RoPA - Records of Processing Activities¶
The RoPA (Records of Processing Activities, Article 30 of the GDPR) lists what the organisation does with personal data.
Each activity¶
- Name of the activity (e.g. Customer management, Newsletter).
- Purpose and Legal basis.
- Categories of data subjects and of data.
- Recipients and any transfers.
- Retention period.
Step by step¶
- GDPR → RoPA tab.
- + Activity → fill in the fields.
- Save - it enters the compliance report.
Why it is mandatory
The RoPA is the map of data processing. It is the first document a supervisory authority asks for in an audit.
➡️ Next: Data breaches · back to GDPR.