WoluTools

Legal & Compliance

Record of processing activities template (GDPR Art. 30)

A blank RoPA workbook with every Article 30 item as its own column: one sheet for controllers, one for processors. Download it and enter one processing activity per row.

Step 1Free template

Download blank RoPA workbook (XLSX)

Sheets: Controller (14 columns), Processor (10 columns), Read me · 5 KB · opens in Excel, LibreOffice and Google Sheets

See every column before you download

Step 2, optionalAlready have a data inventory? Get a draft record from it

or drop it here

CSV or XLSX · up to 30 rows · 64,000 extracted characters
Costs 2 credits (about €0.70), free account needed

See a sample of the output

Sample output · fictional data, shortenedWhat step 2 returns for one inventory row

Your inventory row

Activity: Newsletter delivery. Purpose: send requested updates. Data subjects: subscribers. Data: email address. Processor: Mail Example. Retention: unknown.

Review workbook · activity row

Processing activity
Newsletter delivery
Purposes
Send requested updates
Data subjects
Subscribers
Personal data
Email address
Recipients
Mail Example (processor)
Time limit for erasure
left blank
Legal basis
left blank

Missing-field CSV

Missing fields for Newsletter delivery
ActivityFieldReview question
Newsletter deliveryRetentionSource says unknown. How long are addresses kept?
Newsletter deliveryLegal basisNot in source. Privacy lead to decide.

Data-flow CSV

Data flow for Newsletter delivery
FromDataTo
SubscribersEmail addressMail Example (processor)

A change log records what was taken from your file. Blanks stay blank.

BringNothing for the template · a CSV or XLSX inventory for step 2
GetBlank Art. 30 workbook, or a draft with missing-field CSV, data-flow CSV and change log
Step 2 filesEncrypted source · 24-hour result

Columns in the template

Each item that Article 30 lists has its own column. The header names the paragraph, for example [30(1)(b)].

Controller sheet · Art. 30(1)

  • Controller name and contact details30(1)(a)
  • Joint controller, representative and DPO contact details30(1)(a)
  • Purposes of the processing30(1)(b)
  • Categories of data subjects30(1)(c)
  • Categories of personal data30(1)(c)
  • Categories of recipients, including in third countries30(1)(d)
  • Transfers to third countries or international organisations, with safeguards30(1)(e)
  • Envisaged time limits for erasure30(1)(f)
  • Technical and organisational security measures (Art. 32(1))30(1)(g)

Helper columns: Ref. no., Processing activity, Activity owner, Legal basis, Last reviewed. Legal basis is optional and not an Article 30 item.

Processor sheet · Art. 30(2)

  • Processor name and contact details30(2)(a)
  • Controller on whose behalf you act, with contact details30(2)(a)
  • Representatives and DPO contact details30(2)(a)
  • Categories of processing carried out for this controller30(2)(b)
  • Transfers to third countries or international organisations, with safeguards30(2)(c)
  • Technical and organisational security measures (Art. 32(1))30(2)(d)

Helper columns: Ref. no., Service or processing activity, Sub-processors used, Last reviewed.

From blank sheet to reviewed record

  1. 1

    Download the template

    Use the Controller sheet, the Processor sheet or both. Delete the one you do not need.

  2. 2

    One row per activity

    Ask the owner of each activity. When an answer is not known yet, leave the cell empty instead of guessing.

  3. 3

    Optional: upload for a draft

    Upload your inventory as CSV or XLSX. You get a review workbook and a list of every empty field. 2 credits, free account needed.

What the optional draft step does

What you upload

A CSV or XLSX file with one processing activity per row. One run takes up to 30 rows and 64,000 extracted characters; split longer registers across several runs. The job costs 2 credits and needs a free account. You see the cost before it starts.

What you get back

A review workbook, a missing-field CSV, a data-flow CSV and a change log. Answers from your file are kept as they are. If retention or recipients are missing, the field stays blank and the row appears in the missing-field CSV as an open question. Nothing is filled in from a template.

What stays with you

Organisation role accepts Controller, Processor or Both. If one activity mixes both, choose Both and split the row during review. The tool never picks a legal basis or a retention period and makes no claim of GDPR compliance. The result is a draft, not a filed record: your privacy lead or counsel confirms each entry.

Questions before you start

Is the blank RoPA template free?

Yes. The XLSX download on this page is free and opens in Excel, LibreOffice and Google Sheets. Only the optional draft from an existing inventory uses credits: 2 credits per job, with a free account.

Which columns does Article 30 ask for?

For controllers, Art. 30(1): name and contact details of the controller (and of any joint controller, representative and DPO), purposes, categories of data subjects and of personal data, categories of recipients, transfers to third countries with safeguards, time limits for erasure where possible and a general description of security measures. For processors, Art. 30(2): processor and controller contact details, categories of processing for each controller, third-country transfers and security measures. The template has one column for each.

Will this tool choose a legal basis for each processing activity?

No. It leaves the legal basis blank when your inventory leaves it blank and raises it as a review question. Selecting a basis is a decision for your privacy lead or counsel.

What happens to rows where retention or recipients are unknown?

The field stays empty and the row appears in the missing-field CSV as an open question. Nothing is guessed or filled in from a template.

How do I tell it whether we act as controller or processor?

The Organisation role control accepts Controller, Processor or Both, and the workbook is laid out for the role you pick. If an activity mixes both roles, choose Both and split the row during review.

What source file does it expect and how many activities per run?

A CSV or XLSX inventory with one processing activity per row, up to 30 rows and 64,000 extracted characters per job. Longer registers can be split across several runs.

Is the output a record of processing activities I can file with a supervisory authority?

It is a draft workbook for review, not a filed record. A named owner still has to confirm each entry before it becomes your organisation's official register.