SecurSentry
← All notes
UK GDPR

What a Record of Processing Activities (ROPA) Is, and How to Build One

You've been told you need a 'ROPA'. Here's what it actually is, why most small businesses can't skip it, and how to build a simple one from where your data already lives.

The short version

If someone has told you that your business needs a ‘ROPA’ and you’re not sure whether that’s real or just consultancy noise, here’s the honest answer: a record of processing activities is a genuinely useful document, and most small businesses do need one. It sounds like bureaucracy. In practice it’s a tidy list of what personal data your business holds and what you do with it, and once you’ve written it, several other data protection jobs get much easier.

What a record of processing activities actually is

A ROPA is a written inventory of how your business uses personal data: what you hold, why, who you share it with, how long you keep it, and how it’s kept safe.

Strip away the jargon and a ROPA is a map. It answers a handful of plain questions about every way your business touches personal information:

That’s the whole thing. The legal basis sits in Article 30 of the UK GDPR, which calls it ‘records of processing activities’. But you don’t need to read the article to build a good one. You need to know where your data lives and be honest about what you do with it.

A ROPA is the foundation the rest of your GDPR work stands on. Your privacy notice is essentially the public-facing summary of what your ROPA records privately. So the work you do here is never wasted.

Do you really need one? The 250-employee question, honestly

Most small businesses can’t skip the ROPA, because the under-250 exemption is far narrower than it first appears.

This is where a lot of online advice goes wrong, so it’s worth getting right. Article 30 says organisations with 250 or more employees must keep records. Read on quickly and you’d think anyone smaller is off the hook. You’d be wrong.

The ICO, the UK’s data protection regulator, is clear that the relief for smaller organisations is conditional. If you employ fewer than 250 people, you still have to document any processing that is:

Here’s the catch. Keeping employee records, running a customer database, sending marketing emails, operating a website with analytics: none of that is ‘occasional’. It’s the steady, everyday processing every business does. So the moment you have staff on a payroll or a customer list you contact more than once, you’ve almost certainly tripped one of the exceptions.

WHY "EXEMPT" IS THE WRONG WORD

Don't tell yourself you're exempt because you're small. The exemption only covers processing that is occasional and low-risk and free of special-category data, three conditions at once. Holding staff and customer records fails the first test on its own. On top of that, the ICO recommends documenting your processing whether or not you're strictly required to, because it makes everything else easier to get right.

The practical takeaway: assume you need a ROPA. The handful of businesses that genuinely don’t will lose nothing by keeping a short one anyway.

How to build a simple ROPA

Start from where personal data already lives in your business, write down a few facts about each place, and you’ve built most of your ROPA without trying.

You don’t start with a legal template and try to fill it. You start with your own tools. Walk through the places personal data sits in a typical small business:

  1. Your CRM or customer list: customer names, contact details, purchase history.
  2. Email: correspondence with customers, suppliers and staff.
  3. Your accounting and invoicing tool: billing details, sometimes bank information.
  4. Payroll and HR files: staff records, salaries, next of kin, occasionally health data.
  5. Booking, support or e-commerce systems: whatever your business runs on.
  6. Shared drives and cloud storage: the catch-all where documents accumulate.

For each one, write a short row answering the same questions: what data, whose data, why, who it’s shared with, how long you keep it, and roughly how it’s secured. A plain spreadsheet is completely fine as a ROPA template for a small business. You do not need specialist software to be compliant.

The ICO publishes free documentation resources and templates to give you a structure to copy, so you’re not inventing the format from scratch. Use them as a starting frame, then adapt the wording to how your business actually works rather than forcing your reality into someone else’s boxes.

A ROPA isn’t paperwork you do for the regulator. It’s the moment you finally find out, in writing, exactly where your customers’ and staff’s data has ended up.

Two habits make the difference between a ROPA that helps and one that gathers dust. First, keep it honest by recording what you genuinely do, including the messy shared drive, not an idealised version. Second, keep it living. Review it whenever you add a tool, change a supplier or start a new kind of processing. The ICO’s own guidance is that records should be updated every time a process changes or you bring in a new system. A diary reminder once or twice a year catches the rest.

What it gets you back

A ROPA pays for itself the first time you face a subject access request or sit down to write a privacy notice.

The reason to build one isn’t fear of a fine. It’s that a ROPA quietly makes three of the most stressful GDPR jobs easy.

When someone asks for a copy of their data, a subject access request becomes a checklist instead of a panicked hunt through every inbox and folder. You already know the places to look, because you wrote them down. The same record tells you who you’d need to notify if those systems were ever breached, and it hands you most of the content for your privacy notice on a plate.

It’s also the natural companion to your wider documentation. If you’re assembling the basics, a GDPR policy starter pack gives you the policies, and your ROPA gives you the factual ground underneath them. One describes how you intend to behave; the other records what you actually do. Together they’re what ‘accountability’ under UK GDPR really means: being able to show your working.

Build it once, keep it current, and the ROPA stops being a chore on a to-do list and becomes the thing you reach for whenever a data question lands on your desk.

SecurSentry is launching soon to help UK SMEs build and maintain the records that underpin real data protection, including a living record of processing activities that stays current as your business changes. Join the waitlist to be first to know when we open.


This article is general information, not legal or compliance advice. If your processing is complex, or you handle large volumes of special-category data, seek qualified guidance from a data protection professional or solicitor.

Frequently asked questions

What is a record of processing activities (ROPA)?

A ROPA is a written record of how your organisation uses personal data. It lists the categories of data you hold, the purposes you use it for, the categories of people it relates to, who you share it with, how long you keep it, the security measures protecting it, and any transfers outside the UK. The ICO, the UK's data protection regulator, treats it as the foundation of accountability under UK GDPR.

Does a small business with fewer than 250 employees need a ROPA?

Usually yes, in practice. The under-250 relief only applies to processing that is occasional, low-risk, and free of special-category or criminal-offence data. Because keeping staff and customer records is regular and ongoing, most small businesses fall into an exception and must document that processing. The ICO also recommends documenting your processing regardless, as it makes other obligations far easier.

What must a ROPA contain under Article 30?

If you act as a controller, your record should cover your name and contact details, the purposes of processing, the categories of individuals and of personal data, the categories of recipients you share data with, any transfers to other countries, retention periods where possible, and a general description of your security measures. The ICO provides documentation templates to help you capture this.

How do I build a ROPA for my small business?

Start from where personal data actually lives: your CRM, email, accounting tool, payroll, booking system and shared drives. For each one, note what data is held, why, who it's shared with, and how long it's kept. A simple spreadsheet works well. Treat it as a living document and review it whenever a process or tool changes.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

UK GDPR

Personal Data Breach: What a Small Business Must Do

16 Jul 2026 · 6 min
EU AI Act

EU AI Act Timeline: When Each Rule Starts to Bite

13 Jul 2026 · 7 min
Security questionnaires

Security Questionnaire Examples, Explained Simply

10 Jul 2026 · 7 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.