Skip to content

Processings (ROPA)

A processing is one activity that operates on personal data — collecting it, storing it, sharing it, deleting it. The processings register is your Record of Processing Activities (ROPA): the Article 30 document a supervisory authority can ask for, kept as live objects instead of a stale spreadsheet. Everything else in the privacy register hangs off a processing.

Privacy → Processings in the sidebar. Add Processing creates one.

FieldNotes
DomainScopes permissions; children inherit it
PerimetersThe perimeters this activity belongs to
Ref ID / Name / DescriptionIdentity of the activity in business terms
NatureWhat the activity does — collection, storage, disclosure, erasure. Drawn from Terminologies, so you can use your own wording
StatusDraft, In review, Approved or Deprecated
Assigned toThe people accountable for keeping the entry accurate
DPIA required / DPIA referenceFlag the activity for a data protection impact assessment and point at the study
Associated controlsThe applied controls that protect this activity
EvidencesSupporting documents
LabelsFiltering labels

Has sensitive personal data is computed, not typed: it turns on automatically as soon as any personal-data entry under the processing is marked sensitive.

The list shows Ref ID, Name, Description, Status, Nature, Labels and Domain, and you can add Personal data categories, Data subject categories and Updated at as optional columns. Filters cover domain, status, nature, personal-data category, data-subject category and labels — enough to answer “which activities touch health data?” without leaving the table.

Open a processing and the detail page carries a tab per sub-register. This is where the substance of the ROPA lives:

  • Purposes — one per lawful reason, each with its Article 6 legal basis. See Purposes.
  • Personal data — the categories involved, their retention and deletion policy. See Personal data.
  • Data subjects — who the data is about: customer, prospect, employee, job applicant, contractor, business partner, app user, visitor, child or minor, vulnerable person, general public.
  • Data recipients — who receives it, from internal teams and subsidiaries through service providers, payment processors and analytics providers to auditors, regulators and courts.
  • Data contractors — third parties processing on your behalf. Each links to an entity from the third-party register and records a relationship type: Data processor, Sub-processor, Joint controller, Independent controller or Other, plus the country and a documentation link.
  • Data transfers — flows outside the original jurisdiction, with the destination country and the Chapter V mechanism that legitimises them: Adequacy decision (Art. 45), Standard contractual clauses (Art. 46.2c), Appropriate safeguards (Art. 46), Binding corporate rules (Art. 47), Codes of conduct, Certification mechanisms, or a Derogation (Art. 49). The Guarantees field is where you describe the safeguards in place.
  • Right requests — read-only here; requests that named this processing. See Right requests.
  • Applied controls, Evidences and Documents — the operational and documentary backing.

The detail page has an Export XLSX button that writes the processing and every sub-register to a multi-sheet workbook — handy for sending an authority a single activity, or for reviewing a record offline with people who do not have an account.