GDPR Article 30: do you need a record of processing activities (RoPA)?
GDPR Article 30 requires most controllers and processors to keep a record of processing activities (RoPA). An organisation with fewer than 250 staff is exempt only if its processing is occasional, low-risk, and free of special category data, so companies that process staff or customer data regularly must still keep records.
Applies to: Controllers and processors subject to the GDPR, including organisations under 250 staff whose processing is regular, higher-risk, or involves special category data.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
The record of processing activities, or RoPA, is the internal register GDPR Article 30 asks you to keep of what personal data you process and why. It is the document a supervisory authority tends to ask for first, because it shows at a glance whether you understand your own processing. Many small companies assume they are exempt from it. Most are not.
What Article 30 requires
Article 30 requires most controllers and processors to maintain a written record, including in electronic form, of their processing activities. For a controller, Article 30(1) lists what the record must contain: the name and contact details of the controller, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients, any transfers to third countries and the safeguards for them, and, where possible, the retention periods and a general description of the technical and organisational security measures. A processor keeps a slightly different record under Article 30(2).
Why the under-250-employee exemption rarely applies
The confusion comes from Article 30(5), which appears to exempt organisations with fewer than 250 employees. Read the whole sentence and the exemption almost disappears. It is lost if the processing is likely to result in a risk to the rights and freedoms of data subjects, if the processing is not occasional, or if it includes special category data under Article 9(1) or criminal-offence data under Article 10. Paying staff, running a customer database, or handling support tickets is ongoing, not occasional, so a small company doing normal business usually keeps records anyway. The practical effect is that the 250 figure is not the test most people think it is.
How the RoPA connects to the rest of your obligations
The RoPA is the backbone the other duties hang from. Once you have listed each activity with its purpose, you can confirm a lawful basis for each one under Article 6, decide which activities need a DPIA, and check that your Article 28 processor contracts cover the recipients you listed. Keeping it current is what makes the rest of GDPR manageable rather than a scramble. The GDPR compliance hub shows how these pieces fit together.
Next step
A RoPA is only useful if it reflects what you actually do, which is why a stale template rarely survives a regulator's questions. The free 2-minute Obligation Scan flags whether GDPR applies to your business and which processing activities belong in your Article 30 record, so you start from your real obligations rather than a blank spreadsheet.
Compliance checklist
- Decide whether you are acting as a controller, a processor, or both, since the record differs slightly (Article 30(1) and (2)).
- List each processing activity with its purpose and lawful basis.
- For each, record the categories of data subjects, personal data, and recipients, plus any third-country transfers.
- Note retention periods and a general description of your security measures where you can.
- Keep the record in writing and up to date, ready to show the supervisory authority on request.
Sources
- Regulation (EU) 2016/679, Article 30 (records of processing activities), official text on EUR-Lex
- Article 29 Working Party / EDPB position paper on the Article 30(5) derogation
Last verified: 2026-07-22
Informational, not legal advice.