ComplyChat Start free

Guide · Data protection

Record of processing activities

A record of processing activities (ROPA) is the written register that Article 30 of the UK GDPR requires a controller to keep of its processing of personal data – the purposes, the categories of people and data, the recipients, any international transfers, the retention periods and the security measures – and to make available to the ICO on request; an organisation with fewer than 250 employees need record only processing that is not occasional, is likely to result in a risk, or involves special category or criminal offence data, which in practice covers most of what schools, charities and care providers do.

By ComplyChatPublished 12 minute read

A multi-academy trust’s data protection officer and a school business manager talk with the first aider in a primary school medical room, a treatment couch and a closed wall cupboard behind them

It is the least visible data protection document and the one the others depend on. The privacy notice, the retention schedule, the response to a subject access request and the assessment of a breach all start from knowing what personal data the organisation holds and why. This guide covers what Article 30 requires, who must keep a record, how to build one and how to keep it true.

01

The rule: Article 30 of the UK GDPR

Article 30 of the UK General Data Protection Regulation (UK GDPR) says: "Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility." The record must contain seven things: the name and contact details of the controller (and any joint controller, representative and data protection officer); "the purposes of the processing"; "a description of the categories of data subjects and of the categories of personal data"; the categories of recipients, including any in other countries; any transfers to a third country or international organisation, with the safeguards documented where required; "where possible, the envisaged time limits for erasure of the different categories of data"; and, where possible, a general description of the technical and organisational security measures.

Three further paragraphs complete the rule. Processors keep their own, shorter record of "the categories of processing carried out on behalf of each controller" (Article 30(2)); as the ICO puts it, "Controllers and processors both have documentation obligations." The records "shall be in writing, including in electronic form" (30(3)). And the controller or processor "shall make the record available" to the regulator "on request" (30(4)). The ICO calls the whole exercise documentation, and its guidance on documentation says it matters "not only because it is itself a legal requirement, but also because it can support good data governance and help you demonstrate your compliance with other aspects of the UK GDPR".

The Data (Use and Access) Act 2025 has amended UK GDPR in stages, but as at 3 October 2026 legislation.gov.uk records one change to Article 30 linked to it: from 30 September 2026, Article 30(4) refers to the "Commission", the Information Commission that replaced the office of Information Commissioner that day. The content of the record and the small-organisation exception are unchanged. The ICO's documentation pages carry a banner saying the guidance "is under review and may be subject to change" because of the Act, and list their latest update as 19 May 2023, so check the date on the page before relying on it.

02

Who must keep one: the fewer-than-250 exception

Article 30(5) – which the ICO calls "a limited exemption for small and medium-sized organisations" – is the paragraph most organisations rely on, and most read too generously. It says the obligations "shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10".

So the exception is for processing, not for organisations. The ICO's guidance on who needs to document their processing activities puts it plainly: "If you employ fewer than 250 people, you need only document processing activities that" are "not occasional (e.g., are more than just a one-off occurrence or something you do rarely)", are "likely to result in a risk to the rights and freedoms of individuals", or "involve special category data or criminal conviction and offence data". Its worked example is a company of 100 staff that "regularly processes personal data in the context of processing claims, sales and HR" and so "must still document these types of processing activities because they are not occasional", while an occasional staff survey can be left out.

Apply that to the sectors this site writes for:

  • A school processes pupils' records, attendance, SEN and medical information and safeguarding records every day; all of it is regular and much of it special category data.
  • A care provider processes health and care records about every person it supports, which is special category data, plus staff records and criminal record check information.
  • A charity with a regular service, a supporter database or staff payroll processes personal data that is not occasional, and often beneficiaries' health or other special category data.
  • A small club or group that keeps a members' list and little else may fall within the exception for some of its processing, but the ICO says "it is still good practice" to document it anyway.

The headcount is employees, not volunteers or service users, and the exception never removes the other duties: the privacy notice, the retention decisions and the security measures still have to exist, and the ROPA is the simplest place to keep them.

03

What goes in the record, and how granular it must be

The ICO's summary of what Article 30 requires is: the organisation's name and contact details; the purposes of processing; the categories of individuals and of personal data; the categories of recipients; transfers to third countries and their safeguards; retention schedules; and a description of technical and organisational security measures. Where the organisation processes special category or criminal offence data under a Schedule 1 condition of the Data Protection Act 2018 that requires an appropriate policy document, paragraph 41 of Schedule 1 adds three entries: "which condition is relied on", how the processing satisfies Article 6, and "whether the personal data is retained and erased in accordance with the policies" in the appropriate policy document, with reasons if not.

The record must link these things together, not list them. The ICO says: "A generic list of pieces of information with no meaningful links between them will not meet the UK GDPR's documentation requirements." A spreadsheet with one column of every category of person and another of every category of data fails; one row per purpose, showing which people, which data, which recipients and which retention period belong to that purpose, works. For example (fictional):

  • Purpose: staff administration. People: employees and their emergency contacts. Data: contact and bank details, sickness records (health – special category), DBS check details (criminal offence data). Recipients: payroll bureau, HMRC, pension scheme. Retention: per the staff records schedule. Security: HR system with role-based access.
  • Purpose: delivering the support service. People: service users and their families. Data: contact details, needs assessments, health information. Recipients: referring local authority, GP where agreed. Retention: per the case records schedule. Security: case system, restricted to the support team.

The ICO also suggests documenting, or linking to, the information that does not have to be in the record but is easier to manage beside it: the lawful basis and any legitimate interests, the information needed for privacy notices, records of consent, controller-processor contracts, "the location of personal data", data protection impact assessment reports and records of personal data breaches. Most organisations find the lawful basis column indispensable; our guide to data retention policies covers how to set the retention periods the record points to.

04

How to build a record of processing activities

The ICO's guidance on how to document processing activities starts with "an information audit or data-mapping exercise" and "senior management buy-in", then three steps:

  1. Ask every team six questions. The ICO's examples: "Why do you use personal data?", "Who do you hold information about?", "What information do you hold about them?", "Who do you share it with?", "How long do you hold it for?" and "How do you keep it safe?"
  2. Meet the people who know. The IT lead for security measures, whoever manages records for retention, and whoever signs contracts and data sharing agreements.
  3. Read the paperwork. Privacy notices, the data protection, retention and security policies, processor contracts and sharing agreements – which the ICO says helps "compare and contrast intended and actual data processing activities".

Organise the result by function – the ICO suggests starting "with a business function – e.g. HR, Sales, Customer Services" – so a school might use admissions, teaching and assessment, pastoral and safeguarding, SEN, workforce and governance; a care provider care delivery, staffing, referrals and finance; a charity services, volunteers, supporters and staff. The Department for Education's guidance for schools on data protection policies and procedures (updated 9 July 2026) lists where personal data may be stored, including "management information systems", "communication systems", "safeguarding technology", "photo and video storage systems" and "paper records and photos", which is a good checklist for any sector.

The ICO publishes free spreadsheet templates, one for controllers and one for processors, and says "Using these templates is not mandatory." It also says that "Paper documentation may be adequate for very small organisations whose processing activities rarely change", but most organisations will find a spreadsheet or their compliance software easier to keep current.

At a hospice’s summer fete on the lawn, the data protection lead talks with the head of fundraising beside a cake stall while visitors queue for tea under bunting
05

Keeping it current, and who owns it

The ICO is clear that the record is not finished when it is written: "Keeping a record of your processing activities is not a one-off exercise; the information you document must reflect the current situation as regards the processing of personal data. So you should treat the record as a living document." In practice that means three habits:

  • Update on change. A new system, supplier, service, data sharing arrangement or use of AI adds or changes a row before the processing starts – the same point at which the privacy notice must change.
  • Review on a cycle. At least once a year, each team confirms its rows are still true, and anything that has stopped is removed.
  • Report to the board. The DfE's guidance tells schools to share the record "with your school leadership team (SLT) and governors or trustees", who "are responsible for ensuring your school is compliant". The same is good practice for charity trustees and care providers' boards.

Give the record one owner – the data protection officer where there is one, otherwise a named data protection lead – and a date of last review on its front sheet. When the ICO asks for it under Article 30(4), or a subject access request or a breach requires the organisation to know quickly what it holds and where, the record is only as useful as its last honest review. Our guide to a charity's data protection policy sets out how the record fits with the policy, the notices and the breach log.

06

The processing nobody put in the register

Ask a team the ICO's six questions and they will describe the systems the organisation chose: the MIS, the care planning system, the supporter database, the HR system. They rarely mention the place where much of their personal data now moves. A teaching assistant tells colleagues in the staff group chat that a pupil has been sick and why. A care team shares a resident's change in condition in a WhatsApp group so the night shift knows. A charity coordinator posts the week's home visits, with names and addresses, to the volunteers' group. That is processing of personal data, often special category data, carried out for the organisation's purposes, and it is not occasional.

Try writing the row. Purpose: coordinating care, teaching or support. People: pupils, residents, service users, staff. Data: names, health information, safeguarding concerns. Recipients: every member of the group, on personal phones. Retention: unknown – messages stay until each person deletes them. Security: whatever each handset has. Location: a consumer app the organisation does not run and cannot search. A record of processing activities cannot honestly describe that row, which is usually the sign that the processing needs to change rather than the record.

The fix is to give work messages a place the organisation controls, so the row can be completed: a known service, a retention period the organisation sets and members told that the channel is on the record. ComplyChat is built for that, with messages stored and processed in the UK, a mobile number verified by SMS as the identity so staff and volunteers without a work account can take part, and on paid plans a lasting record that files into the organisation's own Microsoft 365 under its own retention rules once its tenant is connected. It is not a ROPA tool and does not write the record for you.

A question for the next leadership or board meeting: does our record of processing activities include the messaging groups staff and volunteers use for work, and could we fill in the retention and security columns for them truthfully?

07

Questions people ask

Who needs to complete a RoPA?

Every controller and processor under the UK GDPR must keep a record of processing activities, except that an organisation employing fewer than 250 people need record only processing that is not occasional, is likely to result in a risk to individuals, or involves special category or criminal offence data (Article 30(5)). Regular processing such as payroll, HR, pupil records or care records is not occasional, so most schools, charities with staff or regular services, and care providers need one.

Is ROPA mandatory in GDPR?

Yes, subject to the small-organisation exception. Article 30(1) of the UK GDPR says each controller "shall maintain a record of processing activities under its responsibility", Article 30(3) requires it in writing, and Article 30(4) requires it to be made available to the regulator on request. The ICO's guidance says documenting processing "is itself a legal requirement".

What is a RoPA used for?

A RoPA is used to show what personal data an organisation processes, why, who receives it, how long it is kept and how it is protected, which is how the organisation demonstrates accountability under the UK GDPR. It is also the working source for privacy notices, retention schedules, subject access request searches, breach assessments and data protection impact assessments, and the ICO can ask to see it.

Can you provide an example of a record of processing activities?

The ICO publishes free spreadsheet templates for controllers and processors on its documentation guidance pages. A single row for a fictional employer might read: purpose, staff administration; individuals, employees and emergency contacts; data, contact and bank details and sickness records; recipients, the payroll bureau, HMRC and the pension scheme; retention, the staff records schedule; security, an access-controlled HR system. Section three of this guide gives a second example.

08

Official guidance and your next step

The primary sources are Article 30 of the UK GDPR, paragraphs 38 to 41 of Schedule 1 to the Data Protection Act 2018, the ICO's documentation guidance and templates, and, for schools, the DfE's data protection policies and procedures guidance. Quotations are from those pages as read on 3 October 2026. Several ICO pages are under review following the Data (Use and Access) Act 2025, so check the date on the page you use.

This guide is a practical summary, not legal advice. An organisation that processes special category or criminal offence data at scale, shares data with statutory services or uses data in new ways should involve its data protection officer or take professional advice.

Then do one thing: send each team leader the ICO's six questions, ask them to answer for every place personal data sits – including the group chats and personal phones used for work – and compare the answers with the current record.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. A record of processing activities can only describe processing the organisation can see, and in schools, charities and care providers a great deal of personal data moves through staff and volunteer messages. The organisational record described here is on paid plans; Free is personal messaging with one private group, direct messages and three calendar months of recent history, and it is not a way to meet a retention duty.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Article 30 of the UK General Data Protection Regulation (UK GDPR) legislation.gov.uk
  2. Guidance on documentation ico.org.uk
  3. Who needs to document their processing activities ico.org.uk
  4. Paragraph 41 of Schedule 1 legislation.gov.uk
  5. How to document processing activities ico.org.uk
  6. Data protection policies and procedures gov.uk