How Do I Keep Track of All the Personal Data?
A helpful guide
💭 Ask yourself...
"If someone asked me where a particular piece of personal information goes after we collect it, could I answer with confidence?"
If not...
A RoPA can help.
Short answer
A Record of Processing Activities (RoPA) is much more than a compliance document.
It's a practical record of how personal information moves through your business.
A good RoPA should allow you to look at a particular activity and understand:
- what information you collect;
- why you collect it;
- where it comes from;
- who you share it with;
- where it's stored;
- how long it's kept;
- when it should be deleted.
Think of it as a map of your organisation's personal information.
Why is this important?
Businesses rarely lose control of personal information overnight.
It usually happens gradually.
A new supplier is introduced.
A new spreadsheet is created.
A marketing platform is added.
Someone starts using a new system.
Over time, information begins flowing through different systems and departments until nobody has a complete picture.
A RoPA helps bring all of that together.
A RoPA should tell the story of a process
A common mistake is treating a RoPA as a list of systems.
Instead, think about how your business actually works.
For example:
Recruitment
- What information do you collect?
- Why do you collect it?
- Who sees it?
- Is it shared externally?
- Where is it stored?
- How long do you keep it?
- When is it deleted?
Now repeat that exercise for every major business activity.
That's your RoPA.
A RoPA isn't a one-off exercise
One of the biggest misconceptions is that once a RoPA has been completed, it's finished.
It isn't.
Businesses change all the time.
You might:
- introduce a new CRM;
- start using AI;
- change payroll providers;
- appoint a new marketing agency;
- begin collecting new information.
Every significant change should prompt you to ask:
"Does our RoPA still reflect what we actually do?"
Everyone has a role to play
A RoPA shouldn't belong solely to the Data Protection Officer or compliance team.
The people carrying out the work are often the first to notice when something changes.
Creating a culture where staff feel comfortable saying:
"We've started doing something new."
or
"We've changed the way we collect this information."
helps keep your RoPA accurate and your organisation compliant.
Good data protection is a shared responsibility.
Practical steps
- List your main business activities.
- Identify what personal information is used within each activity.
- Record why you're using it.
- Document where it comes from, who it is shared with and how long it is retained.
- Review your RoPA regularly.
- Update it whenever your business changes—not just once a year.
Common Misconceptions
❌ "A RoPA is just another compliance document."
Not at all.
A good RoPA helps you understand your business. It gives you a clear picture of how personal information flows through your organisation and often highlights risks or unnecessary processing you didn't realise existed.
❌ "Once I've completed my RoPA, I don't need to look at it again."
Not correct.
A RoPA should evolve alongside your business. If your processing changes, your RoPA should change too.
❌ "Only the Data Protection Officer needs to know about the RoPA."
Not necessarily.
While one person may be responsible for maintaining it, everyone in the organisation should understand the importance of reporting changes that affect how personal information is used.
❌ "A RoPA is only for large organisations."
Not always.
Even where an organisation isn't legally required to maintain a formal RoPA, documenting your processing activities is often one of the best ways to understand your data and demonstrate accountability.
❌ "A RoPA tells me what systems I use."
Not really.
A RoPA should tell the story of your processing activities—not just list software. It should explain what information you collect, why you need it, where it goes and how long you keep it.
🤝 Need a little support?
Creating a RoPA can feel overwhelming if you try to document everything at once.
The easiest approach is to start with one business process at a time. As your understanding grows, so does your RoPA.
If you're unsure where to start or want to review an existing RoPA, we're happy to help.
Sometimes a conversation about how your business works is all it takes to build a document that genuinely supports good decision-making.
Related Guidance:
Do My Data Protection Policies Actually Reflect My Business?