What is a RoPA?

A Record of Processing Activities, or RoPA, is the documented record of what an organisation does with personal data: each processing activity, its purpose, the categories of personal data and of data principals involved, who receives the data, how long it is kept and on what lawful basis. It is the artefact you produce when asked to demonstrate that you know and control your own processing.

Dinkar Singh

A RoPA is not the same thing as a data inventory. The inventory says where personal data lives; the RoPA says what you do with it and why. The inventory is an input to the RoPA.

The common failure is building one from a questionnaire. That makes it accurate on the day it closes and progressively wrong afterwards, because systems change faster than an annual survey cycle. A RoPA that populates from live system metadata stays true between reviews.

  • The processing activity and its stated purpose.
  • Categories of personal data and of data principals, flagging children's data.
  • The systems where that data actually lives.
  • Recipients, including processors and any transfer outside India.
  • Retention period and the basis for it.
  • The lawful basis relied on, and who approved it.

General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.

Dinkar SinghDinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →