Records management:

3.Record of processing activities

On this page:

    Introduction

    All data controllers are required to keep a record of processing activities (RoPA) to comply with general data protection regulation (GDPR). The record should include:

    • name and contact details of the data controller
    • purpose of processing the data
    • categories of the data subjects and types of personal data
    • categories of data recipients, including those who have already received a user’s data and those who will receive a user’s data in the future
    • transfers of data to a third country or an international organisation
    • time limits for erasure of different categories of data
    • a general description of technical and organisational security measures.

    Service documents

    You can find the record of processing activities for each service below:

    Loading asset information...
    Employee confidential helpline

    0330 380 0658

    Speak to fully qualified counsellors and support specialists at any time, 365 days a year.

    Use code 107574 to access the online resources.

    More about the employee assistance programme

    Loading news articles...
    Search the phonebook
    Search by first or last name, extension number, service name such as 'council tax' or venue such as 'Bridlington library'

    Alerts