GDPR & privacy
Records of processing (RoPA)
The record of processing activities is the document that demonstrates you know what personal data you hold, why you hold it, and how long you keep it. It is typically the first thing a supervisory authority asks for.
Transcript
The record of processing activities is the Article 30 document: the foundational GDPR document, and usually the first thing a supervisory authority asks for.
Open Governance & Docs and switch to the Documents tab. The document generator produces regulator-ready documents from your registered systems and organisation profile.
Open a system's documents to see its full set, including the records of processing that describe how its personal data is handled.
Generate the record of processing. The platform assembles it from the system's registered details: the data categories, lawful basis, retention, and transfers.
Preview the generated document. It reflects your actual configuration, not a template, so what is on paper matches what you registered.
Download it as a PDF when it is ready, and keep it with the rest of the system's documentation set for inspection.
Because the record is generated from live data, keeping the system register accurate keeps the RoPA accurate, with no separate spreadsheet to drift out of date.
Why this is required
Article 30 requires the record in writing, including in electronic form, and requires you to make it available to the supervisory authority on request. The exemption for organisations under 250 employees is narrow: it falls away where processing is likely to result in a risk to rights and freedoms, is not occasional, or includes special category data, which covers most organisations deploying AI at any scale.
Article 30(1) lists what a controller's record must contain: the name and contact details of the controller, the purposes of processing, the categories of data subjects and personal data, the categories of recipients, any transfers to third countries and their safeguards, the envisaged retention periods, and a general description of the technical and organisational security measures.
Retention periods are where most organisations struggle, because Article 30 forces a decision they have usually avoided. Article 5(1)(e) requires storage limitation: personal data must be kept in identifiable form no longer than necessary for the purposes it was collected for. Writing 'as long as required' in a record does not satisfy it.
The record is also the practical enabler for everything else. You cannot answer an access request completely, assess a breach's scope, or honour an erasure request if you do not know where the data is.
What EuroCompliant does
Processing activities are recorded with purpose, lawful basis, data categories, data subject categories, recipients, transfers and retention.
Because AI systems are registered with the data they process, their processing activities feed the record directly rather than living in a separate spreadsheet that drifts out of date.
The record generates as an Article 30 document for the supervisory authority, alongside UK GDPR and CCPA equivalents where those frameworks are enabled.
Walking through it
Record activities, not systems
One system frequently supports several processing activities with different purposes, bases and retention periods. Model the activity.
Open /privacy-hub →State a real retention period
A duration or a defined trigger, not 'as needed'. Article 5(1)(e) requires storage limitation and this is where you evidence it.
Capture recipients and transfers
Including processors and any transfer outside the EEA with the Chapter V safeguard relied on.
Review it periodically
The record is only useful if it is current. Revisit it whenever a system, purpose or vendor changes.
The law
Records of processing activities
A written record maintained by the controller and made available to the supervisory authority on request.
Required contents
Purposes, categories of data subjects and data, recipients, third-country transfers, retention periods and a general description of security measures.
Storage limitation
Personal data kept in identifiable form no longer than necessary for the purposes processed.
Processor
Processor relationships must be recorded and governed by a written contract.
Frequently asked
Are we exempt because we have fewer than 250 employees?
Rarely in practice. The Article 30(5) exemption does not apply where processing is likely to result in a risk to rights and freedoms, where it is not occasional, or where it involves special category or criminal conviction data. Regular processing of customer or employee data is not occasional.
Does training an AI model need its own entry?
Yes, if it uses personal data. Training is a distinct purpose from the operational use of the resulting system, with its own lawful basis and retention analysis, so it should be recorded as its own activity.
Related guides
GDPR & privacy
How data protection obligations run alongside the AI Act, and the parts of the GDPR that carry operational consequences.
Registering your systems
Building the system inventory that every other obligation attaches to, covering both AI and conventional systems, and deciding correctly what counts as an AI system.
Data subject requests (DSARs)
Tracking Articles 15 to 22 requests against the one-month statutory clock, including the automated-decision right that bites hardest on AI.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial