Compliance

ROPA Article 30 Generator

Build an Article 30 record of processing activities from your activity list, with every mandatory field checked, gaps flagged, and a copyable record in the structure supervisory authorities expect.

Last reviewed by the Radiatus Cloud team

The record appears here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

The record is the first thing a supervisory authority asks for

Article 30 requires controllers and processors to maintain a written record of processing activities and to make it available to the authority on request. It is asked for early in almost every investigation, because it is the fastest way to establish whether an organisation knows what it does with personal data. An organisation that cannot produce one within a day has usually revealed more than the record itself would have.

The exemption is narrower than it looks

Article 30(5) exempts organisations with fewer than 250 employees, but only where the processing is occasional, is not likely to result in a risk to rights and freedoms, and does not include special category or criminal offence data. Those conditions are cumulative and the second is met by almost nothing an operating business does. Payroll alone is regular rather than occasional, so in practice the exemption applies to very few organisations that process anything at all.

Controllers and processors record different things

A controller's record covers purposes, categories of data subject and data, recipients, transfers, retention periods and security measures. A processor's record is shorter: the controllers it acts for, the categories of processing carried out on each one's behalf, transfers and security measures. An organisation acting in both capacities needs both records, and conflating them produces a document that satisfies neither obligation.

Related tools

Frequently Asked Questions

Am I exempt if I have fewer than 250 employees?

Only if the processing is also occasional, unlikely to result in a risk, and free of special category or criminal offence data. Those conditions are cumulative, and payroll alone is regular rather than occasional, so very few operating businesses qualify.

What must a controller record contain?

Contact details, purposes, categories of data subject and personal data, categories of recipient, third-country transfers with the safeguard used, retention periods where possible, and a general description of security measures.

Is a processor record different?

Yes, and shorter: the controllers it acts for, the categories of processing performed for each, transfers with safeguards, and security measures. An organisation acting in both capacities needs both records.

Does the record have to be in a particular format?

No format is prescribed, only that it is written, including electronic form, and can be made available to the authority on request. A spreadsheet is acceptable; not having one is not.

Does this send my data anywhere?

No. The record is built in your browser and nothing is transmitted.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter your processing activities to build the record.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.