Past Masterclass April 16, 2026
Data Inventory, Mapping and Records of Processing (RoPA) under Saudi PDPL
The Record of Processing Activities (RoPA) is the operational backbone of a Saudi PDPL program: an organization cannot manage, protect, or govern personal data it has not first inventoried. This masterclass examines how to build and maintain a RoPA as a living system rather than a one-time compliance artifact, from identifying every processing activity across the business to validating and updating it as systems, vendors, and use cases change. It addresses what a compliant record must contain, how the RoPA triggers downstream obligations such as DPIAs and transfer assessments, and why it is the first artifact SDAIA typically requests in an audit.
Presenters

Richard Chudzynsky
Partner, KONEXO/Eversheds Sutherland

Aben Pagar
Head of Digital Risk Consulting, KONEXO/ Eversheds Sutherland
Recording
We'll email you the link and passcode.Read the Blog Post
Key takeaways
- The Record of Processing Activities (RoPA) is the operational backbone of a Saudi Personal Data Protection Law (PDPL) program. An organization cannot manage, protect, or govern personal data it has not first inventoried.
- Maintaining a RoPA is a legal requirement under the PDPL and its Implementing Regulations, not an optional maturity artifact.
- A compliant RoPA must capture a defined set of elements about each processing activity, established by the PDPL and Implementing Regulations.
- Mature organizations extend the RoPA beyond the statutory minimum with additional governance fields, such as risk level, AI usage, and data volumes, to strengthen oversight.
- Data mapping must reach every processing activity across all departments, treating each business process, such as a distinct recruitment or onboarding stage, as a separate activity rather than mapping at a high functional level.
- Processing is not limited to active use. Any exposure to personal data, including shared access or email, can constitute processing that belongs in the RoPA.
- The RoPA is a living document that must be updated continuously as systems, vendors, and use cases change. A static RoPA creates significant exposure in audits and regulatory reviews.
- The RoPA acts as a trigger mechanism for downstream obligations, surfacing which activities require a DPIA, an LIA, a transfer assessment, or vendor due diligence.
- The RoPA provides cross-border transfer visibility and should document data localization and hosting location, especially for cloud and external systems.
- Retention schedules can be embedded in the RoPA so data is not kept beyond justified periods, and the RoPA is the map that makes data subject access requests (DSARs) and breach impact assessments possible.
- Ownership is shared: business units own their processing activities, IT acts as custodian of systems and data, and the Data Protection Officer (DPO) provides oversight and methodological consistency.
- The RoPA cannot be driven by the DPO or legal team alone. Executive and board-level buy-in is essential to keep it accurate and current.
- Building a RoPA is resource-intensive, often spanning hundreds of processes and months of effort in large organizations, and the exercise frequently reveals broader gaps such as a missing vendor register.
- Automation and AI can materially reduce the burden of discovery, mapping, and updates, but the RoPA remains a central control system for privacy, risk, and data governance rather than a one-time compliance document.
Frequently Asked Questions
Yes. Maintaining a RoPA is a legal requirement under the PDPL and its Implementing Regulations. The RoPA is the first artifact the Saudi Data and AI Authority (SDAIA) typically requests in audits and the foundation on which DPIAs, lawful basis determinations, DSAR responses, and transfer assessments depend.
A compliant RoPA must capture processing purpose, data categories, data subject categories, systems, recipients, lawful basis, retention period, and cross-border transfer details. Mature organizations add risk level, AI usage, data volumes, and hosting location to strengthen governance and trigger downstream obligations.
Business units own their processing activities, IT acts as custodian of the systems and data, and the DPO provides oversight and methodological consistency. The RoPA cannot be driven by the DPO or legal team alone, and executive and board-level buy-in is essential for the exercise to remain accurate and current.
The RoPA is a living document and must be updated continuously as new systems, vendors, or use cases are introduced. A static RoPA creates significant compliance risk in audits and regulatory reviews. Many organizations adopt a quarterly review cadence with mandatory updates triggered by material processing changes.
The Implementing Regulations require controllers to keep the RoPA during the processing activity and for a further five years after the activity ends. This obligation is specific to the PDPL and stricter than the equivalent under the GDPR, where no fixed retention period is prescribed for the record.
Without a complete RoPA, an organization cannot identify which activities require a DPIA, where data resides for DSAR responses, what flows across borders, or which vendors hold copies. Most downstream PDPL obligations depend on the RoPA being accurate, which makes it operational infrastructure rather than a standalone compliance artifact.
