
- Products
- Services
- Solutions
By Regulation
- Resources
Our Latest Blog

- Partner With Us
By Regulation
Build and maintain accurate Records of Processing Activities so your teams can document how personal data is collected, used, shared, retained and protected across the organization. Create a single source of truth for processing activities, data categories, recipients, transfers, retention and security controls to support accountability and regulatory readiness.
Maintain one structured record of all personal data processing activities across the business, reducing spreadsheet chaos and makes privacy governance easier to manage.
Connect RoPA to the systems and sources where data lives so records stay current, helping teams capture changes without rebuilding documentation from scratch.
Track responsibilities for both controller and processor activities where applicable, making it easier to document obligations accurately across complex vendor and business relationships.
Document retention timelines, transfer locations and applicable safeguards in one place, helping teams maintain stronger control over cross-border and lifecycle risk.
Keep records formal, comprehensive and available when needed for internal reviews or authority requests, improving confidence during assessments, audits and compliance checks.
Understand where data originates, where it is stored and how it is shared across the organization, supporting better visibility, smarter governance and faster privacy decisions.
Trusted by privacy, security and compliance teams building stronger data governance
A RoPA gives organizations a clear view of their processing activities so they can govern data responsibly. Without it, privacy teams often rely on fragmented records, which makes compliance harder and risk management less effective. It also acts as the backbone for other privacy activities, including assessments, request response, retention management and regulatory reporting. In short, RoPA helps turn privacy documentation into a working operational asset.
| Law | Individual | Legal Requirement |
|---|---|---|
| GDPR | Record of Processing Activities (RoPA) | Each controller, and where applicable the controller’s representative, shall maintain a record of processing activities; each processor, and where applicable the processor’s representative, shall maintain a record of all categories of processing activities carried out on behalf of a controller. |
| DPDPA | Record of Processing Activities (RoPA) | Maintain documentation of processing activities, consent records and compliance records as part of operational compliance. |
| CCPA | Consumer Request Records | Businesses must maintain records and disclosures sufficient to respond to consumer requests and comply with notice and disclosure duties. |
Pull processing details from connected systems and workflows, keeping records aligned with real activity rather than manual updates.
Use RoPA to support assessments, notices and governance reviews, making downstream privacy work more efficient.
Bring together privacy, legal, IT, security and business owners, improving accountability and reducing gaps in ownership.
Update records as systems, vendors and processing purposes change, helping the RoPA stay useful as the business evolves.
Make the “why” behind each processing activity clear, supporting transparency and better governance.
Record what types of data are processed and who receives them, creating a more complete privacy picture.
Capture a general description of security measures and controls, demonstrating diligence and operational maturity.
Keep the RoPA prepared for internal reviews or supervisory authority requests, reducing scrambling when documentation is needed quickly.
Document every processing activity for accountability and readiness.
Keep your data inventory current across teams and systems.
Demonstrate control with clear records of purpose, retention and transfer.
Audit and maintain RoPA without relying on spreadsheets.
A RoPA, or Record of Processing Activities, is a structured record of how personal data is collected, used, shared, retained, and protected. It helps organizations maintain visibility and accountability across their processing activities.
Yes, RoPA is required under GDPR Article 30 for most organizations that process personal data. It serves as a key documentation requirement for privacy compliance and accountability.
A RoPA typically includes the purpose of processing, categories of data subjects and personal data, recipients, transfers, retention periods, and security measures. It provides a complete view of processing activity in one place.
Responsibility usually sits with the privacy, legal, compliance, or data governance team, often in collaboration with business owners. The exact ownership depends on the organization’s structure and privacy operating model.
RoPA should be updated whenever processing activities, systems, vendors, or data flows change. Regular reviews help keep the record accurate and audit-ready.
Yes, RoPA-style documentation can support DPDP readiness by helping organizations understand and document how personal data is processed. It strengthens governance, visibility, and operational control.
Yes, it can connect with data mapping tools to keep processing records more accurate and current. This reduces manual effort and helps align documentation with real data flows.
RoPA gives auditors and internal teams a clear view of processing activities, responsibilities, and safeguards. That makes assessments faster, more consistent, and easier to evidence.
Harness the Power of Permission to give users clear control over their data preferences while helping your business stay compliant, transparent and trusted.
New Jersey Data Privacy Act (NJDPA)
Effective Date: January 15, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumer or 25,000+ consumers with 50% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $10,000 for 1st violation and up to $20,000 for subsequent violations |
Florida Digital Bill of Rights (FDBR)
Effective Date: July 1, 2024
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| gross annual revenue of at least $1 billion or 50% or more revenue from targeted advertising | Access, Delete, Correct, Opt-Out, Portability |
Up to $50,000 per violation |
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
Effective Date: January 1, 2026
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumers or 10,000+ consumers with 20%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
$10,000 per violation and between $100 – $500 for each intentional disclosure of personal data |
Dedicated Data Privacy Laws in Michigan
Michigan does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Indiana Consumer Data Protection Act (INCDPA)
Effective Date: January 1, 2026
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumers or 25,000+ consumers with data 50%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Tennessee Information Protection Act (TIPA)
Effective Date: July 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumer or 10,000+ consumers with 20% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Kentucky Consumer Data Protection Act (KCDPA)
Effective Date: January 1, 2026
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumers or 25,000+ consumers with data 50%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Minnesota Consumer Data Privacy Act (MCDPA)
Effective Date: July 31, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumers or 25,000+ consumers with data 25%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Dedicated Data Privacy Laws in West_Virginia
West_Virginia does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Washington D.C.
Washington D.C. does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Washington
Washington does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Wisconsin
Wisconsin does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Alaska
Alaska does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Louisiana
Louisiana does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Kansas
Kansas does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Vermont
Vermont does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Maine
Maine does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Mississippi
Mississippi does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Missouri
Missouri does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in North_Carolina
North_Carolina does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Georgia
Georgia does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Alabama
Alabama does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Arkansas
Arkansas does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in New_Mexico
New_Mexico does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Arizona
Arizona does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Nevada
Nevada does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Idaho
Idaho does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Wyoming
Wyoming does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in South_Dakota
South_Dakota does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in North_Dakota
North_Dakota does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Hawaii
Hawaii does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
South_Carolina does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Connecticut Data Privacy Act (CTDPA)
Effective Date: July 1, 2023
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumers or 25,000+ 25%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
Up to $500,000 per violation |
Dedicated Data Privacy Laws in Massachusetts
Massachusetts does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Dedicated Data Privacy Laws in Ohio
Ohio does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Dedicated Data Privacy Laws in Illinois
Illinois does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Dedicated Data Privacy Laws in Oklahoma
Oklahoma does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Dedicated Data Privacy Laws in Pennsylvania
Pennsylvania does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in NewYork
New York does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Maryland Online Data Privacy Act (MODPA)
Effective Date: Oct 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumers or 10,000+ consumers with 20%+ revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
up to $10,000 per violation, and up to $25,000 for repeated violations |
Delaware Personal Data Privacy Act (DPDPA)
Effective Date: January 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumer or 10,000+ consumers with 20% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
up to $10,000 per violation |
Effective Date: January 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumer or 10,000+ consumers with 25% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
up to $10,000 per violation |
Virginia Consumer Data Privacy Act (VCDPA)
Effective Date: January 1, 2023
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumer or 25,000+ consumers with 50% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Texas Data Privacy and Security Act (TDPSA)
Effective Date: July 1, 2024
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumer or 10,000+ consumers with 20% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Oregon Consumer Privacy Act (OCPA)
Effective Date: July 1, 2024
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumer or 25,000+ consumers with 25% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Montana Consumer Data Privacy Act (MTCDPA)
Effective Date: October 1, 2024
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 50,000 consumer or 25,000+ consumers with 25% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Not specified |
Iowa Consumer Data Protection Act (ICDPA)
Effective Date: January 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumer or 25,000+ consumers with 50% revenue from data sales |
Access, Delete, Portability Opt-Out |
Up to $7,500 per violation |
Nebraska Data Privacy Act (NDPA)
Effective Date: January 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| Annual gross Revenue exceeding $10 million or buying/selling/sharing personal information of 50,000 or more consumers or 50%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Effective Date: July 1, 2023
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumers or 25,000+ 25%+ revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $20,000 per violation with a total maximum penalty of $500,000 |
Utah Consumer Privacy Act (UCPA)
Effective Date: December 31, 2023
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| $25M revenue and 100,000 consumer or 25,000+ consumers with 50% revenue from data sales |
Access, Delete, Opt-Out, Portability |
Up to $7,500 per violation |
California Consumer Privacy Act (CCPA)/CPRA
Effective Date : January 1, 2020/2023
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| $25M revenue, 50,000 consumers, or 50%+ revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
$2,500 per violation; $7,500 for intentional violations |
Adding {{itemName}} to cart
Added {{itemName}} to cart