All Masterclasses
    Past Masterclass April 16, 2026

    Data Inventory, Mapping and Records of Processing (RoPA) under Saudi PDPL

    The Record of Processing Activities (RoPA) is the operational backbone of a Saudi PDPL program: an organization cannot manage, protect, or govern personal data it has not first inventoried. This masterclass examines how to build and maintain a RoPA as a living system rather than a one-time compliance artifact, from identifying every processing activity across the business to validating and updating it as systems, vendors, and use cases change. It addresses what a compliant record must contain, how the RoPA triggers downstream obligations such as DPIAs and transfer assessments, and why it is the first artifact SDAIA typically requests in an audit.

    Presenters

    Richard Chudzynsky
    Richard Chudzynsky
    Partner, KONEXO/Eversheds Sutherland
    Aben Pagar
    Aben Pagar
    Head of Digital Risk Consulting, KONEXO/ Eversheds Sutherland

    Recording

    We'll email you the link and passcode.Read the Blog Post

    Key takeaways

    • The Record of Processing Activities (RoPA) is the operational backbone of a Saudi Personal Data Protection Law (PDPL) program. An organization cannot manage, protect, or govern personal data it has not first inventoried.
    • Maintaining a RoPA is a legal requirement under the PDPL and its Implementing Regulations, not an optional maturity artifact.
    • A compliant RoPA must capture a defined set of elements about each processing activity, established by the PDPL and Implementing Regulations.
    • Mature organizations extend the RoPA beyond the statutory minimum with additional governance fields, such as risk level, AI usage, and data volumes, to strengthen oversight.
    • Data mapping must reach every processing activity across all departments, treating each business process, such as a distinct recruitment or onboarding stage, as a separate activity rather than mapping at a high functional level.
    • Processing is not limited to active use. Any exposure to personal data, including shared access or email, can constitute processing that belongs in the RoPA.
    • The RoPA is a living document that must be updated continuously as systems, vendors, and use cases change. A static RoPA creates significant exposure in audits and regulatory reviews.
    • The RoPA acts as a trigger mechanism for downstream obligations, surfacing which activities require a DPIA, an LIA, a transfer assessment, or vendor due diligence.
    • The RoPA provides cross-border transfer visibility and should document data localization and hosting location, especially for cloud and external systems.
    • Retention schedules can be embedded in the RoPA so data is not kept beyond justified periods, and the RoPA is the map that makes data subject access requests (DSARs) and breach impact assessments possible.
    • Ownership is shared: business units own their processing activities, IT acts as custodian of systems and data, and the Data Protection Officer (DPO) provides oversight and methodological consistency.
    • The RoPA cannot be driven by the DPO or legal team alone. Executive and board-level buy-in is essential to keep it accurate and current.
    • Building a RoPA is resource-intensive, often spanning hundreds of processes and months of effort in large organizations, and the exercise frequently reveals broader gaps such as a missing vendor register.
    • Automation and AI can materially reduce the burden of discovery, mapping, and updates, but the RoPA remains a central control system for privacy, risk, and data governance rather than a one-time compliance document.

    Frequently Asked Questions