
In this section
Managing Records
Create processing activities — purpose, legal basis, data categories, recipients, transfers, retention — and keep them current.
Reports & Export
Generate GDPR Article 30 reports, controller vs. processor views, and regulator-ready exports.
Auto-population from the data map
RoPA entries are created and updated automatically from the data map. When a new data store is discovered or an existing one changes, the corresponding processing activity record updates without manual intervention. Every Article 30 mandatory field is captured for both controllers and processors:- Processing purposes and data categories
- Categories of data subjects and recipients
- International transfers and their mechanisms
- Retention periods
- Technical and organizational security measures
Workflow
Connect data sources
Integrations feed data discovery, which drafts processing activity records automatically.
Enrich records
Business and legal teams complete purposes, legal bases, retention, and security measures with guided forms that flag missing mandatory fields.
Review and validate
The DPO and legal team approve each record; approvals are tracked per processing activity with who validated what and when.
Multi-entity RoPAs
Manage separate RoPAs for multiple legal entities, controller–processor relationships, and joint controller arrangements from a single interface. View them individually for entity-level compliance or consolidated for group reporting.Export and reporting
Export a fully formatted, printable RoPA on demand in PDF, Excel, or CSV. The export includes all Article 30 fields and is structured to match templates issued by major European DPAs — ready to hand over during an audit or investigation.Under GDPR Article 30, the small-organization exemption is narrow: it does not apply if processing is risky, non-occasional, or involves special category data. Most businesses should maintain a RoPA regardless of headcount.