A Record of Processing Activities, or RoPA, is the documented record of what an organisation does with personal data: each processing activity, its purpose, the categories of personal data and of data principals involved, who receives the data, how long it is kept and on what lawful basis. It is the artefact you produce when asked to demonstrate that you know and control your own processing.
A RoPA is not the same thing as a data inventory. The inventory says where personal data lives; the RoPA says what you do with it and why. The inventory is an input to the RoPA.
The common failure is building one from a questionnaire. That makes it accurate on the day it closes and progressively wrong afterwards, because systems change faster than an annual survey cycle. A RoPA that populates from live system metadata stays true between reviews.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Dinkar Singh — Dinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →