This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.

We work with 11 third parties who may receive and process your information.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
    • Learn more about this provideropens in a new window
      CookieConsentStores the user's cookie consent state for the current domain
      Maximum Storage Duration: 1 yearType: HTTP Cookie
    • Learn more about this provideropens in a new window
      __stripe_midThis cookie is necessary for making credit card transactions on the website. The service is provided by Stripe.com which allows online transactions without storing any credit card information.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      __stripe_sidThis cookie is necessary for making credit card transactions on the website. The service is provided by Stripe.com which allows online transactions without storing any credit card information.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      mDetermines the device used to access the website. This allows the website to be formatted accordingly.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
    • __cflbRegisters which server-cluster is serving the visitor. This is used in context with load balancing, in order to optimize user experience.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      hmt_idThis cookie is used to distinguish between humans and bots.
      Maximum Storage Duration: 30 daysType: HTTP Cookie
    • __cf_bm [x2]This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • Learn more about this provideropens in a new window
      _abThis cookie is necessary for making credit card transactions on the website. The service is provided by Stripe.com which allows online transactions without storing any credit card information.
      Maximum Storage Duration: SessionType: HTML Local Storage
      _mfThis cookie is necessary for making credit card transactions on the website. The service is provided by Stripe.com which allows online transactions without storing any credit card information.
      Maximum Storage Duration: SessionType: HTML Local Storage
      idPending
      Maximum Storage Duration: SessionType: HTML Local Storage
    • firebase-heartbeat-database#firebase-heartbeat-storeUsed in order to detect spam and improve the website's security.
      Maximum Storage Duration: PersistentType: IndexedDB
    • CIDThis cookie is necessary for making credit card transactions on the website. The service is provided by Stripe.com which allows online transactions without storing any credit card information.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • Learn more about this provideropens in a new window
      1This cookie is used in conjunction with the payment window - The cookie is necessary for making secure transactions on the website.
      Maximum Storage Duration: SessionType: HTML Local Storage
  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • SDTPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • appgw02AffinityPending
      Maximum Storage Duration: SessionType: HTTP Cookie
      appgw02AffinityCORSPending
      Maximum Storage Duration: SessionType: HTTP Cookie
      VitriumDownloadToCacheStorage#DataPending
      Maximum Storage Duration: PersistentType: IndexedDB
      VitriumDownloadToCacheStorage#PublicDataPending
      Maximum Storage Duration: PersistentType: IndexedDB
Cookie declaration last updated on 8/29/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
RoPA & SmartRoPA™

Understand your RoPA. Build it the smarter way.

A Record of Processing Activities, or RoPA, is the structured record behind GDPR Article 30. This guide explains what belongs in one and how SmartRoPA™ helps customers organize, review and maintain that information.

A practical journey

From understanding the obligation to maintaining the record

Step 1

Understand the requirement

Learn what a Record of Processing Activities is and why GDPR Article 30 matters.

Step 2

Build a structured record

Work through the tools, activities and business facts that belong in your RoPA.

Step 3

Keep it current

Return to update your processing and prepare a new version when your business changes.

Educational guidance first. A structured SmartRoPA™ workflow when you are ready to build.

The foundation

What is a RoPA, and why does it matter?

RoPA stands for Record of Processing Activities. It is a structured record of how an organisation collects, uses, stores, shares, protects and deletes personal data. Rather than naming every individual, it maps processing into understandable activities and categories.

GDPR Article 30 sets out record-keeping requirements for controllers and processors. A useful RoPA also gives a business a practical view of its own data practices, vendors and responsibilities.

The 250-employee exception is narrower than it sounds

Smaller organisations can still have record-keeping obligations where processing is regular, creates a risk to people, or involves special-category or criminal-conviction data. Regular marketing, payments, memberships, analytics and support can make processing more than occasional.

What you need to record

What goes into a RoPA?

Each processing activity should tell a coherent story. The exact detail depends on the organisation and its role, but these are the core categories most records need to address.

Organisation and contacts

Who is responsible for the processing record and how the organisation can be contacted.

Purposes

Why each processing activity happens, described in practical business terms.

People and personal data

The categories of people involved and the types of personal information used.

Recipients and processors

The internal and external parties, vendors or service providers that receive the data.

International transfers

Where personal data may move outside the relevant jurisdiction and the safeguards involved.

Retention

How long the information is kept, what starts the period and what happens at the end.

Security measures

A suitable high-level description of the organisational and technical protections in place.

Lawful basis and roles

The basis relied on and whether the organisation acts as controller or processor for the activity.

Worked example

An email newsletter

One familiar activity shows how the categories work together without listing individual subscribers.

Purpose
Send opted-in news and product updates.
People and data
Subscribers; names, email addresses and preferences.
Recipients
The organisation and its email service provider.
Retention and security
A defined unsubscribe/deletion rule and appropriate access controls.

Lawful basis and controller/processor roles require organisation-specific judgment. SmartRoPA™ helps structure the information, but it does not choose a lawful basis or provide legal advice.

The practical challenge

Why manual RoPA preparation gets difficult

A blank spreadsheet can look simple at first. The difficulty appears when the organisation has to find the facts, connect tools to activities, ask the right follow-up questions and keep everything aligned over time.

1

Information is scattered across teams, inboxes, contracts and spreadsheets.

2

Unofficial or forgotten tools can be missed when the record is prepared.

3

Vendor, processor, recipient and transfer research is repeated for every update.

4

Generic questions are difficult to apply to a specific processing activity.

5

Retention language can become vague or inconsistent across the record.

6

A static document becomes outdated as tools and business practices change.

From complexity to structure

This is the problem SmartRoPA™ is designed to simplify.

Meet SmartRoPA™
SmartRoPA™
Introducing SmartRoPA™

A structured way to build and maintain your RoPA

Instead of beginning with a blank template, customers work through a guided business-function and tool workflow. SmartRoPA™ helps organize published tool information, customer-specific facts, completion tasks and review steps into a coherent RoPA version.

Business-function workflow
Published Tool Library
Customer-specific questions
Completion and Final Review
Structured RoPA versions
Revision and update journey

SmartRoPA™ structures information from customer inputs and confirmations. It does not determine lawfulness, provide legal advice or guarantee compliance.

How SmartRoPA™ works

How SmartRoPA™ works

SmartRoPA™ moves from the structure of your business to the tools it uses, then to the processing facts that belong in the record.

MarketingCommunity, Social Media & Mobile AppSalesSupportFinancial & BillingAdditional Business Functions
  1. 01

    Work through business functions

    Review the areas of the business that use personal data and record when a function has no relevant tools.

  2. 02

    Identify the tools you use

    Search the published Tool Library or add a custom tool when the service is not yet listed.

  3. 03

    Confirm tool and business facts

    Review structured information for published tools and explain how the tool is actually used in your business.

  4. 04

    Complete activity details

    Supply and confirm facts such as purpose, lawful basis, retention, security and transfers where applicable.

  5. 05

    Review, attest and submit

    Resolve outstanding details, complete Final Review and attest to the information before submitting the version.

  6. 06

    Keep the record current

    Return for requested changes, business updates, new tools or a replacement RoPA version.

See it in action

See SmartRoPA™ in action

The experience connects four practical parts of the RoPA journey. Each area is designed to keep the customer focused on the decisions and information relevant to the current activity.

SmartRoPA™ business-function workspace showing six business areas and progress

Move through the business in a clear order

A function-by-function workspace makes it easier to see what has been reviewed, what is in progress and where no tools are used.

  • Visible progress
  • Tools grouped by use
  • No-tool decisions
  • Return anytime
SmartRoPA™ Tool Library showing recommended Marketing tools

Start with the services your organisation uses

SmartRoPA™ launches with 80 published tools, with approximately 170 planned. New tools will be added regularly as services evolve. If a service is not yet available, add it as a custom tool and continue your RoPA work.

  • 80 tools at launch
  • ~170 planned
  • Regularly expanded
  • Add a custom tool

Want us to consider a tool for the maintained published library? Send us a request.

Request a tool for the library
SmartRoPA™ business-specific questions for a GetResponse processing activity

Add the facts only your organisation can confirm

Structured tool information is combined with customer answers about actual use, connected systems and other business-specific details.

  • Follow-up questions
  • Customer confirmations
  • Activity-level details
  • Answer progress
SmartRoPA™ Final Review showing workspace summary and outstanding items

Bring prepared and outstanding information together

Completion highlights information that still needs attention. Final Review brings prepared information together so customers can resolve outstanding items, review and attest before the RoPA version is submitted.

  • Outstanding checks
  • Workspace summary
  • Customer review
  • Version submission
From workspace to RoPA

Completion, Final Review and a structured RoPA version

SmartRoPA™ brings prepared information and outstanding customer-owned details together. Customers can address what still needs attention, review the assembled record and attest before submitting the version into the GPR review workflow.

Completion

Helps identify currently applicable information that still needs customer attention. It is not a legal or compliance validation.

Final Review

Gives the customer a structured view of the information it is about to submit. It does not mean GPR approval.

The generated version reflects confirmed information and customer inputs. The customer remains responsible for checking that the record matches its actual processing practices.

Keeping it current

Keeping your RoPA current

A RoPA is not a one-time document. New tools, integrations, processing purposes, locations and retention practices can all change the record.

1

Update the facts

Reflect changes to tools, activities and the way personal data is used.

2

Respond to requests

Return to the relevant version when changes or clarification are requested.

3

Prepare a replacement

Build a newer version while the existing approved/current version remains operative where relevant.

4

Maintain history

Keep version history so the current record and earlier submissions remain distinguishable.

Explore the next step
Important context

Responsibilities and limitations

SmartRoPA™ can make the record easier to structure and maintain, but the organisation remains the authoritative source for its own processing facts.

  • The customer remains responsible for the accuracy and completeness of the information supplied.
  • The customer remains responsible for ensuring the record reflects its actual processing practices.
  • SmartRoPA™ structures and prepares information from customer inputs, confirmations and published tool records.
  • GPR review is not legal certification of every processing activity.
  • SmartRoPA™ does not determine lawfulness, independently choose a lawful basis or guarantee GDPR compliance.
  • Independent legal or privacy advice may still be appropriate for the organisation’s circumstances.

This resource is general information, not legal advice. Privacy and legal requirements depend on the organisation’s specific processing and circumstances.

Secondary option

Already have a RoPA?

Customers who already maintain a current RoPA can use the separate uploaded-RoPA workflow instead of rebuilding it immediately through SmartRoPA™. Upload and review do not amount to legal certification.

Upload an existing RoPA
Common questions

RoPA and SmartRoPA™ FAQ

Clear answers about the underlying record, the SmartRoPA™ workflow and the responsibilities that remain with the customer.

What is a RoPA?

A Record of Processing Activities is a structured record of how an organisation collects, uses, stores, shares, protects and deletes personal data. It describes categories of processing rather than listing every individual by name.

What is GDPR Article 30?

Article 30 of the GDPR sets out record-keeping requirements for controllers and processors. The record typically covers purposes, people and data categories, recipients, transfers, retention and security information.

Does every small business need a RoPA?

The exception for organisations with fewer than 250 employees is limited. Regular processing, risk to individuals, or processing involving special-category or criminal-conviction data can still create record-keeping obligations. Seek qualified advice for your circumstances.

What information belongs in a RoPA?

A RoPA generally includes organisation and contact information, processing purposes, categories of people and personal data, recipients and processors, transfers, retention, security measures and role-specific information.

Do individual customer names belong in it?

Usually the RoPA describes categories of people and data rather than naming each customer. The goal is to document the processing activity and its data flows, not to reproduce the underlying customer database.

What is SmartRoPA™?

SmartRoPA™ is GPR’s structured customer workflow for organizing business functions, tools, processing activities, customer-specific facts, completion tasks and review steps into a RoPA version.

How does the SmartRoPA™ Tool Library help?

The Tool Library provides published structured information for supported tools. Customers still confirm how a tool is actually used by their business and supply any facts that are specific to their processing.

Does SmartRoPA™ give legal advice?

No. SmartRoPA™ helps structure information and guide customers through a workflow. It does not provide legal advice, determine lawfulness or guarantee compliance.

Does SmartRoPA™ choose my lawful basis?

No. The organisation remains responsible for identifying and supporting the lawful basis that applies to its processing. Independent advice may be appropriate where the answer is uncertain.

Can I update my RoPA later?

Yes. A RoPA should be kept current as tools and processing practices change. SmartRoPA™ supports returning to the record and preparing an updated version.

What happens if changes are requested?

The customer can return to the relevant SmartRoPA™ workflow, address the requested information and prepare the version for review again. The exact actions shown depend on the current RoPA state.

What if I already have a RoPA?

Customers who already maintain a current RoPA can use the separate uploaded-RoPA workflow instead of rebuilding it immediately through SmartRoPA™.

Does GPR confirm that all my processing is lawful?

No. GPR review is not legal certification of every processing activity. The customer remains responsible for the facts supplied, its actual practices and the lawfulness of its processing.

Ready for the next step?

Turn your processing facts into a record you can maintain

Explore GPR plans, return to your customer RoPA workspace, or ask our team a question about the journey.