Skip to content

Personal data

A personal data entry answers the “what” of a processing activity: which category of information it handles, how long that information is kept, how it is disposed of, and whether it falls under special-category protection. Together the entries of a processing form the data inventory inside your ROPA.

Privacy → Personal Data in the sidebar shows every entry across the domains you can see. Add Personal Data creates one; you can also work inside a single processing from its Personal Data tab.

FieldNotes
ProcessingRequired — an entry always belongs to exactly one processing and inherits its domain
CategoryThe kind of data: name, email, location, health record, and so on. Drawn from Terminologies, so you can add categories that match your own data dictionary
Custom nameOptional free-text name when the category alone is too coarse, e.g. “employee bank details”
DescriptionWhat exactly is stored, and where it comes from
RetentionHow long the data is kept — a free-text period so you can record “3 years after contract end” as easily as “24 months”
Deletion policyHow it goes away when retention expires
Is sensitiveFlags special-category data
AssetsThe assets that actually hold this data
  • Automatic Deletion — a scheduled job removes the record.
  • Anonymization — the record survives, the link to the individual does not.
  • Manual Review Deletion — a human decides at the end of the retention period.
  • User Requested Deletion — removed only on a data-subject request.
  • Legal/Regulatory Hold — retained because the law requires it.
  • Partial Deletion — some fields are purged, others kept.

Ticking Is sensitive does more than colour a row: the parent processing’s Has sensitive personal data flag switches on automatically as soon as one of its entries is sensitive, and back off when the last one goes. That is the flag you filter on when deciding which activities need a DPIA.

The list shows Category, Is sensitive, Retention, Deletion policy, Custom name, Assets and Processing, and filters by processing and category. Sorting by retention is a quick way to find entries where nobody ever decided how long to keep the data.

Linking entries to assets is what turns the register from a paper exercise into something operational: once a personal-data category points at the database or SaaS application that stores it, a breach on that asset immediately tells you which data categories and which processings are in scope.