RoPA
A Record of Processing Activities (RoPA) is an inventory of how an organization processes personal data, maintained to demonstrate GDPR accountability.
Under Article 30 of the GDPR, many organizations must maintain a Record of Processing Activities. The RoPA catalogues each processing activity along with its purpose, the categories of data subjects and personal data involved, recipients, international transfers, retention periods, and the security measures applied.
The RoPA serves as the foundational map of an organization's data flows. It supports other privacy obligations — responding to data-subject requests, scoping DPIAs, and assessing vendor risk — because it shows where personal data lives and how it moves.
Keeping the RoPA current is an ongoing task. As products and integrations change, new processing activities must be added, which is why many teams maintain the RoPA in a tool that links it to the underlying systems and vendors.
Related terms
- GDPRThe General Data Protection Regulation (GDPR) is the European Union law governing the processing of personal data, granting individuals rights over their data and imposing accountability obligations on organizations.
- DPIAA Data Protection Impact Assessment (DPIA) is a structured process for identifying and minimizing the data-protection risks of a project or processing activity.
- Vendor Risk ManagementVendor risk management (VRM) is the process of identifying, assessing, and monitoring the security and compliance risks introduced by third-party suppliers and service providers.
- Evidence CollectionEvidence collection is the process of gathering proof that compliance controls are designed and operating effectively, for use in audits and attestations.