Skip to content

Records of Processing Activities (ROPA): Who Needs One and What to Include

Provimedia Redaktion 7 min read 11 July 2026 2 views
Datenschutz & DSGVO
Records of Processing Activities (ROPA): Who Needs One and What to Include
Illustrative image · AI-generated

A record of processing activities (Verzeichnis von Verarbeitungstätigkeiten, ROPA) is a written or electronic documentation of all personal data processing carried out by a company, required under Article 30 GDPR. After reading this article, you will know why the 250-employee exception almost never exempts your company, and you will set up your ROPA in six steps.

From the Provimedia editorial team · Status: July 2026 · This article is general information, not legal advice.

What is a record of processing activities?

The record of processing activities is the central documentation requirement of the GDPR: it systematically captures which personal data a company processes, for what purpose, on what legal basis, and for how long. The legal basis is Article 30 GDPR, which distinguishes between the obligation for controllers (paragraph 1) and for processors (paragraph 2): the latter keep their own, somewhat leaner record of the activities they carry out on behalf of a controller.

The regulation does not prescribe a specific format: written or electronic documentation is equally permissible. In practice, a tabular structure per processing activity has become the norm, for example with separate rows or individual sheets for "customer data management", "applicant management", or "newsletter distribution". For you, this means: one spreadsheet tab per activity, nothing more is required.

Who must keep a record of processing activities?

In principle, every controller and every processor is obliged to keep a record, regardless of company size or legal form. This applies to corporations just as much as to freelancers, associations, or sole proprietors, as soon as personal data is processed, for example data from customers, employees, or website visitors.

The German Data Protection Conference (Datenschutzkonferenz, DSK) clarifies in its short paper No. 1 (dated December 17, 2018) that the obligation in principle covers all processing, including partly automated processing as well as non-automated processing stored in a filing system. Article 30(5) GDPR provides an exception only for organizations with fewer than 250 employees, and in practice this exception applies less often than many assume.

Does the SME exception really apply to small businesses?

No, the exception under Article 30(5) GDPR practically does not apply to most companies, despite having fewer than 250 employees. It is tied to three narrowly defined conditions: the exemption already ceases to apply as soon as at least one of them is met.

  • The processing poses a risk to the rights and freedoms of the data subjects (according to the DSK, this regularly includes scoring and monitoring measures).
  • The processing is not merely occasional.
  • The processing concerns special categories of data under Article 9 GDPR or criminal offense data under Article 10 GDPR.

According to the DSK, the regular processing of customer or employee data already counts as "not merely occasional". Since practically every company continuously processes customer data, invoice data, or personnel files, the SME exception does not apply in the vast majority of cases. In practice, it is more the exception to the exception than a reliable exemption for small businesses.

The DSK also emphasizes: unlike with the data protection impact assessment under Article 35 GDPR, there is no need for a high risk. Any risk to rights and freedoms is already enough to void the exception.

What must be included in the record? Mandatory content under Article 30(1) GDPR

Article 30(1) sentence 2, points (a) to (g) GDPR conclusively lists which information a controller must document for each individual processing activity.

Mandatory information (Article 30(1))Content
Name and contact details (point a)Controller, joint controllers where applicable, representative, and data protection officer
Purposes of processing (point b)Specific purpose per processing activity, e.g. payroll processing or applicant management
Data subjects and categories of data (point c)Description of the categories of data subjects and the types of data processed
Categories of recipients (point d)Recipients to whom data has been or will be disclosed, including recipients in third countries
Third country transfers (point e)Recipient country or organization plus documentation of appropriate safeguards, where a transfer takes place
Erasure deadlines (point f)Envisaged time limits for the erasure of the respective data categories, where possible
Technical and organizational measures (point g)General description of the TOMs under Article 32(1) GDPR, where possible

How do you create a record of processing activities? Step by step

A ROPA can be built up in a structured way in six steps, regardless of whether you use a spreadsheet, a template form from the supervisory authorities, or dedicated software.

  1. Identify processing activities: survey all departments, HR, sales, marketing, IT, on where personal data arises, from applicant management to newsletter distribution.
  2. Clarify responsibilities: determine who is internally responsible for the content of each processing activity and serves as the point of contact.
  3. Capture mandatory information per activity: document purpose, legal basis, affected groups of data subjects, data categories, recipients, and erasure deadlines under Article 30(1) GDPR.
  4. Check third country transfers: for cloud services or tools based outside the EU or the EEA, note the basis for transfer, for example standard contractual clauses.
  5. Reference the TOMs: briefly describe the technical and organizational measures under Article 32 GDPR or refer to an existing security concept.
  6. Keep the record up to date: promptly update the relevant entry for new tools, processes, or service providers; the record is a living document, not a one-off project.

What are the consequences of a missing or incomplete record?

A missing, incomplete, or, upon request, not-produced record can be sanctioned with a fine under Article 83(4)(a) GDPR. The fine framework reaches up to 10 million euros or up to 2 percent of the total worldwide annual turnover of the preceding financial year, whichever amount is higher.

Under Article 30(4) GDPR, controllers and processors must make the record available to the supervisory authorities on request at any time; by contrast, there is no longer an obligation to present it to the public, unlike the former processing register under the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). Important to know: the record alone does not fulfill the entire accountability obligation under the GDPR arising from Article 5(2) GDPR. According to the DSK, it is only one building block alongside further evidence such as consent documentation, process descriptions, and the results of data protection impact assessments.

Frequently asked questions (FAQ)

Does a freelancer have to keep a record of processing activities?

Yes: as soon as a freelancer regularly processes personal data of customers, patients, or clients, the obligation under Article 30(1) GDPR applies regardless of the number of employees. What matters solely is that the processing is not merely occasional; the size of the practice or firm plays no role.

Who in the company is responsible for the ROPA?

The obligation rests with the company as controller within the meaning of the GDPR, not with a single person. In practice, ongoing maintenance is usually handled by the data protection officer or a designated contact person per department, while overall responsibility remains with management.

ROPA vs. privacy policy: what is the difference?

The record of processing activities is an internal document that is presented to the supervisory authority on request, but, unlike the former processing register under the BDSG, does not need to be publicly accessible. The privacy policy, by contrast, is addressed to the data subjects themselves and must be publicly accessible to them at all times, for example on the website.

How often must the record of processing activities be updated?

There is no fixed statutory deadline for updating it. However, the record must be maintained continuously: as soon as purposes, data categories, recipients, or the tools used change, the affected entry must be promptly updated.

Whoever is responsible for maintaining the record within the company benefits from a solid basic understanding of central GDPR terms such as purpose of processing, legal basis, or erasure deadline. Provimedia's GDPR fundamentals training conveys this basic knowledge compactly and concludes with a certificate of participation, evidence for employees who help create or maintain the record of processing activities.

Sources

Share this article

Stay up to date

Get the latest articles, insights and industry updates straight to your inbox.

Unsubscribe at any time. See our privacy policy.

Decide for yourself what Google shows you

Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.

Add provimedia.de to my preferred sources

Bereit für den dokumentierten Schulungsnachweis?

Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.