GDPR Record of Processing Activities (ROPA) template
Article 30 requires a record of processing activities. Most SMEs either skip it or produce something so abstract it is useless. This template keeps one row per real processing activity, with the columns the ICO and your ISO 27001 auditor both expect.
Every field, explained
| Field | What to put in it |
|---|---|
| Processing activity | A real business activity, e.g. 'Payroll processing', not 'HR'. |
| Purpose | Why you process it, in one sentence a data subject would understand. |
| Lawful basis | One of the six Article 6 bases. If it is legitimate interests, reference the LIA. |
| Data subject categories | Employees, customers, candidates, suppliers, website visitors. |
| Personal data categories | The actual fields — name, address, bank details, IP address. |
| Special category data | Article 9 data (health, biometrics, etc.) and the Article 9 condition relied on. |
| Recipients / processors | Named third parties. Cross-check this list against your supplier register. |
| International transfers | Country plus the transfer mechanism (adequacy, IDTA, SCCs). |
| Retention period | A period with a trigger, e.g. '6 years after end of employment'. 'As long as necessary' is not a retention period. |
| Security measures | Summary of the controls protecting it; link to the SoA rather than repeat it. |
| Owner | The business owner of the activity, not the DPO. |
Worked examples
- Processing activity
- Payroll processing
- Purpose
- Pay employees and meet HMRC reporting obligations.
- Lawful basis
- Art 6(1)(b) contract; Art 6(1)(c) legal obligation
- Data subject categories
- Employees, directors
- Personal data categories
- Name, address, NI number, bank details, salary
- Special category data
- None
- Recipients / processors
- Payroll bureau (UK), HMRC, pension provider
- International transfers
- None
- Retention period
- 6 years after end of tax year in which employment ended
- Security measures
- SSO + MFA, role-based access, encrypted at rest, DPA in place
- Owner
- Head of Finance
- Processing activity
- Website analytics
- Purpose
- Understand site usage and improve content.
- Lawful basis
- Art 6(1)(a) consent (PECR consent for cookies)
- Data subject categories
- Website visitors
- Personal data categories
- IP address, device and page interaction data
- Special category data
- None
- Recipients / processors
- Analytics provider
- International transfers
- US — provider's UK IDTA in place
- Retention period
- 14 months from collection
- Security measures
- IP anonymisation, consent banner, access limited to marketing
- Owner
- Marketing Manager
- Processing activity
- Recruitment
- Purpose
- Assess candidates and manage the hiring process.
- Lawful basis
- Art 6(1)(b) pre-contract; Art 6(1)(f) legitimate interests (talent pool)
- Data subject categories
- Candidates
- Personal data categories
- CV, contact details, interview notes, right-to-work evidence
- Special category data
- Diversity monitoring data — Art 9(2)(b) with explicit consent
- Recipients / processors
- Applicant tracking system, recruitment agencies
- International transfers
- EU — adequacy
- Retention period
- 12 months after decision (unsuccessful), unless consent to talent pool
- Security measures
- ATS access restricted to hiring panel; diversity data separated
- Owner
- HR Manager
How to use it
- Start from the activities the business actually performs — walk each department for 30 minutes.
- One row per activity, not per system; systems appear in the recipients and security columns.
- Fix retention periods now; they are the hardest column to retrofit and the one most often blank.
- Cross-check processors against your supplier register so nothing is processing data without a DPA.
- Review annually and whenever a new system or supplier is introduced.
- Link the ROPA to your asset inventory so ISO 27001 A.5.9 and A.5.34 are evidenced by the same record.
What auditors pick up
- Retention shown as 'as long as necessary' with no trigger or period.
- Processors listed in the ROPA that have no data processing agreement.
- Legitimate interests claimed with no legitimate interests assessment attached.
- International transfers unrecorded because the SaaS provider 'is a UK company' but hosts elsewhere.
FAQ
Do small businesses need a ROPA?
Article 30(5) exempts organisations with fewer than 250 staff unless the processing is likely to result in a risk to individuals, is not occasional, or includes special category or criminal offence data. Employing people and running marketing usually means the exemption does not apply in practice.
Is a ROPA the same as a data map?
They overlap. The ROPA is the Article 30 record of activities; a data map traces data through systems. Keeping the ROPA as the authoritative record and referencing systems inside it avoids maintaining two documents.
How does the ROPA help with ISO 27001?
It directly supports A.5.34 privacy and protection of PII, A.5.9 inventory of information, A.5.31 legal and contractual requirements and A.5.33 protection of records.
Related
Stop maintaining spreadsheets
Every template here exists as a live module inside ISO-STANDARD.app — owners, review dates, evidence links and audit trail included, with AI-generated remediation plans when something fails.
- Pre-loaded ISO 27001, 9001, 42001 and SOC 2 content
- Evidence vault with versioning
- Named owners and review reminders
- Export back to CSV any time
