A Record of Processing Activities (ROPA) is a legal requirement under UK GDPR Article 30. It documents every way your organisation processes personal data — what data you collect, why you collect it, who has access, where it is stored, how long you keep it, and who you share it with.
All organisations that process personal data must maintain a ROPA unless they employ fewer than 250 people AND their processing is only occasional, does not include special category data, and is unlikely to result in a risk to individuals. In practice, almost all UK organisations with any regular data processing should maintain one.
Each entry in Folelse's ROPA represents one processing activity. Entries are linked to your information assets (the systems storing the data), your suppliers (third-party processors), and your services. This linkage means changes in one place automatically update your ROPA.
The ICO can request to inspect your ROPA at any time. Keeping it accurate and up to date is one of the most important accountability measures you can take.
Need more help with this?
Contact support