Compliance registers · Gixo Lex
Records of Processing Activities (RoPA) Builder
Build an Article 30 structure and flag incomplete transfer, safeguard, and retention fields.
RoPA under GDPR Article 30: what the record has to contain
A RoPA is the internal register showing what personal data an organisation processes and why. Article 30 sets the contents, and the nine columns this builder asks for are those contents, one row per processing activity rather than one row per system.
- Activity — the processing operation the row describes.
- Purpose — Article 30(1)(b), the purposes of the processing.
- Data subjects — Article 30(1)(c), the categories of people whose data is processed.
- Data categories — the other half of 30(1)(c), the categories of personal data.
- Recipients — Article 30(1)(d), who the data is disclosed to, including recipients in third countries.
- Third-country transfer — Article 30(1)(e), the country the data goes to.
- Safeguard — the second half of 30(1)(e), the transfer mechanism relied on. A transfer recorded with no safeguard is flagged.
- Retention — Article 30(1)(f), the envisaged erasure time limit. A blank one is flagged.
- Technical and organisational measures — Article 30(1)(g), the general description of security measures. A blank one is flagged.
Record of processing activities
RoPA is the abbreviation for record of processing activities — the same document spelled out. Some organisations call it an Article 30 record or a data processing register. A data map is a different artifact: it shows where data physically sits, which is useful, but it is not the record Article 30 asks for. The register header carries the rest of Article 30(1)(a): who the controller or processor is, their contact details, and the DPO's contact details where one is appointed.
Document inputs
Required gaps remain visible as [ ], so the downloaded handoff never silently hides unfinished work.
Need a different artifact?
Browse all 12 governed builders on the public template hub, or use the smaller checkers on the free tools hub.
Details
Records of Processing Activities (RoPA) Builder details
See the accepted inputs, generated sections, output formats, and important limits.| Topic | Details | What to know |
|---|---|---|
| Inputs | 6 fields across 3 groups | Every field required by this template is shown before generation. |
| Required inputs | 5 required fields | Unfilled required values remain visible instead of being silently invented. |
| Repeatable sections | 1 repeatable sections | Templates without a row field render each field once. |
| Outputs | HTML, Markdown, embed snippet, and print-ready HTML | Every output is generated from the same validated field values. |
Do I need an account to use Records of Processing Activities (RoPA) Builder?
No. The builder runs without an account.
Does the builder invent missing information?
No. Required gaps remain visibly marked for review.
Is my document stored?
No. The public builder does not save the submitted field values.
Which formats can I download?
The public result supports HTML and Markdown downloads, an embed snippet, and print-to-PDF through the browser.
Who must keep a RoPA?
Controllers and processors each keep one for their own side of the processing — a processor's record covers the categories of processing it carries out for each controller. Where a controller outside the EU has appointed a representative, the representative keeps one too.
Does a small company need a record of processing activities?
Often, yes. The under-250-employee exemption in Article 30(5) is conditional, not automatic: it falls away if the processing is more than occasional, if it could risk people's rights and freedoms, or if it involves special-category or criminal-offence data. Paying staff and running a customer list are regular processing. This builder produces the structure and flags the gaps; it does not give legal advice.