Why you should start with the ROPA (Record of Processing Activities)
The ROPA is not just a compliance document, it is the map of your data. Every other privacy obligation gets easier once it exists.
Most privacy programmes start by drafting a privacy notice without a clear picture of what personal data the business actually holds, where it sits, who it is shared with and why. The Record of Processing Activities, the ROPA, is the document that answers those questions, and it is the foundation everything else should be built on. Starting with this record makes for a much more efficient data protection implementation .
Article 30 of the UK GDPR requires most controllers and processors to maintain a ROPA. But beyond the legal requirement, the practical value is that once you have one, every other privacy task, such as DPIAs, DSARs, vendor reviews, breach response and privacy notices, becomes materially easier.
What a ROPA actually contains
For each processing activity, a controller's ROPA should record: the name and contact details of the controller (and, where relevant, the joint controller, representative and DPO); the purposes of the processing; the categories of data subjects and personal data; the categories of recipients (including any in third countries); details of any international transfers and the safeguards relied on; the retention periods (or the criteria used to set them); and a general description of the technical and organisational security measures.
Processors keep a slightly different version, focused on the controllers they act for and the categories of processing carried out on each controller's behalf.
Why start here?
A ROPA pushes the business to confront the technical questions: what systems hold personal data, who inside the organisation owns each system, which vendors receive data, and on what legal basis.
Once this is in place, it becomes a much simpler task to transpose this information into a privacy policy with the information already thoroughly categorised. DPIAs can also be drafted with a much better understanding of the processing details. A Data Map can also provide a helpful overview of the flows of information across vendors and internaionally.
Who is exempt (and why the exemption rarely helps)?
Article 30(5) exempts organisations with fewer than 250 employees from maintaining a ROPA, unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data. For most SaaS, AI and consumer-facing businesses, the exemption does not apply in practice because the processing is continuous and often involves categories of data that push the business back into scope.
Even where the exemption does apply, maintaining a lightweight ROPA is usually still the right call. The operational benefits do not depend on the legal obligation.
A streamlined way to implement compliance
Building and maintaining a ROPA in spreadsheets works at the outset, but it quickly becomes difficult to keep current as the business adds vendors, features and data sources. Hythe Suite is our compliance management software for UK start-ups and scale-ups, and its Data Protection & Privacy module is designed around the ROPA as the central record.
The effect is that the ROPA stops being a static document, we have enabled cross record automation to enable you to update Processor or Ropa records and pull that information to other records automatically.
Getting help
Hythe Legal advises UK technology and AI companies on UK GDPR compliance, including building and maintaining ROPAs, DPIAs and the wider privacy programme. If you are starting from scratch, preparing for enterprise procurement, or want an existing ROPA reviewed, do get in touch.