GDPR Article 30 states that data controllers and processors must create and maintain records of data processing activities (ROPA).
While most companies processing data from EU citizens must create ROPA, there are a few exceptions. ROPA are not required if a companyâs data processing is:
These exceptions leave a fairly narrow group of organizations who are actually exempt. Most organizations that process personal data are doing so more than occasionally.
And, with no further explanation as to what ânot occasionalâ meansâin most cases itâs better to create the ROPA and ensure GDPR compliance.
Complete ROPA must include:
Learn more about ROPA and the practical application of Article 30.