When a Data Protection Authority asks for your Record of Processing Activities, the answer should take minutes, not weeks. TruePrivacy generates fully formatted Article 30 reports from your live records, on demand.
RoPA report generation with format options and entity selection

Generating an Article 30 report

1

Choose the scope

Under RoPA → Reports, select the legal entity (or all entities consolidated), the role view, and optionally filter by business function or data category.
2

Pick the format

PDF for a printable, regulator-facing document; Excel or CSV for working data. See formats below.
3

Generate

The report is built from the current validated records, stamped with the generation date and the version of each included record.

Controller vs. processor views

Article 30 requires different fields depending on your role, and TruePrivacy renders each view accordingly:
Controller view (Art. 30(1))Processor view (Art. 30(2))
IdentityController and DPO contact detailsProcessor and DPO details, plus each controller processed for
ProcessingPurposes, data subject and data categories, recipientsCategories of processing carried out per controller
TransfersThird-country transfers and safeguardsThird-country transfers and safeguards
RetentionEnvisaged erasure time limits
SecurityGeneral description of technical and organizational measuresGeneral description of technical and organizational measures
Organizations that act as both — most SaaS businesses do — maintain both views, and each report renders only the fields required for its role.

Export formats

  • PDF — a printable, paginated document structured to match the RoPA templates issued by major European DPAs. This is the format to hand over in an audit.
  • Excel — one row per processing activity with all Article 30 fields as columns; useful for internal review cycles and annotation.
  • CSV — machine-readable export for feeding GRC tools or your own reporting.
Every export includes all mandatory Article 30 fields, the responsible entity, and per-record validation status.

Regulator-ready output

DPAs reviewing a RoPA typically check three things — and the export is built to pass each:
  1. Completeness — all mandatory fields are present per record; incomplete records are visibly flagged so you resolve them before an audit, not during one.
  2. Legal bases — the documented basis for every processing activity, with Article 9 conditions shown for special category data.
  3. Transfers — every international transfer lists its destination and safeguard mechanism.
Reports are point-in-time snapshots of a continuously updated record set. Each generated report is retained, so you can show exactly what your RoPA said on any past date — useful when an investigation concerns a historical period.
Schedule a quarterly PDF export to your DPO even when no regulator is asking. A standing review cadence catches drift early, and the archived snapshots become evidence of an actively maintained register.
An exported RoPA is itself a sensitive document — it maps your entire data estate. Share it through controlled channels and treat regulator requests as the trigger, not routine distribution.