The controller vs processor ROPA question comes up as soon as a business that provides services to other businesses starts its records of processing. Article 30 of the GDPR asks for two different records: one for processing you carry out as a controller, and a shorter one for processing you carry out on behalf of others. Most service providers need both. This guide sets out what each must contain, how they differ, and how to decide which record an activity belongs in.
For the obligation itself and why the small business exemption rarely helps, start with our guide to records of processing. The legal text is Article 30 of the GDPR, paragraphs 1 and 2; the UK GDPR has the same wording.

Controller vs Processor ROPA at a Glance
| Content | Controller record, Article 30(1) | Processor record, Article 30(2) |
|---|---|---|
| Who is named | The controller, any joint controller, the representative and the DPO | The processor, each controller it acts for, their representatives and DPOs |
| Organized by | Processing activity and purpose | Controller (client), or group of clients using the same service |
| Purposes | Required | Not required: the purposes are the controller’s |
| Data subjects and data | Categories of each, required | Not listed separately; described through the categories of processing |
| What is done | Implied by the purpose | Categories of processing carried out for each controller, required |
| Recipients | Categories of recipients, required | Not required, but sub-processors are usually recorded |
| Transfers outside the EEA or UK | Required, with the country and, for some derogations, the safeguards | Required, on the same terms |
| Retention | Time limits for erasure, where possible | Not required: the controller sets it |
| Security measures | General description, where possible | General description, where possible |
The pattern is simple. A controller records why and whose data; a processor records for whom and what it does. The controller vs processor ROPA split follows the split of responsibility in the GDPR itself.
Which Record Does an Activity Belong In?
Ask who decides the purpose and the essential means. If you decide why the data is processed, it goes in your controller record. If a client decides and you act on its documented instructions, it goes in your processor record. The European Data Protection Board’s guidelines on the concepts of controller and processor use the same test.
- Your staff, your customers, your suppliers. Controller record, always. Every business is a controller for its own HR, finance and customer data.
- Your client’s customers’ data that you host, process or support. Processor record, if you act only on the client’s instructions.
- Using a client’s data for your own purposes, such as improving your product or training a model. Controller record, and check that the contract allows it; a processor that decides its own purposes becomes a controller for that processing under Article 28(10).
- Deciding purposes together with another organization. Controller record, naming the joint controller, with an Article 26 arrangement behind it.
What a Processor ROPA Entry Looks Like
| Field | Example entry |
|---|---|
| Controller and contact | Retail clients using the parcel delivery service; each client’s privacy contact in the client register |
| Categories of processing | Delivering parcels to the client’s customers: names, addresses, phone numbers, delivery instructions, proof of delivery |
| Sub-processors | Transport management system provider; telematics provider |
| Transfers | None outside the EEA |
| Security measures | General description, as in the controller record |
| Contract | Data processing agreement with the Article 28(3) terms in every client contract |
Grouping clients who buy the same standard service keeps the processor record manageable. A client with a bespoke service, or with special category data, deserves its own entry.
Controller vs Processor ROPA: Common Mistakes
- A service provider with only a processor record. It still employs people and has customers, so it needs a controller record too.
- Copying the client’s purposes into the processor record. They belong in the client’s record; yours describes what you do for them.
- No list of sub-processors. Article 30(2) does not name them, but Article 28 requires the controller’s authorisation for each one, and the record is where you keep track.
- Forgetting transfers by sub-processors. A support team or hosting region outside the EEA is a transfer that the processor record has to show.
- Treating product analytics on client data as processor work. If you decide to do it for your own purposes, it is controller processing.
Controller vs Processor ROPA for SaaS and Service Providers
Software and service companies feel the controller vs processor ROPA split most sharply, because the same platform holds data in both roles. A typical SaaS provider is:
- A controller for its account holders’ contact and billing details, its marketing lists, its website analytics, its support tickets about the account, and its own staff.
- A processor for everything its customers upload or collect through the platform, such as their end users’ records, files and messages.
- Possibly a controller again for aggregated usage analytics or security logs, if it uses them for its own purposes such as improving the service, and the contract and privacy notice allow it.
The cleanest way to handle this is to write the controller record first, by department like any other business, then add one processor entry per service line. Where a use of customer data sits in the grey zone, record the decision and the reason: auditors and enterprise customers ask about exactly these cases, and a documented answer saves a long exchange of questionnaires.
A Step-by-Step Approach to Both Records
- List your own activities. HR, finance, customers, marketing, IT and security, legal: these always go in the controller record.
- List your services. For each, ask whether you act on the client’s instructions. If yes, add a processor entry.
- Map your sub-processors. Hosting, support, email and analytics providers used to deliver each service, and where they are.
- Check the contracts. A data processing agreement with each client and each sub-processor, with the Article 28(3) terms.
- Record the grey cases. Any use of client data for your own purposes goes in the controller record with its lawful basis.
Done in this order, the controller vs processor ROPA question answers itself for most activities, and the few that remain are the ones that genuinely need a legal view.
Keeping Both Records Current
The controller record changes when your own processes change; the processor record changes when you win or lose a client, change a service, or add a sub-processor. Tie the processor record to your client onboarding and your sub-processor change notices, and review both at least once a year. Article 30(4) requires both to be made available to the supervisory authority on request.
Frequently Asked Questions
Does the controller vs processor ROPA distinction apply under the UK GDPR?
Yes. Article 30 of the UK GDPR has the same two records with the same contents, and the ICO publishes documentation templates for controllers and for processors.
Can both records live in one spreadsheet?
Yes, on separate sheets or clearly separated sections. The contents differ, so mixing them in one table leaves empty columns and confuses readers.
Do processors with fewer than 250 employees need a record?
The Article 30(5) exemption applies to processors too, on the same conditions. Processing for clients is usually regular rather than occasional, so the exemption rarely applies.
Who is liable if the processor record is missing?
The processor. Article 30(2) is the processor’s own obligation, and breaches of Article 30 fall under the fines in Article 83(4).
Our free ROPA template keeps the controller and processor records side by side and flags missing contents in each, and our ROPA example shows both filled in for one company. For contracts with your clients and sub-processors, see the GDPR data processing agreement guide and the GDPR Toolkit.