GDPR Record of Processing Activities (ROPA) template

Article 30 requires a record of processing activities. Most SMEs either skip it or produce something so abstract it is useless. This template keeps one row per real processing activity, with the columns the ICO and your ISO 27001 auditor both expect.

Every field, explained

FieldWhat to put in it
Processing activityA real business activity, e.g. 'Payroll processing', not 'HR'.
PurposeWhy you process it, in one sentence a data subject would understand.
Lawful basisOne of the six Article 6 bases. If it is legitimate interests, reference the LIA.
Data subject categoriesEmployees, customers, candidates, suppliers, website visitors.
Personal data categoriesThe actual fields — name, address, bank details, IP address.
Special category dataArticle 9 data (health, biometrics, etc.) and the Article 9 condition relied on.
Recipients / processorsNamed third parties. Cross-check this list against your supplier register.
International transfersCountry plus the transfer mechanism (adequacy, IDTA, SCCs).
Retention periodA period with a trigger, e.g. '6 years after end of employment'. 'As long as necessary' is not a retention period.
Security measuresSummary of the controls protecting it; link to the SoA rather than repeat it.
OwnerThe business owner of the activity, not the DPO.

Worked examples

Processing activity
Payroll processing
Purpose
Pay employees and meet HMRC reporting obligations.
Lawful basis
Art 6(1)(b) contract; Art 6(1)(c) legal obligation
Data subject categories
Employees, directors
Personal data categories
Name, address, NI number, bank details, salary
Special category data
None
Recipients / processors
Payroll bureau (UK), HMRC, pension provider
International transfers
None
Retention period
6 years after end of tax year in which employment ended
Security measures
SSO + MFA, role-based access, encrypted at rest, DPA in place
Owner
Head of Finance
Processing activity
Website analytics
Purpose
Understand site usage and improve content.
Lawful basis
Art 6(1)(a) consent (PECR consent for cookies)
Data subject categories
Website visitors
Personal data categories
IP address, device and page interaction data
Special category data
None
Recipients / processors
Analytics provider
International transfers
US — provider's UK IDTA in place
Retention period
14 months from collection
Security measures
IP anonymisation, consent banner, access limited to marketing
Owner
Marketing Manager
Processing activity
Recruitment
Purpose
Assess candidates and manage the hiring process.
Lawful basis
Art 6(1)(b) pre-contract; Art 6(1)(f) legitimate interests (talent pool)
Data subject categories
Candidates
Personal data categories
CV, contact details, interview notes, right-to-work evidence
Special category data
Diversity monitoring data — Art 9(2)(b) with explicit consent
Recipients / processors
Applicant tracking system, recruitment agencies
International transfers
EU — adequacy
Retention period
12 months after decision (unsuccessful), unless consent to talent pool
Security measures
ATS access restricted to hiring panel; diversity data separated
Owner
HR Manager

How to use it

  1. Start from the activities the business actually performs — walk each department for 30 minutes.
  2. One row per activity, not per system; systems appear in the recipients and security columns.
  3. Fix retention periods now; they are the hardest column to retrofit and the one most often blank.
  4. Cross-check processors against your supplier register so nothing is processing data without a DPA.
  5. Review annually and whenever a new system or supplier is introduced.
  6. Link the ROPA to your asset inventory so ISO 27001 A.5.9 and A.5.34 are evidenced by the same record.

What auditors pick up

  • Retention shown as 'as long as necessary' with no trigger or period.
  • Processors listed in the ROPA that have no data processing agreement.
  • Legitimate interests claimed with no legitimate interests assessment attached.
  • International transfers unrecorded because the SaaS provider 'is a UK company' but hosts elsewhere.

FAQ

Do small businesses need a ROPA?

Article 30(5) exempts organisations with fewer than 250 staff unless the processing is likely to result in a risk to individuals, is not occasional, or includes special category or criminal offence data. Employing people and running marketing usually means the exemption does not apply in practice.

Is a ROPA the same as a data map?

They overlap. The ROPA is the Article 30 record of activities; a data map traces data through systems. Keeping the ROPA as the authoritative record and referencing systems inside it avoids maintaining two documents.

How does the ROPA help with ISO 27001?

It directly supports A.5.34 privacy and protection of PII, A.5.9 inventory of information, A.5.31 legal and contractual requirements and A.5.33 protection of records.

Related

Stop maintaining spreadsheets

Every template here exists as a live module inside ISO-STANDARD.app — owners, review dates, evidence links and audit trail included, with AI-generated remediation plans when something fails.

  • Pre-loaded ISO 27001, 9001, 42001 and SOC 2 content
  • Evidence vault with versioning
  • Named owners and review reminders
  • Export back to CSV any time
Start your workspace