Build your Record of Processing Activities — the document inspectors ask for first
RopaFlow is a self-service generator that builds and keeps your Article 30 GDPR Record of Processing Activities (RAT/RoPA) up to date, in 5 EU languages — no DPO, no law firm, no spreadsheets.
Article 30 GDPR: the document almost no small business has properly
The Record of Processing Activities is not a marketing document or a nice-to-have — it's a specific, written obligation inside the GDPR, distinct from your privacy policy, that regulators check first.
The rule: Article 30 of the General Data Protection Regulation (EU) 2016/679 requires every controller — and, in a shorter form, every processor — to maintain a written record of processing activities under its responsibility, made available to the supervisory authority on request.
The exemption is narrower than most owners think: Article 30(5) only exempts organisations with fewer than 250 employees, and only when the processing is occasional, unlikely to result in a risk to people's rights and freedoms, and does not involve special categories of data (health, biometric, union membership — Art. 9) or criminal-record data (Art. 10). Running payroll for your own staff, keeping a customer database or sending a newsletter are regular activities, not occasional ones — so in practice, almost any business with employees or recurring customers falls outside the exemption, regardless of headcount.
Why it gets checked first: the Record of Processing Activities is the document data protection authorities — the AEPD in Spain, the CNIL in France, the DPC in Ireland and equivalents elsewhere — request systematically at the start of an inspection. Not having one, or having an incomplete one, is treated as a stand-alone infringement, independent of whether any data breach ever happened.
- 1. Controller identityName and contact details of the controller (and Data Protection Officer, if you have one).
- 2. PurposesWhy you're processing the data for each activity — payroll, marketing, customer support, CCTV, etc.
- 3. CategoriesCategories of data subjects (employees, customers, visitors...) and categories of personal data involved.
- 4. RecipientsWho receives the data — internal departments and external recipients, including processors.
- 5. International transfersAny transfer outside the EEA, and the safeguard used (adequacy decision, standard contractual clauses, etc.).
- 6. Retention periodsTime limits for erasure of each category of data.
- 7. Security measuresA general description of the technical and organisational security measures applied.
The financial exposure is real and two-layered. In Spain, not having a Record of Processing Activities is classified as a serious ("grave") infringement under Article 73 of the LOPDGDD, punishable with fines of up to €300,000. Under the GDPR's general penalty ceiling (Article 83), the most serious combined infringements can reach up to €20 million or 4% of global annual turnover, whichever is higher — and a missing RAT is often the first item that opens a broader inspection.
Sources: Article 30 GDPR, official text via gdpr-info.eu · Article 83 GDPR (fines), gdpr-info.eu · Records of Processing (Article 30) Guidance, Irish Data Protection Commission · Registro de Actividades de Tratamiento, AEPD (official) · RAT: preguntas frecuentes 2025, Actecil. RopaFlow is not a law firm or DPO service — see our legal notice.
Who the Record of Processing Activities applies to
Businesses with employees
Payroll, HR files and employment contracts are regular processing of employee data — not "occasional" — so the small-business exemption doesn't apply.
E-commerce & online businesses
Customer accounts, order history, delivery data and marketing lists all count as regular processing activities that must be documented.
Health, legal & HR advisers
Clinics, lawyers, psychologists and HR consultancies handle special-category data (Art. 9) — automatically outside the exemption, whatever their size.
Marketing & digital agencies
Agencies process their clients' customer data (often as a processor too), which needs its own entries and a data processing agreement on file.
Freelancers with recurring clients
Invoicing, CRM records and email marketing to a client list are regular activities — a one-person business is not automatically exempt.
The rare true exemption
A business with genuinely occasional processing only, no special-category or criminal-record data, and fewer than 250 employees — narrow enough that most real businesses fall outside it.
From a blank page to a defensible register in four steps
Add a processing activity
Answer guided questions: purpose, legal basis, data categories, recipients, retention and transfers — no legal jargon required.
RopaFlow structures your register
Each activity is formatted to match the seven elements required by Article 30(1), ready to show an inspector or your DPO.
Add every activity your business runs
Payroll, customers, marketing, CCTV, suppliers, recruitment — add as many entries as your business actually has.
Export and keep it current
Download your register in HTML, CSV or JSON, and get notified when a relevant regulatory change affects your entries.
Build your Record of Processing Activities
Add one entry per processing activity your business carries out. Everything runs in your browser — nothing is uploaded until you choose to export it. This is an educational preview, not legal advice; see our legal notice.
Your Record of Processing Activities
- No activities added yet — fill in the form above and click "Add activity to register".
Exports are generated entirely in your browser and are an educational preview of a Record of Processing Activities, not a certified legal document. Review it with a qualified professional before relying on it. See our legal notice.
Simple plans, no consultancy invoices
Priced by number of processing activities, not by hours billed. Cancel any time.
Free tool
€0/forever
- Up to 2 activities
- HTML / CSV / JSON export
- English or Spanish only
- No saved account
For: testing the format before committing.
Use the free generatorStarter
€19/month
- Up to 5 activities
- HTML / CSV / JSON export
- 1 language of your choice
- Email support
For: freelancers and micro-businesses.
Start with StarterGrowth
€29/month
- Up to 15 activities
- All 5 EU languages
- Automatic regulatory-update alerts
- Saved account & version history
For: growing SMEs with several departments.
Start with GrowthPro
€39/month
- Unlimited activities
- Multi-entity workspace
- Priority regulatory alerts
- White-label export for advisories
For: gestorías and advisories managing several clients.
Start with ProGood for: freelancers, e-commerce, agencies, clinics and any SME with employees or recurring customers who need a defensible RAT without hiring a consultant. Not a fit for: large enterprises with complex multi-jurisdiction processing that needs a dedicated DPO/GRC platform (OneTrust, Wired Relations, DataGrail) wired into legal and IT workflows, or organisations that already run in-house DPO tooling. Why it works this way: keeping the tool self-service and template-driven is what lets us stay under €40/month instead of billing consultancy hours.
How much you save vs. hiring a consultant or DPO
Freelance DPO / consultant
€800–3,000 one-off + €100–400/mo
Typical range reported by data-protection consultancies and freelance DPO directories for building and maintaining a Record of Processing Activities for a small business — on top of enterprise GRC platforms (e.g. OneTrust) that start around $10,000/year, built for corporate DPO teams, not SMEs.
RopaFlow
from €228/year
Self-service plans from €19/month, built specifically for SMEs and freelancers — no implementation project, no long-term contract, your first activity added in minutes.
Frequently asked questions
What is the RAT / RoPA and why do I need it?
The Record of Processing Activities (RAT in Spanish, RoPA in English) is the internal register required by Article 30 of the GDPR that lists every way your business processes personal data — who, why, what data, for how long, and who it's shared with. It is a separate, mandatory document from your privacy policy or cookie notice, and it's usually the first thing a data protection authority asks to see during an inspection.
Is my business exempt because I have fewer than 250 employees?
Rarely, in practice. Article 30(5) GDPR only exempts organisations with fewer than 250 employees if the processing is occasional, unlikely to result in a risk to people's rights and freedoms, and does not involve special categories of data (Art. 9) or criminal-record data (Art. 10). Regular activities like payroll, a customer database or an email marketing list are not "occasional," so most real businesses fall outside the exemption regardless of size.
What exactly must the RAT include?
Per Article 30(1) GDPR, at minimum: the controller's name and contact details, the purpose of each processing activity, the categories of data subjects and personal data involved, the categories of recipients, any transfers to third countries and the safeguard used, the retention period for each category, and a general description of the technical and organisational security measures applied.
Isn't this the same as my privacy policy or cookie banner?
No. A privacy policy is a public-facing document explaining to individuals how you handle their data; a cookie policy covers tracking technologies. The RAT/RoPA is an internal register, typically not published, that documents your processing in structured detail for accountability and for supervisory authorities — tools like Iubenda, Termly or CookieYes cover the first two but not this one.
What happens if I'm inspected and don't have one?
In Spain, for example, not having a Record of Processing Activities is classified as a serious ("grave") infringement under Article 73 of the LOPDGDD, with fines of up to €300,000. Under the GDPR's general penalty framework (Article 83), the most serious infringements can reach up to €20 million or 4% of global annual turnover, whichever is higher.
Is RopaFlow a DPO, law firm or certification body?
No. RopaFlow is a self-service software tool that helps you structure and maintain your own Record of Processing Activities. It does not provide legal advice, does not act as your Data Protection Officer, and does not certify or guarantee compliance. For legal advice or a formal DPO appointment, consult a qualified professional.
Can I export and share my RAT with an inspector or my DPO?
Yes. The free generator exports your register as HTML, CSV or JSON directly in your browser — nothing is uploaded unless you choose to. Paid plans add saved accounts, all 5 EU languages and automatic alerts when a relevant rule changes.
Do I need to keep updating it?
Yes — the RAT should reflect reality. Whenever you start a new processing activity, change a supplier or processor, or the applicable rules change, update your register. Paid RopaFlow plans track regulatory changes and prompt you to review affected activities.
Want the full multi-language version with auto-updates?
Leave your details and we'll help you scope which plan fits your number of processing activities — no obligation.