Skip to content

Privacy Hub · plain-language reference

← Guides

accountability

What is a RoPA?

Updated 19 Jul 2026

What is a RoPA?

A Record of Processing Activities (RoPA) is an inventory of every way your organisation uses personal data. It is required under UK GDPR Article 30 and is treated as evidence of accountability under Zimbabwe's CDPA.

What a RoPA records, per activity

  • The purpose of processing.
  • The categories of data subjects and categories of personal data.
  • The recipients — including cross-border transfers and their safeguards.
  • The retention period or the criteria used to determine it.
  • A general description of the technical and organisational security measures.

Why it matters even when the law does not force you

  • It surfaces silent third-party data-sharing you did not know you were doing.
  • It is the first thing a regulator asks for after a breach.
  • It is the artefact that lets anyone in the organisation answer "why do we have this data?" without guessing.

A RoPA is not a policy. It is a live register. Spreadsheets are fine to start; the discipline of keeping it current is the whole exercise.


Looking for something practical? Explore the free privacy tools.