Record of Controller Processing Activities
A record of controller processing activities is an internal document in which an organisation acting as a controller describes how and why it processes personal data. It generally captures information such as the purposes of the processing, the categories of individuals and personal data involved, and other relevant details about the processing. Controllers are typically required to keep more extensive records than processors.
Under Article 30 of the GDPR (and the equivalent provision in the UK GDPR), each controller and, where applicable, the controller's representative is required to maintain a record of processing activities carried out under its responsibility. According to guidance and the Article 30 text referenced in the evidence, such records generally include significant information about the processing, such as the purposes, the categories of data subjects, and the categories of personal data. Both controllers and processors have documentation obligations, but the controller record is typically more extensive than that maintained by a processor. Note that Article 30 contains conditions and possible exemptions affecting who must keep records and the required detail; practitioners should verify the specific content requirements and any exemptions against the current official GDPR/UK GDPR text and applicable regulator guidance, as national implementation and interpretation may vary.
Why it matters
A record of controller processing activities sits at the heart of the GDPR's accountability principle. It provides a structured, internal picture of what personal data an organisation processes, why, and under what conditions, which allows a controller to demonstrate that it understands and can account for its own processing. Without such a record, it is generally difficult for a controller to answer basic questions from a supervisory authority, respond consistently to data subject requests, or maintain a reliable overview of its data flows.
The record also functions as a foundational reference for other compliance activities. Because it captures the purposes of processing, the categories of data subjects, and the categories of personal data, it can inform tasks such as identifying processing that may warrant closer assessment and mapping where personal data is held. Controllers are generally required to keep more extensive records than processors, reflecting the broader responsibility a controller holds for determining the purposes and means of processing.
It is important to note that Article 30 contains conditions and possible exemptions affecting who must maintain records and how detailed those records must be, and national implementation and regulator interpretation may vary. Practitioners should therefore treat the record as a living document and verify the specific content requirements against the current official GDPR or UK GDPR text and applicable guidance rather than relying on a fixed template alone.
Who it's relevant to
Inside RoPA
Common questions
Answers to the questions practitioners most commonly ask about RoPA.