out of date, the rest of the inspection cascades unfavorably. If the ROPA is complete and well-maintained, the inspection is largely a confirmation exercise.

Official sources: Article 30 of Regulation (EU) 2016/679 (records of processing) on EUR-Lex, the ICO documentation and records of processing guidance, and the EDPB guidelines register.

Conclusion

The ROPA is not paperwork — it is the operational nerve center of a privacy program. Every other compliance artifact (DPIA, DPA, breach response, data subject request handling) traces back to entries in the ROPA. Investing in a complete, well-maintained ROPA pays back the first time a regulator asks for it.

FAQ

Is a ROPA mandatory for small businesses?

Article 30(5) provides a narrow exemption for organizations under 250 employees, but only if processing is occasional, doesn’t include special categories, and poses no risk. In practice, virtually no business meets all three conditions. Treat the ROPA as mandatory.

What’s the difference between a controller ROPA and a processor ROPA?

Controllers maintain a ROPA listing all their processing activities (Article 30(1), 8 mandatory fields). Processors maintain a ROPA listing the categories of processing they perform on behalf of each controller (Article 30(2), 5 mandatory fields).

How often should the ROPA be updated?

Quarterly for vendor and sub-processor changes. Annually for full review. Immediately when a new processing activity is introduced or when a major regulation update affects an existing entry.

Does the ROPA need to be in a specific format?

GDPR doesn’t mandate a format. Article 30(3) requires it to be in writing, including electronic form, and made available to the supervisory authority on request. Spreadsheets work for small operations; dedicated tools become necessary beyond 30 activities or 10 vendors.

Can I delegate ROPA maintenance to my DPO?

The DPO can coordinate ROPA maintenance but the controller remains responsible (Article 24). Best practice: business unit owners populate entries for their processing, the DPO reviews for completeness and quality, and the controller approves quarterly.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

ROPA Software: Automate Article 30 Records (2026)

The ROPA is not paperwork for its own sake. It is the first document every DPA requests when an inspection or complaint lands, and an incomplete one is itself evidence of an Art. 30 breach.

July 7, 2026
02Data Privacy

GDPR Article 30 ROPA: Data Model and Fields Template

In one sentence. GDPR Article 30 ROPA requires a structured register with 8 mandatory fields for controllers (Article 30(1)) and 6 for processors (Article 30(2)), expandable to 14 fields total under…

June 3, 2026
03GDPR Compliance

GDPR Record of Processing Activities: Complete Guide

The record of processing activities (ROPA) under Art. 30 GDPR is the single most important compliance document an organization produces. It is the first document supervisory authorities request…

April 12, 2026
04Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
05Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026
06Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
07Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
08Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026