Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ROPA purposes and lawful bases table mapping each processing purpose to an Article 6 lawful basis

ROPA Purposes and Lawful Bases: A 2026 Guide

ROPA purposes and lawful bases are the part of the record where vague thinking is most visible. A record that says “business operations” as the purpose and “legitimate interests” as the basis for everything tells a regulator very little, and it usually means the organization has not really decided why it processes each set of data.

This guide explains how to write clear purposes, how to choose and record a lawful basis for each, how special category data changes the picture and how to keep the record consistent with your privacy notice. It is general information, not legal advice, so confirm the detail with your DPO or counsel.

Why purposes and lawful bases belong in the record

Article 30 requires the record to state the purposes of the processing. The regulation does not list lawful bases as a mandatory field, yet most authorities and auditors expect to see them, because the purpose and the basis together explain why the processing is allowed at all. Recording ROPA purposes and lawful bases side by side also makes it obvious when a basis has never been chosen.

The record is also a check on the rest of your programme. If a purpose appears in the record but not in your privacy notice, or the reverse, one of the documents is wrong. Our ROPA example shows how purposes and bases sit alongside the other fields.

How to write a specific purpose

A good purpose says what you do and why, in plain words, at a level a data subject would recognise. “Managing customer orders and delivery” is useful. “Business purposes” is not. Split unrelated activities into separate entries: staff payroll and staff performance reviews use different data for different reasons and may need different bases.

Test each purpose with three questions. Could a new employee understand it? Does it match what the privacy notice tells people? Would you be comfortable explaining it to a regulator? If the answer to any is no, rewrite it. Specific wording also helps with purpose limitation, because you can see when a new use goes beyond what the record describes.

Purpose exampleTypical lawful basisNote
Delivering an ordered productContractNecessary to perform the contract
Payroll and tax reportingLegal obligationCite the law where practical
Fraud preventionLegitimate interestsNeeds a documented balancing test
Email marketing to prospectsConsent or legitimate interestsDepends on national ePrivacy rules
Occupational health checksArticle 6 basis plus Article 9 conditionSpecial category data

Free ROPA template and builder

Could you hand your records of processing to a regulator tomorrow?

Check whether Article 30 applies to you, add your processing activities from a library organized by department, complete every Article 30 content, and see which activities are missing a lawful basis, a transfer safeguard, a DPIA or an LIA. Free, with a record score and findings.

Build your free ROPA →  or  View premium report sample

Choosing a lawful basis for each entry

Article 6 offers six bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. For each entry, pick the one that genuinely fits and record it. Do not choose consent because it sounds safest: consent must be freely given and can be withdrawn, so it is a poor fit where you must process regardless. Read Article 6 of the GDPR to check the wording of each basis.

Where you rely on legitimate interests, record that a balancing test exists and where to find it. Our guides to a legitimate interests assessment example and legitimate interests vs consent help you decide which basis fits. Employee monitoring in particular needs care, as explained in legitimate interests and employee monitoring.

  • Contract: processing that is needed to deliver what the person signed up for
  • Legal obligation: processing the law requires, such as tax records
  • Legitimate interests: processing that passes a documented three-part test
  • Consent: only where the person has a real choice and can withdraw

Special category data and criminal offence data

If an entry includes health data, biometric data, data revealing ethnic origin, religion, trade union membership, sexual orientation or similar categories, you need an Article 6 basis and a separate Article 9 condition. The record should show both. Criminal offence data has its own rules under Article 10 and national law.

This is where many records fall short. A HR entry that lists sickness absence should not stop at “contract”. It should identify the Article 9 condition relied on, often related to employment obligations under national law. See HR processing in the ROPA for how to describe employee entries accurately.

Keeping purposes and bases consistent with your other documents

The record, the privacy notice, your DPIAs and your contracts must tell the same story. When you add a new purpose, update every document that mentions it. When a basis changes, work out whether the change is allowed at all: switching from consent to legitimate interests after the event is usually not acceptable if you told people consent was the basis.

Build a short consistency check into your ROPA review process. Sample a few entries each quarter and compare them against the notice. Mismatches found by you are easy to fix. Mismatches found by a regulator are not. A regulator request for the record often starts with exactly this comparison.

Common mistakes with ROPA purposes and lawful bases

One mistake is using a single generic purpose for a whole department. Another is choosing legitimate interests everywhere without any balancing test on file. A third is treating consent as the default and then continuing to process after it is withdrawn. Others include forgetting the Article 9 condition, leaving the basis field blank for older entries and copying wording from a template without checking it fits.

Also watch for purposes that have quietly grown. A system bought for customer service may later be used for marketing analytics. If the record still lists only the first purpose, either the record is out of date or the new use has no documented basis. Both need attention.

Reviewing ROPA purposes and lawful bases each quarter

Set a fixed rhythm for reviewing ROPA purposes and lawful bases, because they drift faster than any other field. Each quarter, ask process owners three things: has anything new been done with this data, has anything stopped, and has the reason for doing it changed? Record the answers even when nothing has changed, so the review itself is evidence.

Pay special attention to projects that launched since the last review. New tools, new marketing campaigns and new analytics uses are the usual sources of unrecorded purposes. A simple intake question in your project process, asking whether personal data is involved and which purpose and basis apply, catches most of them before they go live.

Finally, keep a short log of changes to purposes and bases with dates and reasons. If a regulator or auditor asks why an entry changed, you can answer in a sentence. Accurate ROPA purposes and lawful bases are not about perfect first drafts; they are about showing that someone is paying attention and correcting the record when reality moves.

One more practical point on scope: the same discipline applies to processors. If you process data for a client, the purposes are set by that client, and your record should reflect the instructions you actually received rather than your own assumptions. Keep the contract reference next to each entry so the source of the purpose is clear.

Lastly, train the people who fill in the record. A thirty-minute session with examples of good and poor purposes, and a one-page guide to the six bases, prevents most of the errors described above and makes later reviews much faster.

A short worked example

Take a subscription business. Its customer entry has the purpose “creating accounts, billing subscribers and providing the service” with the basis contract. A second entry covers “sending product update emails to existing customers” with legitimate interests, plus a note that an opt-out is offered and the assessment is filed. A third covers “prospect newsletters” with consent, linked to the sign-up form. A fourth covers “retaining invoices for tax purposes” with legal obligation, linked to the retention schedule.

Each entry is short and specific, and each can be defended. That is the aim. The four entries also point to the right supporting documents, so a reviewer can follow the trail without asking anyone.

A ready structure for the record

If you want purposes, bases, categories, recipients, transfers and retention laid out in one working register, the ROPA Report and Workbook provides the Article 30 fields with guidance and a workbook you can maintain. Whatever format you use, the test for ROPA purposes and lawful bases is whether each entry can be explained in a sentence and matches what people were told.

ROPA purposes and lawful bases FAQ

Must the ROPA list the lawful basis?

Article 30 requires purposes but not the lawful basis as a named field. Many regulators and auditors still expect it, and recording it helps you spot gaps and keep the record aligned with notices.

Can one entry have more than one lawful basis?

Usually each distinct purpose should have its own basis. If you have two genuinely different purposes for the same data, create two entries rather than blending them.

How specific should a purpose be?

Specific enough that a data subject would recognise it and a reviewer could tell whether a new use falls within it. Generic labels like “operations” are too vague.

Do we need to record the Article 9 condition?

If the entry includes special category data, yes. Record both the Article 6 basis and the Article 9 condition so the record shows why the processing is allowed.

What if the basis is unclear for an old entry?

Work out the real basis with the process owner and legal advice, document the reasoning and update the privacy notice if needed. Do not leave the field blank.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.