Back to GDPR Hub
Compliance StrategyAugust 2, 2026

What is a ROPA? A Practical Template for Marketing Teams

If you have ever stared at a blank spreadsheet titled "GDPR Compliance" and wondered what exactly you are supposed to put in it, you are not alone.

For most marketing teams and agency operators, the term ROPA (Record of Processing Activities) sounds like a dense regulatory artifact meant for enterprise lawyers. In reality, it is much simpler. A ROPA is essentially a master inventory of your data: what personal data you touch, why you have it, and where it goes.

Under Article 30 of the GDPR, maintaining this record is a strict legal obligation. It is not a privacy policy you paste on your website, it is not a DPA you sign with a vendor, and it is not a cookie banner. It is a structured internal ledger. If a regulator audits your agency, or if an enterprise client sends you a security questionnaire, your ROPA is the very first thing they will ask to see.


The "Under 250 Employees" Myth

There is a pervasive myth in the agency world that small businesses are exempt from Article 30. Many operators read the first line of the exemption—which states that organizations with fewer than 250 employees don't need a ROPA—and they stop reading.

Unfortunately, Article 30(5) has a major caveat. The exemption is immediately voided if your data processing is not occasional.

Think about what your agency does every day. Do you run CRM lists? Do you manage email marketing campaigns? Do you use Google Analytics or ad targeting pixels? None of these activities are "occasional." They are systematic, daily operations. Therefore, the employee count exemption does not apply to you. Marketing teams and digital agencies must maintain a ROPA, period.

Controller vs. Processor ROPAs: You Need Both

Most agencies actually need to maintain two distinct ROPAs, because you operate in two different legal capacities.

  • Controller ROPA: This maps the data where you make the decisions. It covers your own employees, your agency's CRM, your newsletter subscribers, and your prospect lists.
  • Processor ROPA: This maps the data you handle on behalf of your clients. It covers every client engagement where you touch their data (e.g., managing their HubSpot, running their Shopify email lists).

According to the GDPR, a Controller ROPA requires slightly more detailed fields (like the Lawful Basis for processing) than a Processor ROPA. Understanding this distinction is critical—we cover this dynamic extensively in our GDPR compliance guide for agencies. Most agencies have zero of either.

Building Your ROPA: A Practical Example

Let's demystify what this actually looks like. A ROPA is essentially a matrix. Let's walk through building a single row in a Processor ROPA for a very common agency activity: Running email campaigns via Mailchimp for Client X.

Here are the exact fields a regulator expects to see, mapped to our practical example:

ROPA ENTRY: CLIENT EMAIL MARKETING

Name of the Processing Activity
Executing monthly promotional email campaigns for Client X.
Controller Information
Client X (You are the Processor, acting on their written instructions).
Categories of Data Subjects
Client X's active customers and newsletter subscribers.
Categories of Personal Data
Names, email addresses, IP addresses, and email engagement metrics (open rates).
Categories of Recipients (Sub-processors)
Mailchimp (Intuit), AWS (hosting data on Mailchimp's behalf).
Cross-Border Transfers
Yes, data is transferred to the US. Safeguards: EU-US Data Privacy Framework (Intuit/Mailchimp is DPF-certified) with Standard Contractual Clauses (SCCs) as fallback per the Mailchimp DPA.
Retention Period
Data is deleted or returned to Client X within 30 days of contract termination.
Technical & Organizational Measures (TOMs)
Data encrypted in transit (TLS) and at rest. Access restricted via SSO and mandatory 2FA for agency staff.

That is it. If you build out rows like that for every tool and process your agency uses, you have a fully compliant ROPA.

Common Mistakes Agencies Make

When agencies attempt to build this in a spreadsheet, they usually run into a few common pitfalls:

  • Being too vague: Listing your processing purpose simply as "marketing" will fail an audit. You must be specific (e.g., "B2B lead generation via LinkedIn Ads").
  • Ignoring internal data: Your ROPA isn't just about clients. You must document how you process your own employees' payroll data, HR records, and candidate resumes.
  • Missing cross-border transfers: Many US-based SaaS tools process EU data in American data centers. You must log these transfers and note the legal mechanism (like the Data Privacy Framework or SCCs) that makes them legal.
  • Treating it as a one-time project: A ROPA is not a "set it and forget it" task. A ROPA that was last updated 18 months ago is almost as legally useless as not having one at all.

How to Actually Maintain It

The biggest challenge isn't building the ROPA; it's keeping it accurate. To prevent your ROPA from rotting in a Google Drive folder, you must tie updates to operational trigger events.

Make it a strict policy to update your ROPA whenever one of these four things happens:

  1. You onboard a new client (new Processor entry).
  2. You add a new SaaS tool to your tech stack (new sub-processor/recipient).
  3. You start collecting a new category of data (e.g., you add phone numbers to a form).
  4. An employee is hired or leaves (affecting who has access to the data).

If manually managing a spreadsheet sounds like a nightmare, this is exactly what Custodia's Activity Register module solves. It completely replaces the spreadsheet ROPA by syncing directly with your vendor stack, auto-populating sub-processor fields, and ensuring your records stay current without manual data entry.

If you don't know whether your current ROPA (or lack of one) passes an audit, you can find out in 12 minutes by taking our free GDPR gap assessment.

Find out your GDPR score

Take our free 12-minute assessment to see where your agency stands.

Take free assessment