Policy Register

Record of processing activities

The register of every processing activity: purposes, categories, recipients, transfers, retention and security measures.

How the register reads it

Also calledRoPA, processing register, data inventory
FamilyPrivacy
Document typeRecord. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe data protection officer or privacy lead.
Review cadenceNo fixed period: Article 30 requires the record to be maintained, so it changes whenever a processing activity changes; the register's default check is annual.
On the gap list whenGDPR or ISO 27701 is ticked and no line resolves to it.
TemplateRecords of processing activities template.

Which standards require it, and what each expects it to contain

3 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27701:2025

ISO 27701 A.1.2.9 Records related to processing PII

The organization must determine and securely maintain the records that support its obligations for processing, typically an inventory of processing activities covering the type of processing, its purposes, the categories of personal data and of individuals including any special cases such as children, the categories of recipients including those in third countries or international organizations, a general description of the technical and organizational security measures, and the privacy impact assessment report, with a named owner responsible for the inventory's accuracy and completeness.

Evidence an auditor accepts: Processing inventory carrying each required element; named owner accountable for its accuracy and completeness; evidence the inventory is maintained through change, not rebuilt for audits
Common gap: Inventory owned by nobody, so it decays between audits
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.2 Identify and document purpose

The organization must identify and document the specific purposes for which personal data will be processed, documented clearly and in enough detail to be usable in the information given to individuals, in obtaining consent, and in the records of policies and procedures, so that individuals understand why their data is processed.

Evidence an auditor accepts: Purpose register at the level of the processing activity, not the system; evidence the documented purpose text is the text actually used in notices and consent; review record showing purposes are updated when processing changes
Common gap: Purposes written as business objectives such as improving service, too vague to test any later processing against
Source: ISO/IEC 27701:2025

GDPR (Regulation (EU) 2016/679)

GDPR Art. 30 Records of processing activities

Maintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of processing carried out on behalf of each controller. Make the record available to the supervisory authority on request. The obligation does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data.

Evidence an auditor accepts: The record of processing activities in full, checked against the seven controller elements, or the four processor elements, the Article lists; version history showing when each entry was last reviewed and by whom; reconciliation of the record against a system inventory or data flow map, to show nothing is missing rather than that the entries read well
Common gap: Records written once during the implementation project and never updated against reality, so they describe systems long replaced and omit those adopted since
Source: GDPR (Regulation (EU) 2016/679)

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Privacy notice · AI governance policy