RoPA Software
RoPA Software
How assessment-fed drafting works, what a defensible Article 30 register needs, and how to keep RoPA records current under the EU and UK GDPR.
The governed workflow
From assessed processing to a maintained register
The RoPA stays defensible when each field is tied to the assessment, system or supplier evidence that produced it.
Capture Article 30 fields
Collect purposes, categories, recipients, transfers and safeguards inside the work that already happens.
- Assessment-fed answers
- System and supplier selections
- Controller and processor records
Draft with provenance
Turn approved responses into draft register values that retain their source and confidence context.
- Source-linked fields
- Review state per value
- No auto-published record
Approve and version
Keep every published entry attributable to a named reviewer and a dated decision.
- Named approvals
- Change history
- Entity-scoped snapshots
Keep records current
Surface affected records when suppliers, systems, transfers or retention facts change.
- Transfer updates
- Supplier changes
- Audit-ready exports
RoPA software is the tool a privacy team uses to build, maintain and evidence the Article 30 Records of Processing Activities required by the EU and UK GDPR. A useful RoPA tool does more than store the register — it derives each entry from approved assessments, records where every value came from, and keeps a named human accountable for every change. That distinction — storage versus provenance — matters because the register has to be true, current and attributable when a supervisory authority asks to see it. This guide covers what RoPA software is, why it is a legal requirement, how it works, and what to check before choosing a tool. In Acompli — the worked example used throughout this guide — each Article 30 record is derived from an approved assessment and stays traceable to the evidence behind it.
Key takeaways
- A RoPA is a legal obligation under Article 30 of the EU and UK GDPR; Article 30(1) lists seven mandatory content elements for controllers and Article 30(2) a parallel set for processors.
- The under-250-employee exemption (Article 30(5)) rarely applies in full — it falls away the moment processing is non-occasional or touches special-category or criminal-offence data.
- The real test of RoPA software is provenance, not storage: can it show where each value came from, who approved it, and what changed — the questions a DPC or ICO audit asks.
- The strongest tools keep the register true between reviews by deriving it from approved assessments and surfacing records when the business changes, with a per-transfer Chapter V view after Schrems II (C-311/18).
RoPA software turns Article 30 work into governed records
RoPA software manages the Record of Processing Activities — also called a data processing register, a processing activities register, or simply an Article 30 register — that the GDPR requires every controller and most processors to keep. A spreadsheet can list processing activities, but it stores only what someone last typed. RoPA software treats each activity as a governed record: it carries its purpose, the categories of data and data subjects, recipients, international transfers and safeguards, retention period, security measures and a named owner — and it knows where each of those values came from.
That provenance is the point. When the Data Protection Commission (DPC) in Ireland or the Information Commissioner's Office (ICO) in the UK asks to see the register, the question is not “do you have a document” but “can you show this is true, current, and accountable.” Acompli treats the RoPA as a living governance record rather than a file: approved assessments, supplier changes and transfer reviews feed it through controlled review workflows, so what a regulator inspects matches what the business actually does.
The RoPA workflow in practice
The strongest RoPA software makes the register a downstream output of work you already do, rather than a separate data-entry chore. In Acompli the pipeline runs in four governed stages:
- Capture: Article 30 fields are gathered through structured assessment questions (DPIAs, LIAs, vendor reviews) tagged to the relevant register fields.
- Draft: once an assessment is approved, a multi-phase AI extraction pipeline maps the responses to Article 30 fields, with a confidence score on each field and a link back to the source response.
- Review: draft records enter a review queue where a named person can trace every field to its evidence, then approve, edit or reject it before anything is published.
- Maintain: when an upstream fact changes — a new assessment, a supplier contract, a retired system, an updated transfer safeguard — the affected records surface for review with the change that triggered them.
This is the honest meaning of “RoPA automation”: automation reduces the typing and the chasing, not the accountability. Acompli's AI drafts, classifies and surfaces; a person approves every record, and nothing publishes itself. (See RoPA automation: what it should and shouldn't automate.)
What to look for in a RoPA platform
Whatever the vendor, assess whether the tool can support the evidence you would need to produce with the register itself. The criteria that matter:
- Full Article 30(1) and 30(2) coverage — both controller and processor record types, with the dedicated fields each requires.
- Legal-entity scoping — separate records by entity, country and business unit while keeping group-level visibility, with an entity snapshot preserved at approval time.
- Evidence traceability — every field links back to the assessment, contract or system that produced it, so a claim can be substantiated, not just asserted.
- Reviewer-attributed version history — what changed, who changed it, who approved it, and when.
- A Chapter V transfer view — per transfer, the mechanism (SCCs, adequacy, derogation), the linked Transfer Impact Assessment and supplementary measures, after Schrems II (C-311/18).
- A self-contained export — a record the DPC or ICO can read without a login to your platform.
- Jurisdiction overlays as a rigour signal — the ability to distinguish EU GDPR, UK GDPR (and, where relevant, the German BDSG) correctly on one register is granularity a single-regime tool cannot claim.
For a structured side-by-side of the tool categories against these criteria, see RoPA software compared: what to look for. Acompli meets each of these criteria as standard: Article 30(1) and 30(2) record types scoped per legal entity, every field linked to the assessment or contract that produced it, reviewer-attributed version history, a per-transfer Chapter V view, and a self-contained export the DPC or ICO can read.
Who needs RoPA software?
Any organisation that processes personal data on more than an occasional basis needs a RoPA, and in practice that is almost all of them. Controllers need an Article 30(1) record; processors need an Article 30(2) record for the processing they carry out on behalf of each controller. Smaller organisations are rarely fully exempt, and larger groups need entity-scoped records so each subsidiary can answer its own supervisory authority. Acompli serves both ends of that range: the register scopes from a single legal entity up to a multi-entity group, with per-entity exports so each subsidiary answers its own authority.
Common questions about RoPA software
Primary sources
Related research
RoPA Software Compared
How to compare Article 30 tools by coverage, evidence traceability and exports.
Read article →RoPA Requirements: Ireland & UK
Article 30 requirements under the EU and UK GDPR, with the DPC and ICO compared.
Read article →Article 30 (RoPA) Template
The mandatory controller and processor fields, as a usable Article 30 template.
Read article →Related Acompli workflows
RoPA management
Maintain Article 30 records linked to approved assessments, systems, suppliers and transfers.
Open module →Assessments
Use reviewed DPIAs, LIAs, TIAs and processor assessments as source evidence for RoPA updates.
Open module →Data mapping
Keep systems, locations, suppliers and transfers visible behind each controller or processor record.
Open module →Risk management
Track privacy risks raised by processing activities, safeguards and transfer decisions.
Open module →Compliance software
Related compliance software guides
Pricing scales with your compliance estate — data controllers, legal entities, jurisdictions and integrations — never a per-seat price. See Acompli pricing.