Book a call
By LegalEdge News

What is a ROPA and why do you need one? (Otherwise known as: keeping control of personal data in your company)


What is a ROPA? 

ROPA stands for “record of processing activities” – if you don’t have one, you should.

A ROPA is, essentially, a record of the personal information that comes into your business (staff, customers, suppliers, etc.) and it helps you keep track of what you do with it. 

Because internal processes can be haphazard early on, you may not have sufficient visibility of the personal data you hold, why you need it and where it is going. Which is why a ROPA is a good idea, as well as a legal requirement for many. Plus, putting a ROPA in place doesn’t need to be complex, particularly early on. But you do need to keep it under review and update it regularly.

Why do you need a ROPA? 

LegalEdge’s data protection consultant Rhian Burke explains why:

  • For some companies it is a legal requirement (Article 30 of the GDPR). 
  • Even if it isn’t a legal requirement, the UK Information Commissioner’s Office (ICO) expects companies to be transparent and accountable for what they do with personal data and be able to demonstrate the steps taken to protect it – and a ROPA can be evidence that you have done this.
  • In order to process data lawfully in the UK, you need to know the basis for which you are using it – a ROPA can help you justify your use of data and document your lawful basis.
  • A ROPA is a great risk assessment tool; by taking stock of what personal information you have, where it is kept and what you are doing with it, you can check where you are with your data protection compliance and flag up areas where you may be at risk of a breach.
  • No-one wants to have to deal with the reputational fallout from a data breach, nor find themselves facing a fine or compensation claim. A ROPA can help you deal with any issues before they become a problem requiring a more resource heavy/ expensive response.
  • A ROPA makes it much easier to improve information governance and comply with other aspects of data protection law (such as creating a privacy notice and keeping personal data secure).
  • If you’re considering certifying to ISO 27001, you need to be GDPR compliant and have a Data Asset Register.  A ROPA forms the bedrock of this and can act as a Data Asset Register, reducing the burden on your journey to ISO 27001.
  • A ROPA feeds into data and information security policies, which customers often require. 

How can we help?

We can help you put a ROPA in place, train your staff on how to implement it, and help you keep your ROPA up to date. We can also help with privacy notices and other relevant data protection and information security policies and terms. Get in touch at info@legaledge.co.uk to find out more.

Back To Blog Our Services
  • Share:

What do our clients think?

We’ll set up a cost-effective, efficient legal function for your business. You’ll have an experienced lawyer as your single point of contact who works as part of your operations team.

No duplication and no reinventing the wheel each time. We get to know your business quickly to manage your legal matters effectively and add value. And as your flexible in-house legal function, we can be scaled up or down depending on needs.

We analyse risk and prioritise what’s important, then manage and carry out the day-to-day legal work, all to a set budget. We’ve all worked as in-house lawyers in fast growth companies, so know what you need (and don’t need) to worry about. We’ll work with you to get deals and contracts done and help achieve your business goals.

“The fact that all their lawyers have worked inside businesses means they are commercial, pragmatic and know exactly how to prioritise what’s important.”

“We’re very pleased with the work LegalEdge are doing for us. We’re getting quick and decisive responses that are really helping us move forward.”

We work with small in-house legal teams that need additional support on a flexible basis without adding to headcount.

Whether it’s overflow work, a project or just a much-needed extra pair of hands we can help. We get the job done without supervision, working seamlessly as part of your team or behind the scenes, whatever works best for you. We don’t do endless negotiations on the clock or write long legal memos. We just help prioritise, find solutions and get it done.We understand the challenges and demands of small in-house teams because we’ve been there. We work as an extension to your team, get up to speed on business priorities quickly, and help you keep control of legal workflow and budget.

“The ideal solution for the busy in-house counsel who is unable to add a permanent head as you have the ability to flex support without the need to rely on expensive law firms.”

“LegalEdge has provided excellent, commercially focused advice as part of our in-house legal team that has helped us close contracts with our customers and partners.”