GDPR Records of Processing (ROPA) Builder
Build your Article 30 record of processing activities in the browser and export it to CSV.
How to use this tool
Add one row per processing activity (payroll, CCTV, newsletter, CRM and so on) and fill in the fields Article 30(1) requires: purposes, categories of data subjects and personal data, recipients, transfers to third countries, retention periods and security measures. Three editable examples are pre-filled. Data is saved only in your browser; export to CSV or print to PDF for your records and keep the file under version control.
Worked example
A "CCTV at premises" row: purpose security of people and property; data subjects employees and visitors; data video images; recipients installer (processor) and police on lawful request; retention 72 hours; measures role-based access, encryption and audit log.
Frequently asked questions
What is a record of processing activities?
A written record, required by Article 30 GDPR, that describes how an organisation processes personal data: purposes, data subjects, data categories, recipients, transfers, retention and security measures. Supervisory authorities can request it.
Do small companies need one?
Article 30(5) exempts organisations with fewer than 250 employees only if the processing is occasional, unlikely to result in a risk, and does not involve special categories of data. In practice that exemption rarely applies, so most organisations keep a record.
What is the difference between controller and processor records?
Controllers record their own processing activities (Article 30(1)); processors record the categories of processing carried out on behalf of each controller (Article 30(2)). This tool is aimed at controller records.
Is my data stored on your servers?
No. It stays in your browser storage until you export it.