Organisation and contacts
Who is responsible for the processing record and how the organisation can be contacted.
We do not use cookies of this type.
We do not use cookies of this type.
A Record of Processing Activities, or RoPA, is the structured record behind GDPR Article 30. This guide explains what belongs in one and how SmartRoPA™ helps customers organize, review and maintain that information.
A practical journey
Step 1
Learn what a Record of Processing Activities is and why GDPR Article 30 matters.
Step 2
Work through the tools, activities and business facts that belong in your RoPA.
Step 3
Return to update your processing and prepare a new version when your business changes.
Educational guidance first. A structured SmartRoPA™ workflow when you are ready to build.
RoPA stands for Record of Processing Activities. It is a structured record of how an organisation collects, uses, stores, shares, protects and deletes personal data. Rather than naming every individual, it maps processing into understandable activities and categories.
GDPR Article 30 sets out record-keeping requirements for controllers and processors. A useful RoPA also gives a business a practical view of its own data practices, vendors and responsibilities.
Smaller organisations can still have record-keeping obligations where processing is regular, creates a risk to people, or involves special-category or criminal-conviction data. Regular marketing, payments, memberships, analytics and support can make processing more than occasional.
Each processing activity should tell a coherent story. The exact detail depends on the organisation and its role, but these are the core categories most records need to address.
Who is responsible for the processing record and how the organisation can be contacted.
Why each processing activity happens, described in practical business terms.
The categories of people involved and the types of personal information used.
The internal and external parties, vendors or service providers that receive the data.
Where personal data may move outside the relevant jurisdiction and the safeguards involved.
How long the information is kept, what starts the period and what happens at the end.
A suitable high-level description of the organisational and technical protections in place.
The basis relied on and whether the organisation acts as controller or processor for the activity.
Worked example
One familiar activity shows how the categories work together without listing individual subscribers.
Lawful basis and controller/processor roles require organisation-specific judgment. SmartRoPA™ helps structure the information, but it does not choose a lawful basis or provide legal advice.
A blank spreadsheet can look simple at first. The difficulty appears when the organisation has to find the facts, connect tools to activities, ask the right follow-up questions and keep everything aligned over time.
Information is scattered across teams, inboxes, contracts and spreadsheets.
Unofficial or forgotten tools can be missed when the record is prepared.
Vendor, processor, recipient and transfer research is repeated for every update.
Generic questions are difficult to apply to a specific processing activity.
Retention language can become vague or inconsistent across the record.
A static document becomes outdated as tools and business practices change.
From complexity to structure
This is the problem SmartRoPA™ is designed to simplify.
Instead of beginning with a blank template, customers work through a guided business-function and tool workflow. SmartRoPA™ helps organize published tool information, customer-specific facts, completion tasks and review steps into a coherent RoPA version.
SmartRoPA™ structures information from customer inputs and confirmations. It does not determine lawfulness, provide legal advice or guarantee compliance.
SmartRoPA™ moves from the structure of your business to the tools it uses, then to the processing facts that belong in the record.
Review the areas of the business that use personal data and record when a function has no relevant tools.
Search the published Tool Library or add a custom tool when the service is not yet listed.
Review structured information for published tools and explain how the tool is actually used in your business.
Supply and confirm facts such as purpose, lawful basis, retention, security and transfers where applicable.
Resolve outstanding details, complete Final Review and attest to the information before submitting the version.
Return for requested changes, business updates, new tools or a replacement RoPA version.
The experience connects four practical parts of the RoPA journey. Each area is designed to keep the customer focused on the decisions and information relevant to the current activity.

A function-by-function workspace makes it easier to see what has been reviewed, what is in progress and where no tools are used.

SmartRoPA™ launches with 80 published tools, with approximately 170 planned. New tools will be added regularly as services evolve. If a service is not yet available, add it as a custom tool and continue your RoPA work.
Want us to consider a tool for the maintained published library? Send us a request.
Request a tool for the library
Structured tool information is combined with customer answers about actual use, connected systems and other business-specific details.

Completion highlights information that still needs attention. Final Review brings prepared information together so customers can resolve outstanding items, review and attest before the RoPA version is submitted.
SmartRoPA™ brings prepared information and outstanding customer-owned details together. Customers can address what still needs attention, review the assembled record and attest before submitting the version into the GPR review workflow.
Helps identify currently applicable information that still needs customer attention. It is not a legal or compliance validation.
Gives the customer a structured view of the information it is about to submit. It does not mean GPR approval.
The generated version reflects confirmed information and customer inputs. The customer remains responsible for checking that the record matches its actual processing practices.
A RoPA is not a one-time document. New tools, integrations, processing purposes, locations and retention practices can all change the record.
Reflect changes to tools, activities and the way personal data is used.
Return to the relevant version when changes or clarification are requested.
Build a newer version while the existing approved/current version remains operative where relevant.
Keep version history so the current record and earlier submissions remain distinguishable.
SmartRoPA™ can make the record easier to structure and maintain, but the organisation remains the authoritative source for its own processing facts.
This resource is general information, not legal advice. Privacy and legal requirements depend on the organisation’s specific processing and circumstances.
Customers who already maintain a current RoPA can use the separate uploaded-RoPA workflow instead of rebuilding it immediately through SmartRoPA™. Upload and review do not amount to legal certification.
Clear answers about the underlying record, the SmartRoPA™ workflow and the responsibilities that remain with the customer.
A Record of Processing Activities is a structured record of how an organisation collects, uses, stores, shares, protects and deletes personal data. It describes categories of processing rather than listing every individual by name.
Article 30 of the GDPR sets out record-keeping requirements for controllers and processors. The record typically covers purposes, people and data categories, recipients, transfers, retention and security information.
The exception for organisations with fewer than 250 employees is limited. Regular processing, risk to individuals, or processing involving special-category or criminal-conviction data can still create record-keeping obligations. Seek qualified advice for your circumstances.
A RoPA generally includes organisation and contact information, processing purposes, categories of people and personal data, recipients and processors, transfers, retention, security measures and role-specific information.
Usually the RoPA describes categories of people and data rather than naming each customer. The goal is to document the processing activity and its data flows, not to reproduce the underlying customer database.
SmartRoPA™ is GPR’s structured customer workflow for organizing business functions, tools, processing activities, customer-specific facts, completion tasks and review steps into a RoPA version.
The Tool Library provides published structured information for supported tools. Customers still confirm how a tool is actually used by their business and supply any facts that are specific to their processing.
No. SmartRoPA™ helps structure information and guide customers through a workflow. It does not provide legal advice, determine lawfulness or guarantee compliance.
No. The organisation remains responsible for identifying and supporting the lawful basis that applies to its processing. Independent advice may be appropriate where the answer is uncertain.
Yes. A RoPA should be kept current as tools and processing practices change. SmartRoPA™ supports returning to the record and preparing an updated version.
The customer can return to the relevant SmartRoPA™ workflow, address the requested information and prepare the version for review again. The exact actions shown depend on the current RoPA state.
Customers who already maintain a current RoPA can use the separate uploaded-RoPA workflow instead of rebuilding it immediately through SmartRoPA™.
No. GPR review is not legal certification of every processing activity. The customer remains responsible for the facts supplied, its actual practices and the lawfulness of its processing.
Explore GPR plans, return to your customer RoPA workspace, or ask our team a question about the journey.