RoPA Software

RoPA Software

How assessment-fed drafting works, what a defensible Article 30 register needs, and how to keep RoPA records current under the EU and UK GDPR.

See the RoPA module

The governed workflow

From assessed processing to a maintained register

The RoPA stays defensible when each field is tied to the assessment, system or supplier evidence that produced it.

01Capture
02Draft
03Review
04Structure
05Report
06Maintain

Capture Article 30 fields

Collect purposes, categories, recipients, transfers and safeguards inside the work that already happens.

  • Assessment-fed answers
  • System and supplier selections
  • Controller and processor records

Draft with provenance

Turn approved responses into draft register values that retain their source and confidence context.

  • Source-linked fields
  • Review state per value
  • No auto-published record

Approve and version

Keep every published entry attributable to a named reviewer and a dated decision.

  • Named approvals
  • Change history
  • Entity-scoped snapshots

Keep records current

Surface affected records when suppliers, systems, transfers or retention facts change.

  • Transfer updates
  • Supplier changes
  • Audit-ready exports

RoPA software is the tool a privacy team uses to build, maintain and evidence the Article 30 Records of Processing Activities required by the EU and UK GDPR. A useful RoPA tool does more than store the register — it derives each entry from approved assessments, records where every value came from, and keeps a named human accountable for every change. That distinction — storage versus provenance — matters because the register has to be true, current and attributable when a supervisory authority asks to see it. This guide covers what RoPA software is, why it is a legal requirement, how it works, and what to check before choosing a tool. In Acompli — the worked example used throughout this guide — each Article 30 record is derived from an approved assessment and stays traceable to the evidence behind it.

Key takeaways

  • A RoPA is a legal obligation under Article 30 of the EU and UK GDPR; Article 30(1) lists seven mandatory content elements for controllers and Article 30(2) a parallel set for processors.
  • The under-250-employee exemption (Article 30(5)) rarely applies in full — it falls away the moment processing is non-occasional or touches special-category or criminal-offence data.
  • The real test of RoPA software is provenance, not storage: can it show where each value came from, who approved it, and what changed — the questions a DPC or ICO audit asks.
  • The strongest tools keep the register true between reviews by deriving it from approved assessments and surfacing records when the business changes, with a per-transfer Chapter V view after Schrems II (C-311/18).

RoPA software turns Article 30 work into governed records

RoPA software manages the Record of Processing Activities — also called a data processing register, a processing activities register, or simply an Article 30 register — that the GDPR requires every controller and most processors to keep. A spreadsheet can list processing activities, but it stores only what someone last typed. RoPA software treats each activity as a governed record: it carries its purpose, the categories of data and data subjects, recipients, international transfers and safeguards, retention period, security measures and a named owner — and it knows where each of those values came from.

That provenance is the point. When the Data Protection Commission (DPC) in Ireland or the Information Commissioner's Office (ICO) in the UK asks to see the register, the question is not “do you have a document” but “can you show this is true, current, and accountable.” Acompli treats the RoPA as a living governance record rather than a file: approved assessments, supplier changes and transfer reviews feed it through controlled review workflows, so what a regulator inspects matches what the business actually does.

The RoPA workflow in practice

The strongest RoPA software makes the register a downstream output of work you already do, rather than a separate data-entry chore. In Acompli the pipeline runs in four governed stages:

  • Capture: Article 30 fields are gathered through structured assessment questions (DPIAs, LIAs, vendor reviews) tagged to the relevant register fields.
  • Draft: once an assessment is approved, a multi-phase AI extraction pipeline maps the responses to Article 30 fields, with a confidence score on each field and a link back to the source response.
  • Review: draft records enter a review queue where a named person can trace every field to its evidence, then approve, edit or reject it before anything is published.
  • Maintain: when an upstream fact changes — a new assessment, a supplier contract, a retired system, an updated transfer safeguard — the affected records surface for review with the change that triggered them.

This is the honest meaning of “RoPA automation”: automation reduces the typing and the chasing, not the accountability. Acompli's AI drafts, classifies and surfaces; a person approves every record, and nothing publishes itself. (See RoPA automation: what it should and shouldn't automate.)

What to look for in a RoPA platform

Whatever the vendor, assess whether the tool can support the evidence you would need to produce with the register itself. The criteria that matter:

  • Full Article 30(1) and 30(2) coverage — both controller and processor record types, with the dedicated fields each requires.
  • Legal-entity scoping — separate records by entity, country and business unit while keeping group-level visibility, with an entity snapshot preserved at approval time.
  • Evidence traceability — every field links back to the assessment, contract or system that produced it, so a claim can be substantiated, not just asserted.
  • Reviewer-attributed version history — what changed, who changed it, who approved it, and when.
  • A Chapter V transfer view — per transfer, the mechanism (SCCs, adequacy, derogation), the linked Transfer Impact Assessment and supplementary measures, after Schrems II (C-311/18).
  • A self-contained export — a record the DPC or ICO can read without a login to your platform.
  • Jurisdiction overlays as a rigour signal — the ability to distinguish EU GDPR, UK GDPR (and, where relevant, the German BDSG) correctly on one register is granularity a single-regime tool cannot claim.

For a structured side-by-side of the tool categories against these criteria, see RoPA software compared: what to look for. Acompli meets each of these criteria as standard: Article 30(1) and 30(2) record types scoped per legal entity, every field linked to the assessment or contract that produced it, reviewer-attributed version history, a per-transfer Chapter V view, and a self-contained export the DPC or ICO can read.

Who needs RoPA software?

Any organisation that processes personal data on more than an occasional basis needs a RoPA, and in practice that is almost all of them. Controllers need an Article 30(1) record; processors need an Article 30(2) record for the processing they carry out on behalf of each controller. Smaller organisations are rarely fully exempt, and larger groups need entity-scoped records so each subsidiary can answer its own supervisory authority. Acompli serves both ends of that range: the register scopes from a single legal entity up to a multi-entity group, with per-entity exports so each subsidiary answers its own authority.

Common questions about RoPA software

What is Record of Processing Activities (RoPA) software?

RoPA software is the tool a privacy team uses to build, maintain and evidence the Records of Processing Activities required by Article 30 of the EU and UK GDPR. Rather than store the register in a spreadsheet, it treats each processing activity as a governed record — with its purposes, data categories, recipients, transfers, retention and security measures — and keeps a named owner accountable for every change. In Acompli, those records are derived from approved assessments and stay traceable to the evidence behind them.

Why do businesses need RoPA software?

Almost every organisation needs a RoPA because Article 30 of the EU and UK GDPR makes it a legal obligation, and a supervisory authority can request the record on demand. RoPA software keeps that record current and audit-ready instead of relying on a spreadsheet that drifts out of date between reviews — which a regulator reads as weak accountability under Article 5(2).

How does RoPA software work?

Good RoPA software turns the register into a downstream output of work you already do. In Acompli, approved assessments (DPIAs, LIAs, vendor reviews) are read by a multi-phase AI extraction pipeline that drafts Article 30 fields with a confidence score and a link back to the source response; a named reviewer approves, edits or rejects each draft before it reaches the published register. The AI drafts and classifies; a person approves — nothing publishes itself.

What should RoPA software include?

A defensible RoPA tool should cover both Article 30(1) controller records and Article 30(2) processor records, scope records by legal entity, link each field back to the assessment or contract that produced it, preserve reviewer-attributed version history, show Chapter V transfer safeguards after Schrems II, and produce a self-contained export a regulator can read without logging into the platform.

What is the difference between RoPA software and a spreadsheet?

A spreadsheet stores what someone last typed; a governed register knows where every value came from. RoPA software keeps each field's source assessment, extraction confidence and approval chain, preserves every version, and surfaces records for review when the business changes — the things a shared file cannot do, and the first things a DPC or ICO auditor asks about.

Is RoPA software the same as a data processing register or an Article 30 register?

Yes — a RoPA register, a data processing register, a processing activities register and a GDPR Article 30 register are all names for the same record that Article 30 requires. RoPA software is the tool that maintains it as a governed register rather than a static file.

Is RoPA software suitable for organisations of all sizes?

Yes. Organisations of every size need a RoPA because the Article 30(5) under-250-employee exemption rarely applies in full — most employee, customer and supplier processing is recurring rather than occasional, and any special-category or criminal-offence data removes the relief. Acompli scopes the register from a single legal entity up to a multi-entity group, with per-entity exports so each subsidiary can answer its own supervisory authority.

Does RoPA software handle both controller and processor registers?

It should. Article 30(1) requires a controller record and Article 30(2) requires a parallel processor record with its own fields. Acompli maintains both record types on one platform, scoped by legal entity and operating role (controller, joint controller, processor, sub-processor), and preserves an entity snapshot at approval time so historical records reflect the structure that existed when the activity was approved.

How should RoPA software support Ireland and the UK?

Organisations operating under both the EU and UK GDPR need a register that distinguishes the two regimes without creating a separate file per jurisdiction. The software should support full Article 30(1) controller and Article 30(2) processor coverage, legal-entity scoping, evidence traceability, Chapter V transfer safeguards, and exports that the Data Protection Commission (DPC) in Ireland or the Information Commissioner's Office (ICO) in the UK can read without platform access. Acompli maintains EU and UK GDPR overlays on one governed register, scoped per legal entity, with per-entity exports.

How does RoPA software discover the personal data it records?

There are two approaches. Most tools run automated scanners across databases and cloud systems and infer the processing activities from what they find — fast, but the register then reflects what a scanner inferred rather than a decision someone is accountable for. Acompli works the other way round: each Article 30 record is derived from approved assessments (DPIAs, legitimate-interest assessments, vendor reviews) and the Knowledge Base entities — systems, processors, storage locations and transfers — selected during those assessments, so every field traces back to a human-approved source. Where code-level evidence helps, the Code Scan add-on reads nominated repositories for personal-data signals, processor SDKs and transfer indicators, and a named reviewer confirms each finding before it reaches the register. The result is a record grounded in approved decisions and verifiable evidence rather than an unattributed scan output.

What is the best RoPA software?

The best RoPA software is decided less by field count than by whether the register is defensible: whether it covers both Article 30(1) controller and 30(2) processor records, scopes them by legal entity, preserves reviewer-attributed version history, links Chapter V transfers to their Transfer Impact Assessments, and exports evidence that still traces back to the decision behind each field. Acompli's angle is to govern these as connected, human-approved records tied to the wider GDPR and EU AI Act programme, each field traceable to the approved assessment, supplier record or transfer evidence that produced it. If you want to weigh the field neutrally, the RoPA software comparison guide and our full comparison library lay out public-source capability tables and side-by-side vendor breakdowns, and are candid about where rival tools outperform Acompli.

Compliance software

Related compliance software guides

Pricing scales with your compliance estate — data controllers, legal entities, jurisdictions and integrations — never a per-seat price. See Acompli pricing.