Joint Controllers
If you are a joint controller with another organisation, record their details below.
A comprehensive template to document your processing activities in compliance with Article 30 of the UK GDPR.
Under Article 30 of the UK GDPR, controllers must maintain records of processing activities. This is mandatory for organisations with 250+ employees, but also applies to smaller organisations if processing:
If you are a joint controller with another organisation, record their details below.
A DPO must be appointed if you are a public authority, your core activities involve large-scale systematic monitoring, or your core activities involve large-scale processing of special category data.
Document each processing activity separately. Copy this section for additional activities.
Article 30(1)(b) — List all purposes for this processing activity
Article 30(1)(c) — Describe the categories of individuals
Article 30(1)(c) — Mark special category data with ⚠️
Article 30(1)(d) — Include internal and external recipients
Article 30(1)(e) — Document third country transfers
Article 30(1)(f)
Article 30(1)(g) — General description of security measures
Print additional copies of this page to document more processing activities
You must make this ROPA available to the ICO on request. Failure to maintain adequate records is a breach of Article 30 and may result in enforcement action.