Processings (ROPA)
A processing is one activity that operates on personal data — collecting it, storing it, sharing it, deleting it. The processings register is your Record of Processing Activities (ROPA): the Article 30 document a supervisory authority can ask for, kept as live objects instead of a stale spreadsheet. Everything else in the privacy register hangs off a processing.
Where to find it
Section titled “Where to find it”Privacy → Processings in the sidebar. Add Processing creates one.
The processing record
Section titled “The processing record”| Field | Notes |
|---|---|
| Domain | Scopes permissions; children inherit it |
| Perimeters | The perimeters this activity belongs to |
| Ref ID / Name / Description | Identity of the activity in business terms |
| Nature | What the activity does — collection, storage, disclosure, erasure. Drawn from Terminologies, so you can use your own wording |
| Status | Draft, In review, Approved or Deprecated |
| Assigned to | The people accountable for keeping the entry accurate |
| DPIA required / DPIA reference | Flag the activity for a data protection impact assessment and point at the study |
| Associated controls | The applied controls that protect this activity |
| Evidences | Supporting documents |
| Labels | Filtering labels |
Has sensitive personal data is computed, not typed: it turns on automatically as soon as any personal-data entry under the processing is marked sensitive.
The list shows Ref ID, Name, Description, Status, Nature, Labels and Domain, and you can add Personal data categories, Data subject categories and Updated at as optional columns. Filters cover domain, status, nature, personal-data category, data-subject category and labels — enough to answer “which activities touch health data?” without leaving the table.
The sub-registers
Section titled “The sub-registers”Open a processing and the detail page carries a tab per sub-register. This is where the substance of the ROPA lives:
- Purposes — one per lawful reason, each with its Article 6 legal basis. See Purposes.
- Personal data — the categories involved, their retention and deletion policy. See Personal data.
- Data subjects — who the data is about: customer, prospect, employee, job applicant, contractor, business partner, app user, visitor, child or minor, vulnerable person, general public.
- Data recipients — who receives it, from internal teams and subsidiaries through service providers, payment processors and analytics providers to auditors, regulators and courts.
- Data contractors — third parties processing on your behalf. Each links to an entity from the third-party register and records a relationship type: Data processor, Sub-processor, Joint controller, Independent controller or Other, plus the country and a documentation link.
- Data transfers — flows outside the original jurisdiction, with the destination country and the Chapter V mechanism that legitimises them: Adequacy decision (Art. 45), Standard contractual clauses (Art. 46.2c), Appropriate safeguards (Art. 46), Binding corporate rules (Art. 47), Codes of conduct, Certification mechanisms, or a Derogation (Art. 49). The Guarantees field is where you describe the safeguards in place.
- Right requests — read-only here; requests that named this processing. See Right requests.
- Applied controls, Evidences and Documents — the operational and documentary backing.
Exporting a processing
Section titled “Exporting a processing”The detail page has an Export XLSX button that writes the processing and every sub-register to a multi-sheet workbook — handy for sending an authority a single activity, or for reviewing a record offline with people who do not have an account.
Related
Section titled “Related”- Privacy overview — how the register fits together.
- Third parties — the entities behind data contractors.
- Documents — attach the notices and contracts behind a processing.
