Record of Processor Processing Activities
This is a written record that a processor keeps to document the processing of personal data it carries out on behalf of its clients (the controllers). It is a version of a Record of Processing Activities (ROPA) tailored to the processor role, focusing on the categories of processing performed for others rather than the organisation's own purposes. Both controllers and processors have their own documentation obligations, and the ICO provides separate templates for each.
A record maintained by a processor (and, where applicable, its representative) documenting all categories of processing activities carried out on behalf of a controller, as required under Article 30 GDPR (specifically the processor-facing obligation in Article 30(2)). Under the ICO's guidance, this record typically captures information such as the categories of processing performed, and, per the general Article 30 framework, relevant details about the processing may include data categories, the groups of data subjects, and the purposes involved. Because a processor acts on behalf of controllers, a processor's record is oriented to categories of processing performed for each controller rather than the controller's own purpose-level record under Article 30(1). Note that the exact required content, exemptions (for example those tied to organisation size and risk), and any UK-specific variations should be verified against the current official UK GDPR text and ICO guidance, and member state or national implementing positions may differ; the distinction between the controller record and the processor record should be preserved and not conflated.
Why it matters
The processor's Record of Processing Activities is a core accountability instrument under Article 30(2) GDPR. It allows a processor to demonstrate, on demand, exactly what categories of processing it carries out on behalf of each of its controller clients. Because the accountability principle requires organisations not only to comply but to be able to evidence compliance, a well-maintained processor ROPA is often one of the first documents a supervisory authority such as the ICO will expect to see when scrutinising a processor's operations.
The processor record also serves a practical relationship-management function. Controllers frequently rely on their processors' records to complete or corroborate their own Article 30(1) documentation, and to satisfy due diligence obligations when engaging a processor. Keeping the two records distinct matters: a processor record is oriented to categories of processing performed for others, not to the organisation's own purpose-level processing. Conflating a controller record with a processor record can create gaps in documentation and undermine the evidence of accountability that Article 30 is designed to produce. The ICO's provision of separate controller and processor templates reflects this distinction.
The precise required content, any exemptions (for example those linked to organisation size and the risk of the processing), and UK-specific variations should be verified against the current official UK GDPR text and ICO guidance, as member state or national implementing positions may differ. Because these boundaries are subject to change and interpretation, treat the record as a living document rather than a one-time compliance exercise.
Who it's relevant to
Inside ROPA
Common questions
Answers to the questions practitioners most commonly ask about ROPA.