
Creating a processing activity
Records come into existence three ways:Auto-drafted
Data discovery finds a new data store or flow and drafts the corresponding processing activity automatically.
Manual
Create a record directly — useful for offline processing such as paper records or CCTV.
Imported
Bring in an existing spreadsheet RoPA via the CSV import template; imported records are immediately editable.
What each record captures
Guided forms cover every field GDPR Article 30 requires, and flag anything missing:| Field | What to record |
|---|---|
| Purpose | Why the data is processed, in specific terms — “payroll administration”, not “HR” |
| Legal basis | The Article 6 basis (and Article 9 condition for special category data); India DPDP grounds where applicable |
| Data categories | Categories of personal data and of data subjects — pre-filled from classification results |
| Recipients | Internal teams, processors, and third parties who receive the data, linked to Vendor Risk |
| International transfers | Destination countries and the transfer mechanism relied on (adequacy, SCCs, and so on) |
| Retention | Retention period per data category, with the rationale |
| Security measures | The technical and organizational measures protecting the data |
Linking to data map assets
Each processing activity links to the concrete data map assets that implement it — systems, data stores, and flows:- Data categories stay accurate — classification results from data discovery flow into the linked record.
- Recipients stay accurate — data flows to vendors appear on the record as they are observed.
- Gaps become visible — data stores with no linked processing activity are flagged as unaccounted-for processing; records with no linked assets are flagged as potentially stale.
Keeping records current
Continuous change detection
When a connected system gains new data categories, a new integration appears, or a flow changes, the affected records are flagged for review automatically.
Owner notifications
Each record has an owner. Owners are notified of flagged changes and can update the record directly from the alert.
Multi-entity records
Maintain separate RoPAs for multiple legal entities, controller–processor relationships, and joint controller arrangements. Each record is scoped to an entity and a role (controller or processor — the required fields differ), and can be viewed per entity or consolidated for group reporting.Completed, validated records are what feed Reports & Export — a record flagged as incomplete will be visibly incomplete in the regulator-facing output too.