Record of Processing Activities · GDPR Article 30

RoPA software that keeps Article 30 records linked to the work behind them

Build, maintain and evidence your Article 30 register without living in a spreadsheet. Every record stays connected to the approved assessments, systems, suppliers, transfers and review history that justify it.

Owners, review dates, version control and audit-ready exports — for every processing activity, in every legal entity.

On this page
01
The RoPA workflow

From first capture to ongoing maintenance

Each stage adds governance. By the time a record is published, it carries its source evidence, review history, and organisational scope — and stays tied to the assessment work that produced it. Acompli runs all seven stages inside one register, from first capture through ongoing maintenance.

Capture & link

Capture Article 30 fields from structured assessment work or import existing registers.

  • Assessment templates pre-tag DPIAs, LIAs and TIAs to Article 30 fields.
  • Excel, CSV and SharePoint imports bring legacy registers under control.
  • AI column mapping suggests field mapping and data types before commit.

Draft & extract

Acompli's AI extracts and structures Article 30 information from approved assessments.

Confidence scores show what is complete and what needs review.

Review & structure

Review drafts in context, adjust values and approve before publication.

  • Linked context traces every field to the source assessment response.
  • Role-based approvals keep draft, review and published states controlled.
  • Version control shows what changed, who changed it and when.

Report & maintain

Keep records current as your business changes.

  • Regulator-ready exports support Article 30(1), 30(2), per-entity and provenance reports.
  • System and supplier updates propagate changes to affected records.
  • Transfer reviews safeguard renewal and expiry monitoring.

Detailed stage walkthrough

StartChoose your approach

Assessment-linked or import existing

Start from structured assessment work — where Article 30 fields are captured as assessments are completed — or import an existing register from Excel or CSV and move it into a more governed environment.

Teams already maintaining a spreadsheet can import with AI-assisted column mapping that suggests Article 30 field assignments. Preview before committing.

Assessment Templates

DPIAs, LIAs, TIAs — each template pre-tags which questions map to Article 30 fields.

Excel, CSV & SharePoint import

Import from an Excel document, CSV, or directly from SharePoint, OneDrive, or Google Drive. AI-powered column mapping suggests Article 30 field assignments.

AI Template Builder

Describe your processing activity — Acompli generates a tailored assessment with RoPA fields pre-tagged.

01Capture

Gather Article 30 fields through structured questions

Assessment templates are configured so the relevant Article 30 information is captured as part of the assessment workflow.

Each question can be tagged to one or more Article 30 fields at template level. When assessors answer questions about legal basis, data categories, retention, recipients, and transfers, those responses become the source material for draft RoPA records.

Legal basisArt. 6 lawful basis and Art. 9 conditions for special categories
Data categoriesPersonal data types processed, including special categories
RecipientsCategories of recipients including processors and third countries
Retention periodsEnvisaged time limits for erasure of different data categories
TransfersInternational transfers and safeguards under Chapter V (Art. 44–49)
Security measuresTechnical and organisational measures under Art. 32
02Draft

Approved assessments become draft RoPA records

Once an assessment is completed and approved, Acompli's AI reads the responses and maps them to Article 30 fields. Each field receives a confidence score showing how strong the match is.

Draft records are prepared as outputs for review — not treated as final by default. Every extracted field links back to the source assessment response for traceability, so reviewers can see exactly where each value came from.

Draft RoPA — Employee Monitoring System
Processing purposeHigh
Lawful basis (Art. 6)High
Data categoriesHigh
Retention periodsMedium
Recipients & processorsLinked
International transfersHigh
Security measures (Art. 32)Medium
Extraction →Assessment responses are mapped to Article 30 fields, each with a confidence score
03Review

Review before anything reaches the register

Draft records enter a dedicated review queue. Reviewers can trace every field back to the assessment response that produced it, adjust values, and approve or request changes before anything is added to the published register. In Acompli, that review queue is the only route into the published register.

Changes, review actions, and approvals are recorded so teams can see how a record reached its current form. Only authorised users can approve records for publication, supporting a clearer governance process.

Linked assessment context

Every extracted field traces to the source question and response — reviewers see the evidence, not just the value.

Controlled approval

Only authorised users can approve records for publication. Draft, review, and published states are formally tracked.

Audit trail

Every change, review action, and approval is recorded — see how any record reached its current form.

Record lifecycle
DraftIn ReviewPublishedArchived
04Structure

Entity-scoped records for real operating structures

Processing activities can be scoped by legal entity and operating role — controller, joint controller, processor, or sub-processor — rather than forced into a single flat register.

Organisations that act in both controller and processor capacities can maintain both from a single register. Controller snapshots preserve entity details at the time of approval for historical accuracy. In Acompli, that snapshot is taken at the moment of approval, so historical exports reflect the structure that existed at the time.

Legal entity scoping

Activities managed per legal entity. Multi-entity organisations maintain separate registers under a single programme.

Controller and processor roles

Maintain Article 30(1) controller records and Article 30(2) processor records with dedicated fields for each.

Controller snapshots

Entity details preserved at approval time. Historical records reflect the organisational structure when the activity was approved.

05Report

Reviewable Article 30 reports on demand

Generate Article 30 reports per entity, by processing role, or across the full programme. Export filtered records when needed for audit, governance reviews, or supervisory authority queries. Acompli generates the Article 30(1) and 30(2) reports from the live register, so an export always matches what reviewers approved.

Reports are generated from a maintained register with full provenance. Each entry carries its source assessment, extraction confidence, and approval chain.

Controller

Article 30(1) report

Full controller register — purposes, legal bases, categories, recipients, transfers, retention, and security measures.

Processor

Article 30(2) report

Processor register — categories of processing, transfers, and security measures for each controller relationship.

Entity

Per-entity export

Filtered by legal entity for organisations operating across multiple jurisdictions and structures.

Audit

Provenance report

Trace each field to its source assessment, extraction confidence, reviewer actions, and approval chain.

06Maintain

Records update when the business does

When a new assessment is approved, a supplier contract changes, a system is retired, or a transfer safeguard is updated, affected RoPA entries surface for review as changes occur.

Configurable review cycles flag records approaching their review date. When upstream changes affect a published entry, Acompli surfaces it in the review queue with the specific change that triggered it. Every version is preserved, so teams can trace how a record evolved over time.

RoPA
New assess­ments
System changes
Supplier updates
Transfer reviews

How RoPA software works, in seven steps

  1. Choose approachStart from structured assessments, or import an existing register from Excel or CSV.
  2. CaptureArticle 30 fields are gathered through the assessment’s structured questions.
  3. DraftApproved assessments become draft RoPA records, each field carrying a confidence score.
  4. ReviewReviewers trace every field to its source response and approve before it reaches the register.
  5. StructureRecords are scoped by legal entity and operating role, not forced into one flat list.
  6. ReportArticle 30 reports generate per entity, by processing role, or across the whole programme.
  7. MaintainAffected records reopen for review when assessments, suppliers, systems or transfers change.
02

Article 30 lineage

Article 30 fields are assembled from governed sources

This shows the technical difference between a RoPA spreadsheet and a defensible register: purpose, lawful basis, recipients, transfers and retention stay linked to approved source records.

Approved sources

  • DPIA & LIA answers
  • Vendor reviews
  • Data map systems
  • Storage locations
  • Retention schedule
Extraction + named reviewConfidence-scored drafts; a person approves each field

Article 30 fields

  • Processing purpose
  • Lawful basis
  • Recipients
  • Transfers & safeguards
  • Retention period

Every published field keeps a link back to the approved source that produced it.

03

Maintenance loop

A live register reopens when source facts change

This makes the maintenance problem visible: supplier updates, system changes, transfer safeguard expiry and new assessments all need to reopen the affected Article 30 records for review.

  1. 01Source fact changesSupplier, system, safeguard or assessment
  2. 02Impact checkWhich records rely on that fact?
  3. 03Records reopenAffected Article 30 entries are flagged
  4. 04Review & republishNamed approval, new version in history

The register stays live between reviews — not rebuilt once a year

04

The Article 30 answer

What is Record of Processing Activities (RoPA) software?

RoPA software is the tool a privacy team uses to build, maintain and evidence the Records of Processing Activities required by Article 30 of the EU and UK GDPR. It replaces the static spreadsheet with governed records: each processing activity carries its purpose, data categories, data subjects, recipients, international transfers and safeguards, retention period, security measures and a named owner.

What separates RoPA software from a spreadsheet is provenance: Acompli treats the register as a living governance record where every field knows where it came from and who approved it. Approved assessments, supplier changes, data-mapping updates and transfer reviews feed it through controlled review workflows — so what the DPC or ICO inspects matches what the business actually does. For the full category guide, see RoPA software: what it is, how it works, and what to look for.

Key takeaways

  • A RoPA is legally required for almost every controller and processor — Article 30 of the EU GDPR (in Ireland via the Data Protection Act 2018) and of the UK GDPR. The under-250-employee exemption rarely applies in practice.
  • Keep it current and complete — to the DPC and ICO, a stale spreadsheet reads as weak accountability. Version control, named owners and approvals are what make the record defensible.
  • Records should stay connected to the systems, vendors, assessments, risks and retention decisions behind them, not copied between tools.
  • Multi-entity structure matters where one group spans several legal entities, countries or processing owners.
Demonstrate accountabilityShow how data is processed, why and where.
Save timeNo spreadsheets or manual reconciliation.
Reduce riskFewer gaps, fewer compliance surprises.
Audit-readyExports, provenance and audit trails built in.
05

What Acompli includes

What should RoPA software include?

A strong RoPA platform should make the record easier to maintain and easier to defend. Acompli focuses on multi-entity ownership, a structured processing directory, role-based collaboration, audit trails, exports, data-map linkage, and connections to DPIAs, TIAs, risk reviews and mitigation actions.

Last reviewed: 11 June 2026. Read the canonical answer surface: RoPA requirements guide for Ireland and the UK.

Acompli RoPA pricing is based on your compliance estate — data controllers, legal entities, jurisdictions and integrations — never per seat. See Acompli pricing.

Primary sources

Multi-entity management

Separate records by legal entity, country, business unit or operating function while keeping group-level visibility.

Version control and review history

See what changed, who changed it, who approved it and when the record was last reviewed.

Audit trail and exports

Export regulator-ready records and keep evidence of review, approval and updates.

Data map and assessment linkage

Use systems, vendors, recipients, retention, purposes and approved assessments to keep processing records current.

Roles and permissions

Control who can edit, approve and publish records across entities, teams and operating roles.

Retention and transfer linkage

Keep retention decisions, Chapter V safeguards and transfer review dates attached to the records they affect.

Recent Article 30 and accountability updates

Regulatory signals that affect records of processing

Recent enforcement, transfer and accountability updates often come back to the same question: can the organisation show what it processes, why and where?

RoPA FAQ

RoPA questions answered

Short answers for Article 30, RoPA maintenance, format, DPIA linkage, imports, and processor records.

What is RoPA software?

RoPA software is the tool a privacy team uses to build, maintain and evidence the Records of Processing Activities required by Article 30 of the EU and UK GDPR. In Acompli, each processing activity is a governed record: its fields are drafted from approved assessments, reviewed and approved by a named owner, and exportable for a DPC or ICO audit with the version history attached.

How should you choose RoPA software?

Choose RoPA software by the quality of the register it maintains, not just by how it stores rows. For Irish and UK privacy teams, the tool should cover Article 30(1) controller records and Article 30(2) processor records on one platform, scope records by legal entity, preserve reviewer-attributed version history, show Chapter V transfers with linked Transfer Impact Assessments, and export records that stay traceable to the source assessment behind every field. Acompli is built for this: Article 30 fields are drafted from approved assessments and supplier records with a confidence score on each, a named owner reviews and approves before anything publishes, and the approval chain travels with the record.

What does RoPA automation software actually automate?

In Acompli, automation means the register maintains itself between reviews. Article 30 fields are drafted from approved DPIAs and supplier records with a confidence score on each extracted field, and when an upstream fact changes - a new assessment is approved, a supplier contract changes, a system is retired, a transfer safeguard is updated - the affected records surface in a review queue with the change that triggered them. A person approves every update; nothing publishes itself.

How does RoPA software help with GDPR Article 30?

It maintains both registers the law describes: Article 30(1) controller records and Article 30(2) processor records, each with the dedicated fields the DPC and ICO expect - purposes, data categories, recipients, international transfers and safeguards, retention and security measures. Acompli generates these reports per legal entity, by processing role, or across the whole programme, with every field traceable to the assessment that produced it.

What should RoPA software include?

Look for both Article 30(1) and 30(2) record types, legal-entity scoping, reviewer-attributed version history, a transfer view that holds Schrems II safeguards, links from each record to the assessments and suppliers behind it, and regulator-ready exports. Acompli also preserves an entity snapshot at approval time, so historical records reflect the organisational structure that existed when the activity was approved.

How is RoPA software different from a spreadsheet?

A spreadsheet stores what someone last typed; a governed register knows where every value came from. In Acompli each field carries its source assessment, extraction confidence and approval chain, every version is preserved, and records flag themselves for review when the business changes - the things a shared file cannot do, and the first things a DPC or ICO auditor asks about.

More detailed questions
What features matter for multi-entity RoPA management?

Legal-entity scoping with group-level visibility, per-entity Article 30 exports, role-based ownership so local teams maintain their own records, and entity snapshots preserved at approval time. Acompli keeps one register across Irish, UK and EU entities while letting each subsidiary answer its own supervisory authority.

What affects RoPA rollout effort?

The effort usually depends on your compliance estate — data controllers and legal entities — along with jurisdictions, integrations and the quality of the existing register. Acompli scopes the rollout around those factors and focuses the migration on getting the Article 30 record current rather than rebuilding a spreadsheet by hand.

How does Acompli manage RoPA templates and version history?

Acompli uses structured Article 30 templates, mapped assessment questions, approval workflows and version history. When systems, suppliers or assessments change, affected records surface for review and exports remain traceable to the source evidence.

What should an Article 30 RoPA record prove?

It should cover the Article 30(1) and 30(2) fields, show whether the organisation is acting as controller or processor, scope records by legal entity, preserve version history, and link each field back to the assessment, supplier or transfer evidence that supports it.

How do completed DPIAs feed an Article 30 RoPA?

A DPIA (Article 35) and a RoPA (Article 30) ask many of the same questions about purposes, lawful basis, categories of data, recipients, transfers, retention, and security measures. In Acompli, approved DPIA responses are extracted through a multi-phase pipeline, mapped to the matching Article 30 fields, and surfaced as draft RoPA entries with per-field confidence scores and a link back to the source DPIA response. A reviewer approves, edits, or rejects before anything reaches the published register — so the DPIA evidence trail the DPC and ICO expect under EDPB Guidelines 04/2022 is preserved end-to-end.

What should a RoPA tool track for Schrems II international transfers?

After Schrems II (C-311/18) and the DPC's 1.2 billion euro Meta decision, an Article 30 entry that simply names a destination country is no longer sufficient. The register should record, per transfer, the legal mechanism under Chapter V (Articles 44-49), the Standard Contractual Clauses module in use, the linked Transfer Impact Assessment, any supplementary technical and contractual measures, and the assessment date. A tool that links the Article 30 transfer field directly to its supporting TIA gives the DPC or ICO a single thread to pull during an inquiry, rather than a spreadsheet column and a separate folder of PDFs.

Article 30 governance that keeps pace with the business

Acompli gives your register the governance process it needs to stay current — assessment-fed, review-governed, and structured for real operating models.