Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ROPA exemption: the GDPR Article 30(5) decision for organizations with fewer than 250 employees

ROPA Exemption: The Essential 2026 Guide to GDPR Article 30(5) for Small Organizations

The ROPA exemption is one of the most misunderstood provisions in the GDPR. Article 30(5) says organizations with fewer than 250 employees do not have to keep a record of processing activities, and many small businesses stop reading there. They should not, because the same sentence removes the exemption in three situations that describe almost every real organization. For most employers, the exemption exists on paper and disappears in practice.

This guide explains what Article 30 requires, how the ROPA exemption works, why most organizations lose it, what the Commission’s proposal to raise the threshold would change, and why keeping a record is sensible even if you technically qualify.

Free gap assessment

Could you demonstrate GDPR compliance today?

Score yourself against what a supervisory authority actually asks for, free — the records, not the policy.

Run the free GDPR gap assessment →  or  View premium report sample

What Article 30 requires before any ROPA exemption

Article 30 requires controllers to maintain a record of processing activities under their responsibility, and processors to keep a record of the categories of processing carried out on behalf of each controller. The records must be in writing, including electronic form, and must be made available to the supervisory authority on request.

A controller’s record includes the controller’s contact details, the purposes of processing, the categories of data subjects and personal data, the categories of recipients, transfers to third countries, retention time limits where possible and a general description of security measures where possible. A processor’s record is shorter and focuses on the controllers it works for, the categories of processing, transfers and security measures. Our guide to controller versus processor ROPA compares the two records, and our ROPA example shows a completed entry.

How the ROPA exemption in Article 30(5) works

Article 30(5) states that the record-keeping obligations do not apply to an enterprise or organization employing fewer than 250 persons. Then it adds three exceptions. The exemption falls away if the processing is likely to result in a risk to the rights and freedoms of data subjects, if the processing is not occasional, or if it includes special categories of data or personal data relating to criminal convictions and offences. You can read the wording in the text of GDPR Article 30 on gdpr-info.eu.

Read literally, the three conditions are alternatives, so meeting any one of them means you must keep a record. That makes the ROPA exemption much narrower than the headline threshold suggests.

ConditionWhat it means in practiceTypical example
Likely risk to individualsThe processing could plausibly harm rights or freedomsProfiling customers, monitoring staff, large customer databases
Not occasionalThe processing happens regularly or continuouslyPayroll, customer accounts, newsletter lists, CCTV
Special category or criminal dataHealth, biometric, union membership and similar data, or criminal recordsSick leave records, occupational health, background checks
None of the aboveRare, low-risk, non-sensitive processing onlyA one-off event mailing for a small club

Why the “not occasional” condition catches almost everyone

Any organization that employs people processes employee data continuously: payroll, contracts, absences and pensions. Any organization with customers keeps customer accounts and invoices on an ongoing basis. Those activities are not occasional. Even if every other activity is minor, a regular processing activity removes the ROPA exemption for at least that activity, and in practice the safest reading is that you need a record for all of your processing.

Special categories are easier to trigger than you think

Sick notes are health data. A photo used for biometric door access is biometric data. A payroll deduction for union dues reveals union membership. A background check on a new employee may involve criminal offence data. If any of these appear in your HR or security processes, the third condition applies.

Who can actually rely on the ROPA exemption

Realistically, only very small and unusual organizations. A micro business with no employees beyond its owner, no sensitive data and only occasional low-risk processing might qualify, though even those often find that ordinary customer records are regular processing. The safest position is to assume you need a record unless you have documented a clear reason why each of the three conditions does not apply. If you do decide you are exempt, write down the reasoning and the date, because you may have to defend it to a regulator.

The proposal to raise the threshold to 750

The European Commission proposed in 2025, as part of a simplification package, to raise the employee threshold from 250 to 750 and to narrow the exception so that it applies only where processing is likely to result in a high risk. The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion in July 2025 supporting the aim of reducing administrative burden for smaller organizations, while stressing that the register remains a valuable compliance tool even when it is no longer mandatory.

Whether the change has since been adopted is something to verify, so check the current text of the GDPR and any amending regulation before relying on the higher threshold. Until a change takes effect, the 250 threshold and the three conditions in Article 30(5) apply as written. Even under the proposal, larger organizations and many mid-sized ones would still need a record, and the other accountability duties would continue.

A worked example: a 40-person design agency

Picture a design agency with forty staff. It has fewer than 250 employees, so the headline threshold looks satisfied. But it runs payroll every month, keeps client contact records, stores freelancer bank details, uses CCTV at its office and holds sick-leave notes. The regular activities alone remove the exemption. The sick-leave notes involve health data, which removes it again. The agency therefore needs a record, and the practical task is to list a handful of activities, such as recruitment, payroll, client management, marketing and building security, with their purposes, data categories, recipients, transfers and retention periods. That is an afternoon of work, not a project, and once the first version exists the agency can update it whenever it adopts a new tool or supplier.

Why to keep a record even if you qualify for the ROPA exemption

A record is the easiest way to know what you process, and you need that knowledge for other obligations. Privacy notices must describe purposes, recipients and retention. Data subject requests require you to locate personal data quickly. Breach response depends on knowing what was affected. Data protection impact assessments start from a description of the processing, and transfer decisions start from knowing where data goes. Our guide to GDPR data mapping shows how a mapping exercise feeds all of these.

Many small organizations therefore keep a short, simple record voluntarily. A one-page register with a row per activity is enough to start with. The effort is small compared with the cost of reconstructing the same information under pressure after a complaint or incident.

A 6-step check of your ROPA exemption

  1. Count your people. Confirm the headcount against the threshold in force.
  2. List regular processing. If anything recurs, the exemption fails.
  3. Check for special category and criminal data. Look in HR, security, health and screening processes.
  4. Assess risk. Consider profiling, monitoring and large-scale handling.
  5. Document the conclusion. Record who decided, when and why.
  6. Decide on a voluntary record. Most organizations should keep one.

Common ROPA exemption mistakes

  • Reading only the headcount. The threshold is the start of the test, not the end.
  • Forgetting employee data. Payroll alone is regular processing.
  • Ignoring sensitive data in HR files. Sickness and union deductions count.
  • Undocumented reliance. If you claim the exemption, record the reasoning.
  • Assuming the proposal is law. Verify the current text before relying on a higher threshold.
  • Treating a record as bureaucracy only. It supports notices, requests, breaches and assessments.

Build the record once and keep it current

If you decide to keep a record, start from a structure that already meets Article 30. The Records of Processing Activities Report and Excel Register gives you a completed Article 30 record structure, a processor record and a register you can adapt to your own activities. For layout guidance, see our ROPA template.

ROPA exemption FAQ

Does the ROPA exemption apply to companies with fewer than 250 employees?

Only if none of the three conditions applies. Regular processing, likely risk to individuals or special category and criminal data each removes the exemption, and most employers meet at least one.

Are processors covered by the ROPA exemption?

Article 30(5) refers to the obligations in paragraphs 1 and 2, so the same exemption and the same three conditions apply to processor records.

Is payroll processing occasional?

No. Payroll happens regularly, so it is not occasional, and it often involves special category data such as sickness or union deductions.

What happens if I am exempt and a regulator asks for a record?

You should be able to show why the exemption applies. Without a record or a documented reason, you risk being treated as non-compliant, so keep your reasoning on file.

Will the 750-employee proposal remove the need for a ROPA?

Not for most mid-sized organizations, and the register remains useful even where not mandatory. Check whether the proposal has been adopted before relying on it.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.