A Record of Processing Activities is only useful if it is complete and current. TruePrivacy drafts records automatically from data discovery and gives your business and legal teams guided forms to finish them — with alerts when reality drifts from the record.
Processing activity record editor with Article 30 fields and completion status

Creating a processing activity

Records come into existence three ways:

Auto-drafted

Data discovery finds a new data store or flow and drafts the corresponding processing activity automatically.

Manual

Create a record directly — useful for offline processing such as paper records or CCTV.

Imported

Bring in an existing spreadsheet RoPA via the CSV import template; imported records are immediately editable.

What each record captures

Guided forms cover every field GDPR Article 30 requires, and flag anything missing:
FieldWhat to record
PurposeWhy the data is processed, in specific terms — “payroll administration”, not “HR”
Legal basisThe Article 6 basis (and Article 9 condition for special category data); India DPDP grounds where applicable
Data categoriesCategories of personal data and of data subjects — pre-filled from classification results
RecipientsInternal teams, processors, and third parties who receive the data, linked to Vendor Risk
International transfersDestination countries and the transfer mechanism relied on (adequacy, SCCs, and so on)
RetentionRetention period per data category, with the rationale
Security measuresThe technical and organizational measures protecting the data
“Legitimate interests” as a legal basis needs a documented balancing test. Attach it to the record — regulators ask for it.

Linking to data map assets

Each processing activity links to the concrete data map assets that implement it — systems, data stores, and flows:
  • Data categories stay accurate — classification results from data discovery flow into the linked record.
  • Recipients stay accurate — data flows to vendors appear on the record as they are observed.
  • Gaps become visible — data stores with no linked processing activity are flagged as unaccounted-for processing; records with no linked assets are flagged as potentially stale.

Keeping records current

1

Continuous change detection

When a connected system gains new data categories, a new integration appears, or a flow changes, the affected records are flagged for review automatically.
2

Owner notifications

Each record has an owner. Owners are notified of flagged changes and can update the record directly from the alert.
3

Review and validation

The DPO and legal team approve records; approvals are tracked per activity with who validated what and when. Set a periodic re-attestation cadence so every record is confirmed on schedule.

Multi-entity records

Maintain separate RoPAs for multiple legal entities, controller–processor relationships, and joint controller arrangements. Each record is scoped to an entity and a role (controller or processor — the required fields differ), and can be viewed per entity or consolidated for group reporting.
Assign record ownership to the business function that runs the processing, not to the privacy team. The privacy team reviews; the people closest to the processing keep the facts right.
Completed, validated records are what feed Reports & Export — a record flagged as incomplete will be visibly incomplete in the regulator-facing output too.