Glossary

RoPA

A Record of Processing Activities (RoPA) is an inventory of how an organization processes personal data, maintained to demonstrate GDPR accountability.

Under Article 30 of the GDPR, many organizations must maintain a Record of Processing Activities. The RoPA catalogues each processing activity along with its purpose, the categories of data subjects and personal data involved, recipients, international transfers, retention periods, and the security measures applied.

The RoPA serves as the foundational map of an organization's data flows. It supports other privacy obligations — responding to data-subject requests, scoping DPIAs, and assessing vendor risk — because it shows where personal data lives and how it moves.

Keeping the RoPA current is an ongoing task. As products and integrations change, new processing activities must be added, which is why many teams maintain the RoPA in a tool that links it to the underlying systems and vendors.

Related terms