How to Create a RoPA (Record of Processing Activities): A Practical Guide
16th March 2026
For many business owners, the acronym ‘RoPA’ sounds like just another piece of dry, regulatory paperwork. However, the Record of Processing Activities is actually one of the most powerful tools in your data protection toolkit, with a well-maintained RoPA being the foundation of your entire compliance framework.
Under Article 30 of the UK and EU GDPR, most organisations are legally required to maintain a record of their processing activities. But how do you actually build one from scratch? In this blog, we will break down what needs to be included and provide a methodical approach to getting it right.
What is a RoPA?
Put simply, a RoPA is a register of what data you hold and where, but it is so much more. A RoPA is a living document that logs how your organisation handles personal data. It tracks the ‘who, what, where, when, and why’ of your data processing. If the Information Commissioner’s Office (ICO) were to knock on your door for an audit, this is likely the first document they would ask to see to verify that you understand your data flows.
As we have discussed in our guide to ICO audits, being able to demonstrate accountability is an essential element of compliance.
Does Every Business Need One?
While there is a small exemption for organisations with fewer than 250 employees, this only applies if the processing you do is low-risk and infrequent. In reality, almost all businesses process data that carries some risk, such as employee records, criminal conviction data, or health information. This means a RoPA is a legal requirement for the vast majority of UK companies (Source: ICO).
Download a RoPA Template
The ICO has many templates, and there are two RoPA templates, one for Controllers and one for Processors.
Once downloaded you can start to complete the RoPA. We find that the templates do not suit all organisations and so feel free to add or remove columns to meet your specific circumstances.
Steps to Creating Your RoPA
1. Data Discovery (The ‘Data Audit’)
You cannot record what you do not know exists. Start by talking to different departments, such as HR, Marketing, Sales, and IT. Ask them:
- What personal data do you collect? (e.g. names, IP addresses, health data)
- Where is it stored? (e.g. Excel sheets, cloud software, physical filing cabinets)
- Who do you share it with? (e.g. payroll providers, email marketing platforms)
Often there are a lot of hidden datasets within an organisation, especially when departments are using free of charge cloud services. At the end of this document is a full set of questions which you may wish to add to a survey or spreadsheet and circulate to each of your departments.
2. Define the Purpose and Lawful Basis
For every processing activity, such as ‘Processing Monthly Payroll’, you must identify the reason for the processing why you are doing it and which lawful basis you are relying on. Common examples include Consent, Contract, Legal Obligation, or Legitimate Interests. This is similar to the transparency required in your privacy notice, where you must tell individuals exactly why you need their data.. If processing sensitive or criminal record data you must identify which authority allows you to process the information, i.e. GDPR Article, Data Protection Act Section or other relevant legislation.
Often you will have multiple processing activities taking place on the same set of data, for example, you may have one HR CRM system, but use it for general employment matters, EDI monitoring, sickness, disciplinary and safeguarding. You would therefore have each of these processing activities on a different row on the RoPA.
3. Set Retention Periods
A key part of data minimisation is knowing when to let go. Your RoPA should state how long you keep each category of data. For example, you might keep unsuccessful job applications for 6 months from receipt but employment financial records for 6 years after an employee resigns..
4. Identify Processors
Within the RoPA you must identify where data is shared with third parties. If using a Processor they must be listed along with their geographical location, whether due-diligence has been performed and if a data processing agreement is in place. If you share with other Controllers they must be listed and if a data sharing agreement is in place provide a link to this.
5. Describe Security Measures
You do not need to list every technical and organisational security measure that will protect the data firewall, but you should list any specific measures over and above your basic security standards, for example, encryption. provide a high-level overview of how the data is protected.
RoPA – The single source of truth
Once completed your RoPA will provide all the information you need to complete your public privacy notice, and influence other policies such as your deletion and retention schedule.
Common RoPA Mistakes to Avoid
- ‘Once and Done’ Mentality: A RoPA is not a static document. It should be reviewed at least annually or whenever you introduce a new system or process.
- Too Much Jargon: Write your RoPA so that a person with no legal background can understand what is happening to the data.
- Ignoring Third Parties: Ensure you record where data leaves your organisation, especially if it is being transferred outside of the UK (Source: Article 30(1)(e) UK GDPR).
Additional benefits
Your RoPA is not just a fancy asset register, it has tangible business benefits:
- Efficiency: Knowing what data you have and why you have it streamlines processes and cuts waste.
- Trust: Clients and partners are more likely to do business with organisations that treat their data with respect.
- Competitive Advantage: In a market where reputation is everything, strong data governance can be a key differentiator.
How Griffin House Consultancy Can Help
Building a RoPA can feel like a daunting task, especially if you have years of legacy data to sift through. At Griffin House Consultancy, we specialise in helping organisations map their data and build robust, easy-to-manage Records of Processing Activities.
Whether you need a template to get started or a full internal audit to ensure your current RoPA is audit-ready, we are here to help. Get in touch with us here or call us on 01673 885533 for a chat about your data governance needs.
For a full set of questions to include in your RoPA survey, click here to view and download.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Sources