markdowneditor

Record of Processing Activities (ROPA)

Record of Processing Activities – all required fields

ISO & KepatuhanStandarGDPR Art.30gdprropa

Cara menggunakan: Any controller under GDPR. Art.30(1) prescribes the columns – keep all of them even when a cell is "none".

Pratinjau

Record of Processing Activities (ROPA)

GDPR Art.30 record – the mandatory inventory of every processing activity. Art.30(1) prescribes exactly which fields a controller's record must contain; regulators ask for this document on request.

FieldValue
Doc IDDOC-GDPR-NNN
Controller[legal entity]
DPO / contact@name
Last reviewedYYYY-MM-DD
Review cycle[quarterly / on change]
ClassificationInternal – contains processing map

Controller details

FieldValue
Name[legal entity + address]
Representative (if non-EU)[Art.27 rep]
DPO[name / contact, if appointed]

Processing activities

One row per activity – Art.30(1) requires all columns present:

#ActivityPurposeData subjectsData categoriesRecipientsThird-country transferRetentionTOMs ref
PA-01e.g. account managementservice deliverycustomersname, email, prefsinternal, [processor][SCCs / none][period]TOM-NN
PA-02

Lawful basis per activity

#Lawful basis (Art.6)Special category basis (Art.9)Notes
PA-01contract / consent / legitimate interest

Special category processing

ActivitySpecial dataArt.9 conditionDPIA ref

Data sharing & transfers

RecipientRole (proc/joint/ind.)MechanismLocation
[processor]processorDPA + SCC[country]

Processors' records (Art.30(2))

Processors keep their own record of processing on your behalf – verify they maintain one; list the responsible contracts here.

ProcessorServiceDPA signedTheir ROPA verified
YYYY-MM-DD[ ]

Maintenance

  • Updated on every new/changed processing activity
  • Reviewed at least [quarterly]
  • Available to supervisory authority on request
  • Aligned with DPIAs and legal register entries

Templat terkait