UK GDPR Article 30: records of processing activities (RoPA)
“The controller or the processor and, where applicable, the controller’s or the processor’s representative, shall make the record available to the Commissioner on request.” — UK GDPR Article 30(4).
Article 30 is the documentation duty in UK GDPR: a written record of what personal data an organisation processes, why, for whom and for how long. It applies to controllers and processors, it has an exemption for organisations under 250 people that is narrower than it looks, and much of what a customer's due-diligence questionnaire asks can be answered from it. This page quotes the Article and the ICO's guidance on it.
What a controller must record: Article 30(1)
“Each controller and, where applicable, the controller’s representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information:”
| The record shall contain | In practice | |
|---|---|---|
| a | the name and contact details of the controller and, where applicable, the joint controller, the controller’s representative and the data protection officer | Your organisation, any joint controller, representative and DPO |
| b | the purposes of the processing | Why each processing activity happens |
| c | a description of the categories of data subjects and of the categories of personal data | Whose data, and what kinds |
| d | the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations | Who receives it, including abroad |
| e | where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards | International transfers and their safeguards |
| f | where possible, the envisaged time limits for erasure of the different categories of data | Retention periods |
| g | where possible, a general description of the technical and organisational security measures referred to in Article 32(1) or, as appropriate, the security measures referred to in section 28(3) of the 2018 Act | A summary of your security measures |
“Where possible”
Items (f) and (g), retention periods and security measures, are qualified by “where possible”. Everything else is unqualified. The ICO's list of what to document states retention schedules and a description of your security measures without that qualifier.
The link to Article 32
Item (g) points to the security measures in Article 32(1). A general description is enough for the record; the measures themselves are what Article 32 requires.
What a processor must record: Article 30(2)
“Each processor and, where applicable, the processor’s representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing:”
| The processor's record shall contain | |
|---|---|
| a | the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller’s or the processor’s representative, and the data protection officer |
| b | the categories of processing carried out on behalf of each controller |
| c | where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards |
| d | where possible, a general description of the technical and organisational security measures referred to in Article 32(1) or, as appropriate, the security measures referred to in section 28(3) of the 2018 Act |
A processor's record is organised by controller: which customers it processes for, and what kinds of processing. That is why a SaaS supplier's record looks different from its customers' records of the same data. The contract terms a processor works under are on Article 28.
Form, and who can ask for it
“The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.” “The controller or the processor and, where applicable, the controller’s or the processor’s representative, shall make the record available to the Commissioner on request.”
What the ICO expects the record to look like
“The information must be documented in a granular and meaningful way.” “Records must be kept up to date and reflect your current processing activities.” And: “Most organisations will benefit from maintaining their records electronically.”
Why the ICO says it matters beyond the duty itself
“Documenting your processing activities is important, not only because it is itself a legal requirement, but also because it can support good data governance and help you demonstrate your compliance with other aspects of the UK GDPR.”
The 250-employee exemption: Article 30(5)
“The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.”
The ICO's reading
“If you have 250 or more employees, you must document all your processing activities.” “There is a limited exemption for small and medium-sized organisations.” If you have fewer than 250 employees, the ICO says you only need to document processing activities that:
| The processing |
|---|
| are not occasional; or |
| could result in a risk to the rights and freedoms of individuals; or |
| involve the processing of special categories of data or criminal conviction and offence data. |
Why the exemption is narrow (our reading)
The three conditions are joined by “or”. Processing that happens every month — payroll, a customer list, a support inbox — is not occasional, so it has to be recorded whatever the headcount. What the exemption tends to remove is the one-off processing, not the core.
What else the ICO suggests documenting
The ICO says it can be useful to document, or link to, other parts of your compliance as part of the record, including:
| Item |
|---|
| information required for privacy notices |
| records of consent |
| controller-processor contracts |
| the location of personal data |
| Data Protection Impact Assessment reports |
| records of personal data breaches |
Two of those have their own pages here: controller-processor contracts (Article 28) and the design-stage assessments behind Article 25.
How to build the record
“Doing an information audit or data-mapping exercise can help you find out what personal data your organisation holds and where it is.” The ICO also suggests questionnaires, meeting business functions and reviewing policies, procedures, contracts and agreements.
Where ISO 27001 and ISO 27701 fit (our reading)
ISO/IEC 27001 does not require a record of processing activities: its subject is information security, and processing purposes are a privacy question. But some ISO/IEC 27002 controls produce material the record needs. We quote their titles from the standard's contents:
| Article 30 item | Related control (title) |
|---|---|
| Art. 30(1)(c): categories of personal data | 5.9 Inventory of information and other associated assets; 5.12 Classification of information |
| Art. 30(1)(f): time limits for erasure | 5.33 Protection of records; 8.10 Information deletion |
| Art. 30(1)(g): security measures | The Statement of Applicability and the controls it lists |
| The record as a whole | 5.34 Privacy and protection of PII |
The asset inventory is not the record
An ISMS asset inventory lists information and systems; Article 30 lists processing activities and their purposes. A good inventory makes the record faster to build and keep current, but it does not replace it.
ISO/IEC 27701
The privacy extension is written for this: “This document is intended for personally identifiable information (PII) controllers and PII processors holding responsibility and accountability for PII processing.” Its Annex D maps it to the GDPR. See ISO 27701 certification.
If a customer asks for your RoPA
What matters to them (our reading) is the part that covers their data: the processing you do for them, where it happens, who you pass it to, how long you keep it and a summary of your security. As a processor, that is your Article 30(2) record for that controller.
We do not give legal advice, audit or certify, and are paid the same fixed fee per enquiry whichever firm you use. The law is quoted from legislation.gov.uk and the guidance from ico.org.uk; the ISO section and the right-hand column of the first table are our reading.
Where this fits
Common questions
What is a record of processing activities (RoPA)?
The written record UK GDPR Article 30 requires controllers and processors to keep of their processing of personal data. For a controller it must include the purposes, the categories of people and data, the recipients, international transfers, retention periods where possible and a description of the security measures where possible. The ICO calls this “documentation”.
Who has to keep records under Article 30?
Controllers and processors. “If you have 250 or more employees, you must document all your processing activities.” Below 250, Article 30(5) disapplies the duty unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.
Does the small business exemption mean we do not need a RoPA?
Rarely in full. The exemption falls away for processing that is not occasional, and routine processing such as payroll or a customer database is not occasional. That is our reading of Article 30(5) and of the ICO's summary, which says you then document the processing that meets any of the three conditions.
What must a processor record?
Under Article 30(2): its own and each controller's name and contact details (and representatives and DPO), the categories of processing carried out for each controller, international transfers, and where possible a general description of its security measures.
Does the RoPA have to be in a particular format?
No. “The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.” The ICO adds: “Most organisations will benefit from maintaining their records electronically.” and “We have developed basic templates to help you document your processing activities.”
Who can ask to see our records?
The Information Commissioner. “The controller or the processor and, where applicable, the controller’s or the processor’s representative, shall make the record available to the Commissioner on request.” A customer may ask for parts of it too, but that is a contractual request, not an Article 30 right.
Has the Data (Use and Access) Act 2025 changed Article 30?
Not the text: legislation.gov.uk showed no outstanding changes to Article 30 when we read it on 30 September 2026. The ICO's guidance carries this notice: “Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change.”
Does ISO 27001 require a record of processing activities?
No. ISO/IEC 27001 is about information security, not about recording processing purposes. Its asset inventory control overlaps with parts of the record. ISO/IEC 27701, the privacy extension, is where processing records sit in the ISO family.
Sources cited on this page
- UK GDPR Article 30 (Records of processing activities), legislation.gov.uk
- ICO, Documentation (Guide to accountability and governance)
- UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
- ISO/IEC 27002:2022, official preview (contents, foreword, introduction, clauses 1–3), read first-hand
- ISO/IEC 27701:2025, Privacy information management systems — Requirements and guidance, official preview (foreword, introduction, clauses 1–3, contents), read first-hand
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
A customer asked for your records of processing?
Say whether you act as controller or processor, and what they asked for.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.