Skip to main content
Category: Impact Assessments & Documentation

Record of Processor Processing Activities

Also known as: ROPA, Processor ROPA, Record of Categories of Processing Activities, Article 30(2) Record
Simply put

This is a written record that a processor keeps to document the processing of personal data it carries out on behalf of its clients (the controllers). It is a version of a Record of Processing Activities (ROPA) tailored to the processor role, focusing on the categories of processing performed for others rather than the organisation's own purposes. Both controllers and processors have their own documentation obligations, and the ICO provides separate templates for each.

Formal definition

A record maintained by a processor (and, where applicable, its representative) documenting all categories of processing activities carried out on behalf of a controller, as required under Article 30 GDPR (specifically the processor-facing obligation in Article 30(2)). Under the ICO's guidance, this record typically captures information such as the categories of processing performed, and, per the general Article 30 framework, relevant details about the processing may include data categories, the groups of data subjects, and the purposes involved. Because a processor acts on behalf of controllers, a processor's record is oriented to categories of processing performed for each controller rather than the controller's own purpose-level record under Article 30(1). Note that the exact required content, exemptions (for example those tied to organisation size and risk), and any UK-specific variations should be verified against the current official UK GDPR text and ICO guidance, and member state or national implementing positions may differ; the distinction between the controller record and the processor record should be preserved and not conflated.

Why it matters

The processor's Record of Processing Activities is a core accountability instrument under Article 30(2) GDPR. It allows a processor to demonstrate, on demand, exactly what categories of processing it carries out on behalf of each of its controller clients. Because the accountability principle requires organisations not only to comply but to be able to evidence compliance, a well-maintained processor ROPA is often one of the first documents a supervisory authority such as the ICO will expect to see when scrutinising a processor's operations.

The processor record also serves a practical relationship-management function. Controllers frequently rely on their processors' records to complete or corroborate their own Article 30(1) documentation, and to satisfy due diligence obligations when engaging a processor. Keeping the two records distinct matters: a processor record is oriented to categories of processing performed for others, not to the organisation's own purpose-level processing. Conflating a controller record with a processor record can create gaps in documentation and undermine the evidence of accountability that Article 30 is designed to produce. The ICO's provision of separate controller and processor templates reflects this distinction.

The precise required content, any exemptions (for example those linked to organisation size and the risk of the processing), and UK-specific variations should be verified against the current official UK GDPR text and ICO guidance, as member state or national implementing positions may differ. Because these boundaries are subject to change and interpretation, treat the record as a living document rather than a one-time compliance exercise.

Who it's relevant to

Processor organisations
Any organisation that processes personal data on behalf of a controller may have its own documentation obligation under Article 30(2). Such organisations typically need to maintain a record oriented to the categories of processing they perform for each controller client. Whether and to what extent the obligation applies can depend on factors such as organisation size and the risk of the processing, so the current exemptions should be checked against ICO guidance and the UK GDPR text.
Data protection officers and compliance leads
DPOs and compliance teams within processor organisations are generally responsible for establishing and maintaining the processor ROPA, keeping the controller and processor records distinct, and ensuring the record can be produced to a supervisory authority on request. They also manage the relationship between the processor record and controllers' own due diligence and Article 30(1) documentation needs.
Controllers engaging processors
Controllers frequently rely on their processors' records to support their own accountability and due diligence. Understanding what a processor's Article 30(2) record should contain helps controllers assess whether a prospective or existing processor can evidence its processing activities, though controllers should remember their own separate Article 30(1) obligations remain distinct.
Supervisory authorities and auditors
Regulators such as the ICO, and internal or external auditors, use the processor record as a primary source of evidence when assessing whether a processor's activities are documented and accountable. The availability and completeness of this record is often an early indicator of an organisation's broader governance posture.

Inside ROPA

Processor and representative identity details
The name and contact details of the processor (and where applicable the processor's representative and the data protection officer), together with the name and contact details of each controller on whose behalf the processor acts. This reflects the processor-specific record obligation under Article 30(2) GDPR, which differs in content from the controller's record under Article 30(1).
Categories of processing carried out
A description of the categories of processing performed on behalf of each controller. Note that a processor's record generally focuses on the categories of processing activity rather than the detailed purposes, which are typically the controller's responsibility to document.
International transfer information
Where applicable, details of transfers of personal data to a third country or international organisation, including the identification of that country or organisation. Documentation of the transfer tool relied upon may also be recorded; transfer mechanisms and any supplementary measures evolve, so the recorded position should be reviewed against current requirements.
General description of technical and organisational security measures
Where possible, a general description of the technical and organisational security measures referred to in Article 32 GDPR. This is generally a high-level description rather than a full security specification, and should be kept consistent with the measures actually implemented.

Common questions

Answers to the questions practitioners most commonly ask about ROPA.

Is a processor's record of processing activities the same as a controller's record?
No. Although both are records of processing activities under Article 30, they are distinct in content and perspective. A controller's record (Article 30(1)) documents the controller's own processing purposes, legal bases, categories of data subjects and data, and related details. A processor's record (Article 30(2)) documents the categories of processing carried out on behalf of each controller, generally including the identity of the controllers and any sub-processors, categories of processing, cross-border transfers, and a description of security measures. The processor is documenting activities it performs for others, not defining its own purposes. Treating the two records as interchangeable is a common error; they serve different accountability functions and should be maintained separately for each role an organisation holds.
Does the record of processor processing activities need to include a legal basis for the processing?
Generally no. The lawful basis under Article 6 (and any additional Article 9 condition for special category data) is determined by the controller, and the controller's record is where such matters are typically addressed. Article 30(2), which governs the processor's record, does not list the legal basis among the required elements. A processor documents the categories of processing it carries out on behalf of controllers rather than justifying the lawfulness of the underlying purposes. Readers should consult the current text of Article 30(2) to confirm the specific elements required, as the processor's and controller's obligations differ on this point.
Who within a processor organisation is responsible for maintaining the record?
Article 30(2) places the obligation on the processor (and, where applicable, the processor's representative). In practice, responsibility is typically assigned to a designated function such as a data protection officer, privacy or compliance team, or a records owner, though the DPO's role is generally advisory and oversight-focused rather than one of primary ownership. The allocation of internal responsibility is an organisational matter not prescribed by the Regulation; what matters is that the record is accurately maintained and available to the supervisory authority on request. Organisations should verify their internal governance against their own accountability framework and applicable national guidance.
In what form must the record be kept, and does it have to be produced on request?
Article 30 requires the record to be maintained in writing, which includes electronic form. There is no prescribed template mandated by the Regulation, so organisations may use spreadsheets, dedicated tooling, or other structured formats provided the required elements are captured. The record must generally be made available to the supervisory authority on request. Some supervisory authorities publish suggested templates or guidance, and approaches can vary between regulators, so it is advisable to check the relevant authority's current expectations.
How should a processor keep the record up to date as engagements change?
The record is generally expected to reflect current processing, so it should be reviewed and updated when relevant circumstances change, such as onboarding a new controller client, appointing or removing a sub-processor, altering categories of processing, or changing cross-border transfer arrangements. Because the Regulation frames Article 30 records as a living accountability document rather than a one-off exercise, many organisations adopt periodic review cycles alongside event-triggered updates. The specific cadence is a matter of organisational risk assessment and is not fixed by the Regulation text.
Are all processors required to maintain this record, or do exemptions apply?
Article 30 contains a limited derogation that can, subject to conditions, relieve certain smaller organisations from the record-keeping obligation. However, this exemption is narrow and typically does not apply where processing is not occasional, where it involves special category data, or where it is likely to result in a risk to the rights and freedoms of data subjects. Because these conditions are frequently met in practice, many processors cannot rely on the exemption. Organisations should assess their specific circumstances against the precise wording of the exemption in the current Article 30 text and any applicable national or supervisory authority guidance before concluding that it applies.

Common misconceptions

A processor's Record of Processing Activities must contain the same information as a controller's record.
The processor's record under Article 30(2) has a distinct, generally narrower content than the controller's record under Article 30(1). For example, a processor typically records categories of processing carried out on behalf of controllers rather than the purposes of processing, which remain the controller's responsibility.
A Record of Processing Activities is the same instrument as a Data Processing Agreement.
These are distinct. A Record of Processing Activities under Article 30 is an internal documentation obligation, whereas a Data Processing Agreement under Article 28 is a contract governing the controller-processor relationship. Maintaining one does not satisfy the requirement for the other.
Small organisations are automatically exempt from keeping a processor record.
Article 30 contains a limited derogation that is subject to specific conditions, and its application is context dependent rather than a blanket exemption based on size. Practitioners should assess whether the conditions are met and verify against the current official text, as interpretation and guidance may vary.

Best practices

Maintain the processor record in a structured, writable format (including electronic form) so it can be readily produced to a supervisory authority on request.
Keep a separate record for each controller you act for, clearly linking the categories of processing to the corresponding controller and, where relevant, the underlying Article 28 processing agreement.
Record international transfers with the identified destination and the transfer tool relied upon, and schedule periodic reviews because adequacy decisions, transfer mechanisms, and supplementary measures change over time.
Include a general, accurate description of the Article 32 security measures where possible, and reconcile it against the measures actually deployed rather than an idealised list.
Review and update the record whenever processing activities, sub-processors, transfers, or security measures change, and treat it as a living document rather than a one-off exercise.
Where you consider relying on any Article 30 derogation, document the assessment supporting that position and verify the conditions against the current official Regulation text, noting that member state and regulator interpretations may vary.