iso27001partnersUK certification, costed Get a cost estimate

UK GDPR Article 30: records of processing activities (RoPA)

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 30 September 2026
By the iso27001partners.co.uk editorial team · Published 30 September 2026 · Last reviewed 30 September 2026 · 9 min read
5 primary sources cited on this page. How we check what is on this site
On request To the Commissioner

“The controller or the processor and, where applicable, the controller’s or the processor’s representative, shall make the record available to the Commissioner on request.” — UK GDPR Article 30(4).

Article 30 is the documentation duty in UK GDPR: a written record of what personal data an organisation processes, why, for whom and for how long. It applies to controllers and processors, it has an exemption for organisations under 250 people that is narrower than it looks, and much of what a customer's due-diligence questionnaire asks can be answered from it. This page quotes the Article and the ICO's guidance on it.

What a controller must record: Article 30(1)

“Each controller and, where applicable, the controller’s representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information:”

UK GDPR Article 30(1) (verbatim) and what each item means in practice (our summary)
The record shall containIn practice
athe name and contact details of the controller and, where applicable, the joint controller, the controller’s representative and the data protection officerYour organisation, any joint controller, representative and DPO
bthe purposes of the processingWhy each processing activity happens
ca description of the categories of data subjects and of the categories of personal dataWhose data, and what kinds
dthe categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisationsWho receives it, including abroad
ewhere applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguardsInternational transfers and their safeguards
fwhere possible, the envisaged time limits for erasure of the different categories of dataRetention periods
gwhere possible, a general description of the technical and organisational security measures referred to in Article 32(1) or, as appropriate, the security measures referred to in section 28(3) of the 2018 ActA summary of your security measures

“Where possible”

Items (f) and (g), retention periods and security measures, are qualified by “where possible”. Everything else is unqualified. The ICO's list of what to document states retention schedules and a description of your security measures without that qualifier.

The link to Article 32

Item (g) points to the security measures in Article 32(1). A general description is enough for the record; the measures themselves are what Article 32 requires.

What a processor must record: Article 30(2)

“Each processor and, where applicable, the processor’s representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing:”

UK GDPR Article 30(2), verbatim
The processor's record shall contain
athe name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller’s or the processor’s representative, and the data protection officer
bthe categories of processing carried out on behalf of each controller
cwhere applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards
dwhere possible, a general description of the technical and organisational security measures referred to in Article 32(1) or, as appropriate, the security measures referred to in section 28(3) of the 2018 Act

A processor's record is organised by controller: which customers it processes for, and what kinds of processing. That is why a SaaS supplier's record looks different from its customers' records of the same data. The contract terms a processor works under are on Article 28.

Form, and who can ask for it

“The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.” “The controller or the processor and, where applicable, the controller’s or the processor’s representative, shall make the record available to the Commissioner on request.”

What the ICO expects the record to look like

“The information must be documented in a granular and meaningful way.” “Records must be kept up to date and reflect your current processing activities.” And: “Most organisations will benefit from maintaining their records electronically.”

Why the ICO says it matters beyond the duty itself

“Documenting your processing activities is important, not only because it is itself a legal requirement, but also because it can support good data governance and help you demonstrate your compliance with other aspects of the UK GDPR.”

The 250-employee exemption: Article 30(5)

“The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.”

The ICO's reading

“If you have 250 or more employees, you must document all your processing activities.” “There is a limited exemption for small and medium-sized organisations.” If you have fewer than 250 employees, the ICO says you only need to document processing activities that:

ICO: processing a smaller organisation must still document (verbatim)
The processing
are not occasional; or
could result in a risk to the rights and freedoms of individuals; or
involve the processing of special categories of data or criminal conviction and offence data.

Why the exemption is narrow (our reading)

The three conditions are joined by “or”. Processing that happens every month — payroll, a customer list, a support inbox — is not occasional, so it has to be recorded whatever the headcount. What the exemption tends to remove is the one-off processing, not the core.

What else the ICO suggests documenting

The ICO says it can be useful to document, or link to, other parts of your compliance as part of the record, including:

ICO: documentation to keep with, or link from, the record (verbatim)
Item
information required for privacy notices
records of consent
controller-processor contracts
the location of personal data
Data Protection Impact Assessment reports
records of personal data breaches

Two of those have their own pages here: controller-processor contracts (Article 28) and the design-stage assessments behind Article 25.

How to build the record

“Doing an information audit or data-mapping exercise can help you find out what personal data your organisation holds and where it is.” The ICO also suggests questionnaires, meeting business functions and reviewing policies, procedures, contracts and agreements.

Where ISO 27001 and ISO 27701 fit (our reading)

ISO/IEC 27001 does not require a record of processing activities: its subject is information security, and processing purposes are a privacy question. But some ISO/IEC 27002 controls produce material the record needs. We quote their titles from the standard's contents:

Article 30 items and ISO/IEC 27002:2022 controls whose titles relate to them (our reading)
Article 30 itemRelated control (title)
Art. 30(1)(c): categories of personal data5.9 Inventory of information and other associated assets; 5.12 Classification of information
Art. 30(1)(f): time limits for erasure5.33 Protection of records; 8.10 Information deletion
Art. 30(1)(g): security measuresThe Statement of Applicability and the controls it lists
The record as a whole5.34 Privacy and protection of PII

The asset inventory is not the record

An ISMS asset inventory lists information and systems; Article 30 lists processing activities and their purposes. A good inventory makes the record faster to build and keep current, but it does not replace it.

ISO/IEC 27701

The privacy extension is written for this: “This document is intended for personally identifiable information (PII) controllers and PII processors holding responsibility and accountability for PII processing.” Its Annex D maps it to the GDPR. See ISO 27701 certification.

If a customer asks for your RoPA

What matters to them (our reading) is the part that covers their data: the processing you do for them, where it happens, who you pass it to, how long you keep it and a summary of your security. As a processor, that is your Article 30(2) record for that controller.

We do not give legal advice, audit or certify, and are paid the same fixed fee per enquiry whichever firm you use. The law is quoted from legislation.gov.uk and the guidance from ico.org.uk; the ISO section and the right-hand column of the first table are our reading.

Where this fits

Common questions

What is a record of processing activities (RoPA)?

The written record UK GDPR Article 30 requires controllers and processors to keep of their processing of personal data. For a controller it must include the purposes, the categories of people and data, the recipients, international transfers, retention periods where possible and a description of the security measures where possible. The ICO calls this “documentation”.

Who has to keep records under Article 30?

Controllers and processors. “If you have 250 or more employees, you must document all your processing activities.” Below 250, Article 30(5) disapplies the duty unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.

Does the small business exemption mean we do not need a RoPA?

Rarely in full. The exemption falls away for processing that is not occasional, and routine processing such as payroll or a customer database is not occasional. That is our reading of Article 30(5) and of the ICO's summary, which says you then document the processing that meets any of the three conditions.

What must a processor record?

Under Article 30(2): its own and each controller's name and contact details (and representatives and DPO), the categories of processing carried out for each controller, international transfers, and where possible a general description of its security measures.

Does the RoPA have to be in a particular format?

No. “The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.” The ICO adds: “Most organisations will benefit from maintaining their records electronically.” and “We have developed basic templates to help you document your processing activities.”

Who can ask to see our records?

The Information Commissioner. “The controller or the processor and, where applicable, the controller’s or the processor’s representative, shall make the record available to the Commissioner on request.” A customer may ask for parts of it too, but that is a contractual request, not an Article 30 right.

Has the Data (Use and Access) Act 2025 changed Article 30?

Not the text: legislation.gov.uk showed no outstanding changes to Article 30 when we read it on 30 September 2026. The ICO's guidance carries this notice: “Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change.”

Does ISO 27001 require a record of processing activities?

No. ISO/IEC 27001 is about information security, not about recording processing purposes. Its asset inventory control overlaps with parts of the record. ISO/IEC 27701, the privacy extension, is where processing records sit in the ISO family.

Sources cited on this page

  1. UK GDPR Article 30 (Records of processing activities), legislation.gov.uk
  2. ICO, Documentation (Guide to accountability and governance)
  3. UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
  4. ISO/IEC 27002:2022, official preview (contents, foreword, introduction, clauses 1–3), read first-hand
  5. ISO/IEC 27701:2025, Privacy information management systems — Requirements and guidance, official preview (foreword, introduction, clauses 1–3, contents), read first-hand

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

A customer asked for your records of processing?

Say whether you act as controller or processor, and what they asked for.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now