Glossary

Records of processing activities (ROPA)

The records of processing activities (ROPA) are the document required by Article 30 of the GDPR listing, for each personal data processing activity, its purpose, the categories of data and data subjects, the recipients, transfers outside the EU, retention periods and security measures.

Who must keep them

Controllers and processors each keep records, with different content: the former describe their own processing, the latter the processing carried out on behalf of clients. The exemption for organisations under 250 employees is practically void: it falls away as soon as processing is not occasional, involves special categories of data or poses a risk to individuals — which covers nearly all HR and customer processing.

Why this is a TPRM artefact, not just a compliance one

Every recipient listed in the records is a third party, and every third party listed should have a signed DPA, a known sub-processor list and an assessed criticality level. Kept separately, the records become a declarative document that drifts from reality; attached to the vendor file, they become the "data" view of third-party mapping and are updated at the same pace. See the GDPR page.

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account