New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

GDPR & privacy

Records of processing (RoPA)

The record of processing activities is the document that demonstrates you know what personal data you hold, why you hold it, and how long you keep it. It is typically the first thing a supervisory authority asks for.

Transcript

The record of processing activities is the Article 30 document: the foundational GDPR document, and usually the first thing a supervisory authority asks for.

Open Governance & Docs and switch to the Documents tab. The document generator produces regulator-ready documents from your registered systems and organisation profile.

Open a system's documents to see its full set, including the records of processing that describe how its personal data is handled.

Generate the record of processing. The platform assembles it from the system's registered details: the data categories, lawful basis, retention, and transfers.

Preview the generated document. It reflects your actual configuration, not a template, so what is on paper matches what you registered.

Download it as a PDF when it is ready, and keep it with the rest of the system's documentation set for inspection.

Because the record is generated from live data, keeping the system register accurate keeps the RoPA accurate, with no separate spreadsheet to drift out of date.

Why this is required

Article 30 requires the record in writing, including in electronic form, and requires you to make it available to the supervisory authority on request. The exemption for organisations under 250 employees is narrow: it falls away where processing is likely to result in a risk to rights and freedoms, is not occasional, or includes special category data, which covers most organisations deploying AI at any scale.

Article 30(1) lists what a controller's record must contain: the name and contact details of the controller, the purposes of processing, the categories of data subjects and personal data, the categories of recipients, any transfers to third countries and their safeguards, the envisaged retention periods, and a general description of the technical and organisational security measures.

Retention periods are where most organisations struggle, because Article 30 forces a decision they have usually avoided. Article 5(1)(e) requires storage limitation: personal data must be kept in identifiable form no longer than necessary for the purposes it was collected for. Writing 'as long as required' in a record does not satisfy it.

The record is also the practical enabler for everything else. You cannot answer an access request completely, assess a breach's scope, or honour an erasure request if you do not know where the data is.

What EuroCompliant does

Processing activities are recorded with purpose, lawful basis, data categories, data subject categories, recipients, transfers and retention.

Because AI systems are registered with the data they process, their processing activities feed the record directly rather than living in a separate spreadsheet that drifts out of date.

The record generates as an Article 30 document for the supervisory authority, alongside UK GDPR and CCPA equivalents where those frameworks are enabled.

Walking through it

1

Record activities, not systems

One system frequently supports several processing activities with different purposes, bases and retention periods. Model the activity.

Open /privacy-hub →
2

State a real retention period

A duration or a defined trigger, not 'as needed'. Article 5(1)(e) requires storage limitation and this is where you evidence it.

3

Capture recipients and transfers

Including processors and any transfer outside the EEA with the Chapter V safeguard relied on.

4

Review it periodically

The record is only useful if it is current. Revisit it whenever a system, purpose or vendor changes.

The law

Frequently asked

Are we exempt because we have fewer than 250 employees?

Rarely in practice. The Article 30(5) exemption does not apply where processing is likely to result in a risk to rights and freedoms, where it is not occasional, or where it involves special category or criminal conviction data. Regular processing of customer or employee data is not occasional.

Does training an AI model need its own entry?

Yes, if it uses personal data. Training is a distinct purpose from the operational use of the resulting system, with its own lawful basis and retention analysis, so it should be recorded as its own activity.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial