Records of Processing
Records of Processing Activities are internal documents in which an organisation describes what personal data it handles, why, and how. Under the GDPR, they capture details such as the purposes of processing, the categories of data and individuals involved, and how long data is kept. They serve as evidence that an organisation understands and can account for its data processing, and must be provided to a supervisory authority on request.
Records of Processing (RoPA) are the documentation that controllers and, where applicable, processors are required to maintain under Article 30 of the EU GDPR (and the UK GDPR). Article 30 prescribes the specific information the records must contain, which generally includes the purposes of processing, categories of data subjects and personal data, categories of recipients, retention periods, and applicable safeguards, with the content differing between controller records and processor records (the latter covering categories of processing carried out on behalf of a controller). The records must be kept current to reflect the organisation's actual processing and must be capable of being made available to the relevant supervisory authority (such as the ICO in the UK or the DPC in Ireland) on request. RoPA is an accountability instrument; it does not itself establish a lawful basis or authorise processing, and Article 30 includes conditions that may narrow the obligation for certain organisations. Scope note: this entry addresses the EU/UK GDPR Article 30 obligation and does not cover analogous record-keeping requirements that may exist under US state privacy laws or other regimes, which differ in form and application.
Why it matters
Records of Processing Activities are a cornerstone of the GDPR's accountability principle. Under Article 30, controllers and, where applicable, processors are generally required to document what personal data they handle, why, and how, and they must be in a position to provide those records to the relevant supervisory authority on request. In practice, this means RoPA is often one of the first documents a data protection authority such as the ICO or the DPC may ask to see when reviewing an organisation's compliance posture, making it a tangible test of whether an organisation actually understands its own processing.
For cookie and tracking contexts, RoPA matters because the personal data collected through cookies, pixels, SDKs, and similar technologies typically constitutes processing that should be reflected in the records. Where consent or another lawful basis is relied upon for such processing under the GDPR, maintaining accurate records helps an organisation demonstrate that it can account for the purposes, data categories, and retention periods involved. RoPA does not itself establish a lawful basis or authorise any processing; it is an evidentiary and governance instrument rather than a permission.
Because the records must reflect the organisation's actual, current processing rather than a one-off snapshot, outdated or incomplete records can undermine an organisation's ability to respond credibly to a supervisory authority. Article 30 also includes conditions that may narrow the obligation for certain organisations, so the practical scope of the requirement depends on facts specific to each organisation.
Who it's relevant to
Inside RoPA
Common questions
Answers to the questions practitioners most commonly ask about RoPA.

