Our own servers in Europe · GDPR · Support in your language

Module 2 of 6 · GDPR · Block 2

Record of processing activities

The record of processing activities (RoPA) is the mandatory inventory of all data processing carried out by the organization.

Content reviewed on

Record contents

Purpose, categories of data and data subjects, recipients, erasure periods, and security measures for each processing activity.

Keeping the record up to date

Periodic review of the record to reflect new processing activities or changes to existing ones.

Controller and processors

Identifying who is the data controller and which processors are involved in each activity.

What an auditor usually asks for

  • Record of processing activities complete
  • Record updated whenever processes change
  • Data processors identified per activity
  • Record available to the supervisory authority

How to cover this block in Kimobox

  1. 1Keep the record of processing activities as a version-controlled record in Kimobox.
  2. 2Link each processing activity to the business process that generates it.
  3. 3Update the record automatically whenever a related process changes.

The record of processing activities stays linked to the company's real processes, not in a standalone document.

See Kimobox's process map

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Regulation (EU) 2016/679, General Data Protection Regulation EUR-Lex · Applicable since 25 May 2018
  2. Organic Law 3/2018 on Data Protection and guarantee of digital rights BOE-A-2018-16673 · 6 December 2018
  3. Spanish Data Protection Agency AEPD · Supervisory authority