Organisations hold information across business systems, shared drives, email accounts, spreadsheets, paper files and supplier platforms. A Record of Processing Activities (ROPA) and an Information Asset Register (IAR) provide two different but complementary views of that information:
- a ROPA records how and why personal data is processed; and
- an IAR records the information assets an organisation holds and how they are managed.
Understanding the distinction helps organisations meet their legal obligations and maintain a clearer view of their information.
What is a ROPA?
A ROPA records the processing of personal data for which an organisation is responsible.
The principal legal requirement comes from Article 30 of the UK GDPR. Controllers and processors have separate obligations, reflecting their different roles.
A controller’s ROPA must include:
- relevant contact details, including those of the data protection officer where applicable;
- the purposes of the processing;
- the categories of individuals and personal data involved;
- the categories of recipients;
- relevant international transfers;
- where possible, the intended retention periods; and
- where possible, a general description of the security measures.
Processors must maintain their own record covering the categories of processing undertaken for each controller, together with relevant contact details, international transfers and, where possible, a general description of the security measures. The ICO explains the information controllers and processors must document.
The ROPA must be in writing, including electronically, and made available to the ICO if requested.
Does every organisation need one?
Organisations with 250 or more employees must document all their processing activities.
There is a limited exemption for organisations with fewer than 250 employees. However, they must still document processing that:
- is not occasional;
- is likely to result in a risk to individuals’ rights and freedoms; or
- involves special category or criminal offence data.
An activity must be documented if any one of these conditions applies.
Routine processing involving employees, customers or service users is unlikely to be occasional. Most organisations will therefore need to document at least some of their processing.
What is an IAR?
An IAR takes a broader, asset-based view. It identifies the information assets an organisation holds and supports their management throughout their lifecycle.
These assets might include:
- databases and business systems;
- shared drives and document libraries;
- paper filing systems;
- contracts and case records;
- operational reports; and
- intellectual property or commercially sensitive information.
Unlike a ROPA, Article 30 does not impose a general requirement to maintain an IAR or prescribe what it must contain.
An IAR will commonly record an asset’s location, owner, format, sensitivity, access arrangements, retention requirements and relevant suppliers. The precise contents should reflect the organisation and how it manages information.
The ICO’s audit framework nevertheless expects organisations to identify their manual and electronic record-keeping systems, maintain a central log or information asset register and assign responsibility for keeping it current.
An IAR may also contain assets that do not involve personal data. This is one of the main differences between an IAR and a ROPA.
How do the registers work together?
Organisations can maintain separate but linked registers or use an integrated system. An integrated register can meet the Article 30 requirement, but only if it records all the required information for each relevant processing activity.
One information asset may support several processing activities. For example, a customer management system might hold names, contact details, purchase histories, service enquiries and marketing preferences.
Within the ROPA, this could represent several activities:
- processing orders and administering customer accounts;
- responding to enquiries or complaints;
- analysing customer activity; and
- sending marketing communications.
The activities have different purposes and may require separate consideration of the lawful basis, recipients and retention period. Marketing activity may also be subject to the Privacy and Electronic Communications Regulations. Recording only the name of the system would not explain these differences.
The reverse can also apply. One processing activity may involve several information assets. Recruitment, for example, could involve an application platform, email accounts, interview notes, shared folders and a payroll system.
Linking the registers shows how processing activities and information assets relate to each other without unnecessarily duplicating information.
How do they support accountability?
A ROPA is part of the wider accountability requirements of the UK GDPR.
Under Article 5(2), a controller is responsible for complying with the data protection principles and must be able to demonstrate that compliance.
The ROPA can support this by linking each processing activity to relevant evidence, such as:
- the lawful basis;
- privacy information;
- records of consent;
- legitimate interests assessments;
- data protection impact assessments;
- controller–processor contracts;
- retention arrangements; and
- the conditions applying to special category or criminal offence data.
Not all this information has to appear directly within the ROPA. The ICO recommends that the ROPA includes or links to wider accountability documentation.
The ROPA can therefore provide a route into the evidence supporting the organisation’s data protection arrangements, rather than operating as a standalone compliance record.
What would an auditor look for?
An auditor would typically consider whether the registers are complete, accurate, current and supported by evidence. This is likely to include whether:
- the ROPA covers processing across the organisation;
- the information required by Article 30 is recorded;
- controller and processor roles are correctly identified;
- lawful bases and any additional conditions are appropriate;
- entries agree with privacy notices, contracts, retention schedules and data protection impact assessments;
- responsibility for maintaining the registers is clear;
- changes to systems, suppliers or processing activities trigger updates; and
- a sample of entries can be verified through discussions with staff and examination of systems or records.
Keeping the records useful
A ROPA and IAR should reflect how the organisation currently operates. New systems, suppliers and uses of information can quickly make them out of date.
Clear ownership, regular review and a process for recording changes are therefore important. Used together, the registers help an organisation understand what information it holds, why personal data is processed, where it is located, who can access it and which requirements apply.
This supports compliance while providing a stronger basis for decisions about systems, suppliers, security, retention and the wider use of information.


