Privacy
Glossary

Records of processing activities

Records of processing activities document which personal data a business processes, for which purposes, with which recipients and under which safeguards.

In brief

Records of processing activities, often called RoPA, are the structured documentation of an organisation’s processing operations. Under Article 30 GDPR, controllers keep records of processing activities under their responsibility. Processors record the categories of processing carried out on behalf of each controller. The record therefore shows which personal data are processed, for what purpose, with which recipients and for how long.

Article 30 GDPR lists, among other things, the controller’s or processor’s contact details, the purposes of processing, the categories of data subjects and personal data, recipients, transfers to third countries, envisaged erasure periods where possible and a general description of technical and organisational security measures where possible. The record may be kept electronically and must be made available to the supervisory authority on request. It is not a privacy notice and does not replace an assessment of a specific processing operation.

The exemption for businesses with fewer than 250 employees applies only within narrow limits. It does not apply in particular where processing is likely to result in a risk to people’s rights and freedoms, is not occasional, or involves special categories of personal data or data covered by Article 10 GDPR. New processes, service providers, recipients and retention periods should be added promptly. The privacy compliance and governance topic helps assign responsibilities. For external providers, see the guidance on processors and service providers and the processor assessment checklist.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich