Article 30 Requirements
Article 30 is a section of the EU General Data Protection Regulation (GDPR) that requires organizations processing personal data to keep written records of their processing activities. These records document what personal data is handled, why, and how, and apply both to organizations that decide the purposes of processing (controllers) and to those that process data on another's behalf (processors). The requirement focuses on documentation and record-keeping rather than on the broader security or lawful-basis obligations found elsewhere in the GDPR.
Article 30 of the EU GDPR mandates that controllers (and, where applicable, their representatives) and processors maintain records of processing activities (RoPA) under their responsibility. For controllers, the record typically documents information such as the purposes of processing and related particulars; for processors, it typically includes their name and contact details and the categories of processing carried out on behalf of controllers. The obligation is a documentation and accountability control specific to record-keeping; it does not by itself establish a lawful basis for processing, satisfy security requirements, or discharge other GDPR obligations, which are addressed under separate articles. The UK GDPR imposes an analogous Article 30 record-keeping obligation, though organizations should confirm the applicable regime and any exemptions or thresholds relevant to their jurisdiction and circumstances.
Why it matters
Article 30 records of processing activities (RoPA) function as a foundational accountability control under the EU GDPR. For third-party risk and procurement professionals, these records matter because they establish a documented map of what personal data an organization handles, why, and how, including data processed by third parties acting as processors. When a controller engages a vendor to process personal data on its behalf, both parties carry their own Article 30 obligations: the controller documents purposes and related particulars, while the processor documents its identity, contact details, and the categories of processing performed on behalf of controllers. This creates a paper trail that supports oversight of the extended data-handling relationship.
It is important to recognize the boundaries of what Article 30 achieves. The requirement is a documentation and record-keeping obligation; maintaining a RoPA does not by itself establish a lawful basis for processing, satisfy security requirements, or discharge other GDPR obligations, all of which are addressed under separate articles. In practice, an organization can hold complete and accurate Article 30 records while still failing to meet its broader compliance duties. Treating a RoPA as evidence of overall GDPR compliance would therefore overstate its scope.
For organizations operating across jurisdictions, the picture varies. The UK GDPR imposes an analogous Article 30 record-keeping obligation, but the applicable regime, along with any exemptions or thresholds, depends on jurisdiction and circumstances. Organizations should confirm which requirements apply to them rather than assuming a single standard governs all their processing activities.
Who it's relevant to
Inside Article 30 Requirements
Common questions
Answers to the questions practitioners most commonly ask about Article 30 Requirements.
