RoPA Example for a SaaS Company: Controller and Processor Records
A SaaS company may act as controller for its own subscriber billing and as processor for customer content. Keep the records and role analysis separate. These filled examples show useful fields and owners; copying them does not prove that a real company's processing is documented.

Record the role for each processing activity
A record of processing activities (RoPA) describes actual processing under an organisation's responsibility. The GDPR sets different information fields for controllers and processors under Article 30. A SaaS provider can hold both types of record, depending on the activity; the contractual label alone is not a substitute for analysing who determines purposes and means.
The fictional company Cedarboard Cloud sells a project-management subscription. It decides why it uses subscriber contacts for billing, but handles project files on customer instructions. Its two illustrative records below should be adapted to a real service, contract and retention schedule.
Illustrative controller record: subscriber billing
This example intentionally omits real people and customer names. It is a model of the field structure, not a completed compliance assessment.
| Field | Filled fictional example |
|---|---|
| Purpose / people | Subscription billing and account administration / customer administrators |
| Data / recipients | Business contact, invoices and payment reference / billing provider and authorised finance team |
| Transfer / retention | Check provider access locations / retain according to documented tax and dispute schedule |
| Security / owner | Role-based access and invoice audit trail / finance lead; quarterly review |
Illustrative processor record: customer project files
The processor record should describe categories of processing carried out for each controller and other Article 30(2) fields. Keep a route to the customer instructions and sub-processor schedule. Do not simply duplicate the controller's billing entry.
| Field | Filled fictional example |
|---|---|
| Controller / service | Customer organisation / project workspace hosting |
| Categories of processing | Store, retrieve, back up and delete project files on documented instructions |
| Transfers / recipients | List relevant hosting and support entities; verify remote access |
| Security / owner | Encryption, access review and restore test / platform lead; update on supplier change |
Keep records tied to the live service
Link the RoPA to the data-flow map, contracts, notices, retention configuration and supplier list. Assign owners who can confirm changes when a new feature or provider launches. Where information is uncertain, mark it for verification instead of filling a template with assumptions.
Article 30 includes a limited derogation for some organisations with fewer than 250 people, but the conditions need assessment and are often misunderstood. Do not assume that company size alone removes the need for records.
Frequently asked questions
Can a SaaS company have both controller and processor records?
Yes. Its role can differ by activity. For example, it may decide its own billing purpose while processing customer files on the customer's instructions.
Can I copy these RoPA rows into my register?
Use them as a field example only. Replace the fictional facts with verified data flows, recipients, retention, transfers, safeguards and owners for your organisation.
Keep researching
Related resources
A practical next step
Make the next privacy decision clearer
Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.
This guide provides general information, not legal advice or a conclusion that a particular obligation applies. Confirm the legal scope and practical next steps against your organisation's facts.
Sources: EUR-Lex: GDPR, EDPB: Be compliant
