What a Record of Processing Activities (ROPA) Is, and How to Build One
You've been told you need a 'ROPA'. Here's what it actually is, why most small businesses can't skip it, and how to build a simple one from where your data already lives.
The short version
- A ROPA is a written inventory of your processing: what personal data you hold, why, who you share it with, how long you keep it, and how it's protected.
- Most small businesses can't claim the exemption. Under-250-staff relief falls away if your processing is regular, risky, or involves special-category data, which covers nearly everyone with staff and customers.
- You build one from where data already lives: your CRM, email, accounting tool, payroll and shared drives. A simple spreadsheet is a perfectly good start.
- It pays you back. A ROPA turns a subject access request from a scramble into a checklist and makes your privacy notice almost write itself.
If someone has told you that your business needs a ‘ROPA’ and you’re not sure whether that’s real or just consultancy noise, here’s the honest answer: a record of processing activities is a genuinely useful document, and most small businesses do need one. It sounds like bureaucracy. In practice it’s a tidy list of what personal data your business holds and what you do with it, and once you’ve written it, several other data protection jobs get much easier.
What a record of processing activities actually is
A ROPA is a written inventory of how your business uses personal data: what you hold, why, who you share it with, how long you keep it, and how it’s kept safe.
Strip away the jargon and a ROPA is a map. It answers a handful of plain questions about every way your business touches personal information:
- What personal data do you hold? Names, emails, payroll details, customer orders, CCTV footage, and so on, grouped into sensible categories.
- Who does it relate to? Customers, employees, suppliers, job applicants, website enquiries.
- Why do you hold it? The purpose: fulfilling orders, paying staff, marketing, answering support requests.
- Who do you share it with? Your accountant, your email provider, your payroll bureau, HMRC. These are your ‘recipients’.
- How long do you keep it, and how is it protected? Retention periods, and a general note on your security measures.
- Does any of it leave the UK? If a supplier stores data overseas, that’s an international transfer worth recording.
That’s the whole thing. The legal basis sits in Article 30 of the UK GDPR, which calls it ‘records of processing activities’. But you don’t need to read the article to build a good one. You need to know where your data lives and be honest about what you do with it.
A ROPA is the foundation the rest of your GDPR work stands on. Your privacy notice is essentially the public-facing summary of what your ROPA records privately. So the work you do here is never wasted.
Do you really need one? The 250-employee question, honestly
Most small businesses can’t skip the ROPA, because the under-250 exemption is far narrower than it first appears.
This is where a lot of online advice goes wrong, so it’s worth getting right. Article 30 says organisations with 250 or more employees must keep records. Read on quickly and you’d think anyone smaller is off the hook. You’d be wrong.
The ICO, the UK’s data protection regulator, is clear that the relief for smaller organisations is conditional. If you employ fewer than 250 people, you still have to document any processing that is:
- not occasional (in other words, regular or ongoing rather than a genuine one-off), or
- likely to result in a risk to people’s rights and freedoms (anything intrusive or that could adversely affect someone), or
- involves special-category data or criminal-offence data (health, ethnicity, religion, sexual orientation, trade union membership, and similar, or criminal records).
Here’s the catch. Keeping employee records, running a customer database, sending marketing emails, operating a website with analytics: none of that is ‘occasional’. It’s the steady, everyday processing every business does. So the moment you have staff on a payroll or a customer list you contact more than once, you’ve almost certainly tripped one of the exceptions.
WHY "EXEMPT" IS THE WRONG WORD
Don't tell yourself you're exempt because you're small. The exemption only covers processing that is occasional and low-risk and free of special-category data, three conditions at once. Holding staff and customer records fails the first test on its own. On top of that, the ICO recommends documenting your processing whether or not you're strictly required to, because it makes everything else easier to get right.
The practical takeaway: assume you need a ROPA. The handful of businesses that genuinely don’t will lose nothing by keeping a short one anyway.
How to build a simple ROPA
Start from where personal data already lives in your business, write down a few facts about each place, and you’ve built most of your ROPA without trying.
You don’t start with a legal template and try to fill it. You start with your own tools. Walk through the places personal data sits in a typical small business:
- Your CRM or customer list: customer names, contact details, purchase history.
- Email: correspondence with customers, suppliers and staff.
- Your accounting and invoicing tool: billing details, sometimes bank information.
- Payroll and HR files: staff records, salaries, next of kin, occasionally health data.
- Booking, support or e-commerce systems: whatever your business runs on.
- Shared drives and cloud storage: the catch-all where documents accumulate.
For each one, write a short row answering the same questions: what data, whose data, why, who it’s shared with, how long you keep it, and roughly how it’s secured. A plain spreadsheet is completely fine as a ROPA template for a small business. You do not need specialist software to be compliant.
The ICO publishes free documentation resources and templates to give you a structure to copy, so you’re not inventing the format from scratch. Use them as a starting frame, then adapt the wording to how your business actually works rather than forcing your reality into someone else’s boxes.
A ROPA isn’t paperwork you do for the regulator. It’s the moment you finally find out, in writing, exactly where your customers’ and staff’s data has ended up.
Two habits make the difference between a ROPA that helps and one that gathers dust. First, keep it honest by recording what you genuinely do, including the messy shared drive, not an idealised version. Second, keep it living. Review it whenever you add a tool, change a supplier or start a new kind of processing. The ICO’s own guidance is that records should be updated every time a process changes or you bring in a new system. A diary reminder once or twice a year catches the rest.
What it gets you back
A ROPA pays for itself the first time you face a subject access request or sit down to write a privacy notice.
The reason to build one isn’t fear of a fine. It’s that a ROPA quietly makes three of the most stressful GDPR jobs easy.
When someone asks for a copy of their data, a subject access request becomes a checklist instead of a panicked hunt through every inbox and folder. You already know the places to look, because you wrote them down. The same record tells you who you’d need to notify if those systems were ever breached, and it hands you most of the content for your privacy notice on a plate.
It’s also the natural companion to your wider documentation. If you’re assembling the basics, a GDPR policy starter pack gives you the policies, and your ROPA gives you the factual ground underneath them. One describes how you intend to behave; the other records what you actually do. Together they’re what ‘accountability’ under UK GDPR really means: being able to show your working.
Build it once, keep it current, and the ROPA stops being a chore on a to-do list and becomes the thing you reach for whenever a data question lands on your desk.
SecurSentry is launching soon to help UK SMEs build and maintain the records that underpin real data protection, including a living record of processing activities that stays current as your business changes. Join the waitlist to be first to know when we open.
This article is general information, not legal or compliance advice. If your processing is complex, or you handle large volumes of special-category data, seek qualified guidance from a data protection professional or solicitor.