Record of processing activities
The register of every processing activity: purposes, categories, recipients, transfers, retention and security measures.
How the register reads it
| Also called | RoPA, processing register, data inventory |
|---|---|
| Family | Privacy |
| Document type | Record. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The data protection officer or privacy lead. |
| Review cadence | No fixed period: Article 30 requires the record to be maintained, so it changes whenever a processing activity changes; the register's default check is annual. |
| On the gap list when | GDPR or ISO 27701 is ticked and no line resolves to it. |
| Template | Records of processing activities template. |
Which standards require it, and what each expects it to contain
3 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27701:2025
ISO 27701 A.1.2.9 Records related to processing PIIThe organization must determine and securely maintain the records that support its obligations for processing, typically an inventory of processing activities covering the type of processing, its purposes, the categories of personal data and of individuals including any special cases such as children, the categories of recipients including those in third countries or international organizations, a general description of the technical and organizational security measures, and the privacy impact assessment report, with a named owner responsible for the inventory's accuracy and completeness.
Common gap: Inventory owned by nobody, so it decays between audits
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.2 Identify and document purposeThe organization must identify and document the specific purposes for which personal data will be processed, documented clearly and in enough detail to be usable in the information given to individuals, in obtaining consent, and in the records of policies and procedures, so that individuals understand why their data is processed.
Common gap: Purposes written as business objectives such as improving service, too vague to test any later processing against
Source: ISO/IEC 27701:2025
GDPR (Regulation (EU) 2016/679)
GDPR Art. 30 Records of processing activitiesMaintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of processing carried out on behalf of each controller. Make the record available to the supervisory authority on request. The obligation does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data.
Common gap: Records written once during the implementation project and never updated against reality, so they describe systems long replaced and omit those adopted since
Source: GDPR (Regulation (EU) 2016/679)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register