ROPA Template — Records of Processing Activities
Document all of your organization's personal data processing activities in a structured format, as mandated by Indonesia's PDP Law No. 27 of 2022.
In short
A ROPA (Records of Processing Activities) is the record of every personal data processing activity an organisation performs — what is processed, for what purpose, on what lawful basis, who receives it, and how long it is kept. Indonesia's PDP Law requires controllers to maintain such records, and a ROPA is their most practical form.
- Format
- XLSX
- Size
- —
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
Nearly every other PDP Law obligation depends on one thing that is often skipped: knowing what personal data your organisation actually holds. Without it, an erasure request cannot be answered with confidence, a breach notification deadline cannot be met, and an impact assessment has nothing to work from.
This template records that inventory per processing activity, not per system. The distinction matters: one HR system can host five processing activities with different lawful bases and retention periods, and recording it as a single row hides exactly the part that needs deciding.
Most Useful For
- Personal data controllers starting a PDP Law compliance programme
- Data protection officers needing a single inventory across business units
- Organisations preparing for a rising volume of data subject requests
What's Inside
Processing activity
Activity name, owning unit, processing purpose, and the systems involved.
Data & subject categories
Types of personal data processed, a flag for specific personal data, and data subject categories.
Lawful basis
The basis relied on for each activity, including a reference to consent evidence where relevant.
Recipients
Internal and external recipients, including processors and sub-processors.
Retention & disposal
Retention period with its justification, and the disposal method once it expires.
Cross-border transfer
Destination country, safeguard mechanism, and the assessment behind it.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| Law 27/2022 (PDP Law) | Record-keeping obligation | The controller's duty to record all personal data processing activities. |
| ISO/IEC 27701 | PIMS | A processing inventory as a foundational privacy information management control. |
| ISO/IEC 27001:2022 | Control A.5.9 | Inventory of information and associated assets, which overlaps the personal data inventory. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
How does a ROPA differ from an IT asset register?
An IT asset register records devices and systems; a ROPA records personal data processing activities. One server may appear once in the asset register while forming the backdrop to several distinct processing activities in the ROPA. They complement rather than replace each other.
How finely should activities be split?
Down to the level where lawful basis, data categories, or retention differ. If two activities share all three, merge them. If one differs, separate them — because that difference is what will later drive a different decision.
Who fills in the ROPA?
Process owners in each unit, coordinated by one person who keeps it consistent. A ROPA completed entirely by the IT team almost always misses on processing purpose and lawful basis, because both are business decisions rather than technical ones.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
Risk Register Template
Manage information security risk identification, assessment, and mitigation in one structured worksheet.
Free DownloadStatement of Applicability (SoA) Template — ISO 27001:2022
Document the applicability of all 93 ISO 27001:2022 Annex A controls along with their justifications.
Free DownloadInformation Security Policy Template
An organization-level information security policy framework ready to tailor to your business context.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.