EU GDPR service
Records of Processing Activities Support
Build a processing record that reflects how the organisation actually uses personal data and supports wider privacy decisions.
A practical service built around your evidence
A useful record of processing activities connects business purposes, systems, data, people, recipients, locations, safeguards, retention, and accountable owners. It should help answer operational questions rather than exist only as a static spreadsheet.
We help design the record, gather information from the right teams, resolve inconsistent descriptions, and establish a maintenance process so material changes are captured after the initial exercise.
Service outputs
What you receive
The exact scope is confirmed before work begins. These are the core outputs normally used to turn the review into accountable action.
RoPA structure
A usable record design with fields, definitions, owners, and completion guidance.
Stakeholder interviews
Structured information gathering from the teams that understand the processing.
Quality review
Checks for gaps, duplication, conflicting descriptions, and unsupported assumptions.
Maintenance workflow
Change triggers, review dates, accountable owners, and evidence expectations.
How we work with your team
Confirm the scope
We agree the business question, processing, stakeholders, locations, deadlines, and evidence needed for a useful review.
Gather reliable evidence
We collect the relevant records, system and vendor information, existing documents, and input from accountable teams.
Complete the review
We test the current position, make assumptions explicit, resolve inconsistencies, and identify practical improvements.
Deliver and maintain
You receive decision-ready outputs, prioritised actions, accountable owners, and clear triggers for future review.
How we help
See how this service fits your organisation
Use the sections below to understand what we review, what you receive, what your team provides, and how you can keep the result useful after delivery.
01 · Fit
Is Records of Processing Activities support right for your organisation?
If your processing inventory is missing, stale, inconsistent, or difficult to use, this service helps you build a working source of facts. It can support a customer review, DPO appointment, product launch, transfer assessment, acquisition, or broader accountability programme.
A RoPA is useful when the organisation needs to explain its processing to itself, customers, management, or an authority. It can start with a new business, a fragmented inventory, an acquisition, a customer diligence cycle, or a programme where purpose and ownership are no longer clear. The value is the relationship between activities, systems, owners, recipients, and evidence.
02 · Decision
What you will be able to decide
The record should help the organisation decide what processing exists, who owns it, why it happens, where data goes, how long it stays, and which safeguards and rights processes support it. A useful RoPA is a working source of facts, not a spreadsheet completed once for an audit.
The work helps you decide which processing activities belong in scope, how to describe them accurately, where gaps are material, and which owner should maintain each record. It also gives a foundation for notices, DPIAs, transfers, retention, security questions, and rights handling. A RoPA should reflect the operation, not merely reproduce department names or a global spreadsheet.
03 · Trigger
When to bring us in
New systems, vendors, acquisitions, product launches, customer diligence, incidents, and staff turnover expose gaps in inventories. Teams may use different names for the same processing or describe the intended flow while the actual system, retention, and access path has changed.
04 · Evidence
What we need from your team
The work uses business processes, systems, data flows, purposes, data and people categories, recipients, locations, retention, safeguards, rights, transfers, vendors, and owners. Interviews are helpful, but records should be checked against architecture, contracts, product documentation, and operating evidence.
We gather information from product and service owners, system inventories, vendor and contract records, HR and customer processes, privacy notices, transfer assessments, retention schedules, and security documentation. The important test is whether each activity has a purpose, data category, affected people, recipient, location, retention idea, and accountable owner supported by a source.
05 · People
Who should join the work
Business and process owners are essential because they understand why the activity exists. Privacy coordinates definitions and quality; technology, security, procurement, HR, marketing, sales, and customer teams confirm their areas. Leadership resolves ownership gaps when a process crosses functions.
06 · Method
How we will work together
We choose a workable structure, set definitions, gather records, resolve duplication and gaps, validate the result, and establish a change workflow. Starting with your priority product or business process often produces a better model than asking the whole company for perfect data at once.
The deliverable can be a structured register, evidence map, gap list, owner workflow, review calendar, and instructions for new activities. We can align the record to your existing systems where practical instead of creating a second inventory. The team should know how a release, supplier, process change, or incident updates the relevant row and who approves it.
07 · Output
What you will receive
Outputs can include the record structure, completed priority entries, field definitions, quality findings, ownership map, evidence links, review dates, change triggers, and maintenance guidance. The format should match the systems and skills the company can actually use.
08 · Friction
What can make this harder
RoPAs fail when they are written by one team without interviews, copy policy language without system detail, or use fields that no owner understands. A long inventory with unclear definitions can be less useful than a smaller record with reliable ownership and evidence.
09 · Maintenance
How you keep it current
Link updates to new systems, vendors, products, purposes, locations, data categories, incidents, and retention changes. Use scheduled sampling as well as change triggers. The record should be part of onboarding and change management, not a separate annual project.
A RoPA should be updated by change, not only by an annual reminder. Connect review to new products, vendors, purposes, data categories, recipients, transfers, retention, incidents, and organisational changes. Sample records periodically to test whether the description still matches the system and whether the named owner can explain the activity.
10 · Boundaries
What stays with your organisation
A RoPA does not prove that every processing activity is lawful or that the listed controls operate. It is an accountability record and an input to other decisions. The organisation remains responsible for validation, approvals, notices, security, and implementation.
11 · Scope
What to prepare before you start
Choose the first scope, name the process owners, gather the current inventory or spreadsheets, identify the systems used, and state the next deadline. Decide whether you need a focused build, a clean-up, or an ongoing maintenance workflow.
- Processing activities, purposes, and affected people
- Systems, vendors, recipients, locations, and transfers
- Retention, security, notices, and source evidence
- Owner workflow for new and changed activities
- Review triggers and sample-check routine
12 · Buyer brief
What your first working brief should contain
Start the RoPA with activities the business can explain, not department labels copied from an organisation chart. For each activity, collect purpose, affected people, data categories, systems, recipients, locations, vendors, transfers, retention, security, notice, and accountable owner. Use product, customer, HR, procurement, and system evidence together. If a record cannot be supported by a source or an owner, mark the gap. That is more useful than filling every field with a confident but unverified description.
Give the register a maintenance route before declaring it complete. A new product, vendor, purpose, data category, transfer, retention choice, incident, or organisational change should reach the person who can update the relevant activity. Sample records later with the system owner and compare the row with the live operation. Use the RoPA to support notices, DPIAs, transfer work, requests, and customer answers, but keep accountability for the processing with the controller or processor.
13 · First test
What we will test first
The first RoPA period tests a representative set of processing activities against systems, purposes, people, data, recipients, locations, vendors, transfers, retention, security, notices, and owners. We identify records that cannot be explained or supported and prioritise the gaps that affect other work. Give the register a source and maintenance route before treating it as complete. Link new activities and changes to product, procurement, HR, security, and incident routines. Sample the rows later with system owners to confirm the descriptions remain true. A RoPA should help the organisation answer questions and maintain notices, DPIAs, transfers, and risk work; it is not an inventory that stays accurate without owners.
14 · Working record
How the result stays usable
A useful result has a home after delivery. Keep the source evidence, decision, owner, scope, open actions, and next review together in a register, project record, contract file, or management routine that your team already uses. The format can be short; it just needs to make the next action and the reason for reopening the question visible. That is how professional input stays connected to the business instead of becoming a document that no one can find when the facts change.
15 · Progress
How you can judge progress
Judge progress by what your team can use and explain. Look for a supported decision, an owner who understands the action, a route that works in practice, and evidence that the agreed output reached the right system, notice, contract, ticket, or meeting. A large document or a high-level score is not enough on its own. The stronger signal is fewer repeated questions, clearer escalation, and a review date that responds to actual change.
16 · Proportion
What a proportionate scope looks like
A proportionate scope should leave you with enough detail to act and enough clarity to know what remains outside the work. We will ask for the facts that can change the answer, explain material uncertainty, and keep specialist dependencies visible. You should be able to tell a manager what was reviewed, an operating owner what to do next, and a future reviewer what event would reopen the question. That balance protects your budget and makes the result more likely to stay useful after delivery.
17 · Handoff
What remains with your organisation
Your organisation remains responsible for the processing, resources, implementation, and final business decision. We can review the supplied facts, provide professional direction, prepare agreed outputs, and make open issues easier to act on. Bring in security, technical, employment, communications, or specialist legal expertise when the question needs it. Before you buy, name the decision, evidence, owner, deadline, and boundary so the selected scope is proportionate and easy to judge.
In practice
See what you can expect
Each view shows a different part of the buyer journey: the evidence, decision, working route, safeguards, and review point behind the service.






Frequently asked questions
Can you work with our current spreadsheet or platform?
Yes. We can improve an existing format where it is workable or recommend a clearer structure if the current model blocks reliable maintenance.
Who should own each record?
Ownership normally sits with a business or process owner who understands the activity, supported by privacy, legal, security, and technology stakeholders.
How often should records be reviewed?
Use both scheduled reviews and change triggers so new systems, vendors, purposes, data, or locations are captured when they arise.
Related European Union services
EU Data Breach Management
Structured EU data breach assessment, documentation, response coordination, and supervisory-authority communication support.
EU Data Protection Impact Assessment Support
Practical EU DPIA support for high-risk projects, including scoping, evidence gathering, risk analysis, and documented recommendations.
EU GDPR Compliance Programme
Build a practical EU GDPR compliance programme with clear priorities, ownership, documentation, controls, and review routines.
EU International Data Transfer Support
Map EU data transfers, review transfer mechanisms, assess practical safeguards, and maintain decision-ready transfer documentation.
Discuss the scope before you commit
Tell us what changed, what evidence you already have, and which decision or deadline the work needs to support.
Service information is general and does not replace advice based on the facts of a specific matter. Final scope, responsibilities, and deliverables are confirmed in the service documentation.
