A GDPR data map shows how personal data moves through people, systems, vendors and locations. A record of processing activities (ROPA) documents the information required by Article 30 at the level of processing activities. Most organisations need both: the map exposes facts; the ROPA turns validated facts into an accountable regulatory record.
Data map and ROPA are different
| Artifact | Main question | Typical format |
|---|---|---|
| Data map | Where does personal data come from, go and persist? | Flow diagram, system inventory or linked register |
| ROPA | What processing occurs, why, for whom, for how long and with what safeguards? | Structured register owned by controller or processor |
Article 30 sets different minimum content for controllers and processors. The fewer-than-250-person derogation is narrow: it does not apply where processing is likely to risk individuals’ rights and freedoms, is not occasional, or includes Article 9 special-category data or Article 10 criminal-conviction data. Headcount alone is therefore not a safe reason to keep no record.
What to capture
For each processing activity, record enough detail to answer:
- who is the controller, joint controller, processor and relevant contact;
- whose data is involved and which categories of personal data are used;
- the specific purposes and the Article 6 lawful basis;
- any additional Article 9 condition for special-category data;
- recipients, processors and sub-processors;
- transfers to third countries or international organisations and the relied-on safeguard;
- retention or deletion criteria by data category; and
- a general description of technical and organisational security measures where required.
The ROPA is not a place to paste “business operations” as a universal purpose. Use language that lets a reviewer distinguish, for example, account administration from product analytics and fraud prevention.
A six-step mapping method
1. Define scope and ownership
List legal entities, business units, products and locations. Assign a business owner and a privacy reviewer. Decide how systems and activities will be given stable identifiers.
2. Start with processes, not software
Interview the people who run recruiting, sales, service delivery, support, finance, marketing and security. A single application may serve several purposes with different lawful bases and retention rules.
3. Trace the full lifecycle
For each activity, trace collection, use, sharing, access, storage, backup, archive and deletion. Include exports, logs, support tools, collaboration platforms and sub-processors—not only the primary database.
4. Validate legal and transfer fields
Confirm the lawful basis rather than inheriting a default. For transfers outside the EEA, identify whether adequacy, appropriate safeguards or a limited Article 49 derogation applies. A server region is useful operational information but does not by itself resolve transfer compliance.
5. Reconcile with other evidence
Compare the map with privacy notices, contracts, consent records, DPIAs, retention schedules, security inventories and vendor lists. Contradictions are findings to resolve, not fields to hide.
6. Build change control
Update triggers should include a new purpose, data category, vendor, integration, country, retention rule or material system change. Record an owner and last validation date for every activity.
Quality checks
A useful register can answer these questions without a new investigation:
- Which activities use biometric, health or other special-category data?
- Which processors receive customer identifiers outside the EEA?
- Which notices describe this activity?
- What event starts each retention period?
- Which activities may require a DPIA?
- When was the business owner last asked to validate the record?
Avoid false precision. If a legacy flow remains uncertain, label the gap, owner and resolution date. An unsupported complete-looking map is less useful than an honest, managed record.
Our data protection service can facilitate interviews and build a maintainable processing inventory. For an independent check of existing records and evidence, see our GDPR audit service.
Sources and review
- Regulation (EU) 2016/679, including Articles 6, 9, 10 and 30
- European Commission: how organisations demonstrate GDPR compliance
Reviewed on 8 August 2026. The Article 30 exemption is deliberately qualified because it depends on the nature and regularity of processing, not headcount alone.
Ivana Ludiga, mag. iur., is an Associate at Vision Compliance focused on data protection, GDPR implementation, and regulatory advisory. She supports compliance projects for organizations across healthcare, financial services, and technology sectors.