So, how well do you know what personal data your organisation processes? That is one of the questions a Record of Processing Activities (RoPA) is designed to help answer.
Under Section 60 of Botswana’s Data Protection Act, 2024, data controllers are required to maintain a record of their processing activities. Data processors are also required to maintain records of the categories of processing activities they carry out on behalf of data controllers.
For healthcare organisations in particular, this visibility is critical. Patient registration, consultations, medical records, billing, laboratory services, referrals, communications and digital health platforms can all involve the processing of personal and sensitive personal data.
The RoPA helps an organisation answer a simple but important question:
“What personal data are we processing, why are we processing it, where does it go, and how are we protecting it?”
What Should a RoPA Contain?
Section 60(2) of the Data Protection Act sets out the information that a controller’s RoPA should contain.
This includes:
- The name and contact details of the data controller and, where applicable, joint controllers, the controller’s representative and the Data Protection Officer
- The purpose of the processing
- The categories of data subjects and personal data
- The categories of recipients to whom personal data is or will be disclosed
- Applicable transfers of personal data to third countries or international organisations, including relevant safeguards
- Where possible, the envisaged time limits for erasure of different categories of data
- Where possible, a general description of the technical and organisational measures used to protect personal data
For processors, Section 60(3) requires records covering the processing activities carried out on behalf of each controller, together with the other information specified by the Act.
How Do You Create and Maintain a RoPA?
1. Identify Your Processing Activities
Start by identifying how your organisation uses personal data.
Look across departments and business functions and consider activities such as:
- Patient registration
- Appointment scheduling
- Medical consultations
- Electronic health records
- Billing and payments
- Staff and recruitment records
- Marketing and communications
- CCTV
- Customer support
- Laboratory and diagnostic services
- Sharing information with external service providers
2. Document the Purpose of Each Activity
For every processing activity, clearly document why the organisation processes the information.
For example, a healthcare organisation may process a patient’s identification and contact information to register the patient and manage their care.
It is also good practice to document the applicable lawful basis and, where relevant, the condition permitting the processing of sensitive personal data. This helps connect each processing activity to the organisation’s wider compliance obligations.
3. Map Where the Data Goes
A useful RoPA should tell you more than what information you hold. It should help you understand the journey that information takes.
Mapping these flows can reveal risks that may otherwise be difficult to see, such as unnecessary access, excessive sharing, unknown third parties or international transfers that have not been properly documented.
4. Identify Recipients and Third Parties
Organisations rarely process personal data entirely on their own.
A healthcare organisation may share information with laboratories, insurers, pharmacies, technology providers, payment providers, consultants or other healthcare professionals.
The RoPA should therefore capture the relevant categories of recipients and, where applicable, international recipients.
This can also help organisations identify where appropriate data processing agreements, contractual safeguards or other privacy controls may be required.
5. Document Retention and Security Measures
A RoPA should help an organisation understand how long personal data is expected to be retained and how it is protected. Section 60 requires the envisaged erasure time limits to be recorded where possible, and requires, where possible, a general description of the technical and organisational measures used to protect personal data.
6. Review and Update the RoPA Regularly
A RoPA should never be treated as a document that is completed once and then forgotten.
Organisations change. New systems are introduced, new service providers are engaged, new information is collected and existing processing activities change.
Whenever there is a significant change to how personal data is collected, used, stored or shared, the RoPA should be reviewed and updated accordingly.
Who Can Help You Create and Maintain a RoPA?
The responsibility for creating and maintaining a RoPA rests with the organisation that processes personal data. With input from the different teams involved in processing activities, such as IT, HR, Finance, Marketing and Operations, a Data Protection Officer (DPO) can support this process by providing guidance, coordinating privacy activities, reviewing the RoPA and helping the organisation identify gaps or changes that need to be reflected in it.
For organisations that do not have dedicated internal privacy expertise, DPO-as-a-Service can provide ongoing professional support with privacy governance, compliance monitoring, documentation and other data protection activities.
Learn more about [DPO-as-a-Service] and how an outsourced Data Protection Officer can support your organisation.
Keeping the RoPA current ensures that it remains an accurate representation of the organisation’s processing activities. And importantly, under Botswana’s Data Protection Act, your RoPA is a record that must be made available to the Information and Data Protection Commission when requested.
For organisations operating in healthcare, where personal and sensitive personal data are central to everyday operations, that visibility is an essential part of responsible data protection.
Know your data. Understand your processing. Protect it better.

