Description
What the record contains
You already have your register, your record score and your findings for free. This is the finished record of processing activities behind them, laid out the way a supervisory authority, an auditor or a client’s due diligence team expects to read it.
- The controller, Article 30(1)(a). Your contact details, representative, data protection officer and joint controllers, with the Article 30(5) check that shows whether the record is required in full.
- The register at a glance. One line per activity: purposes, data subjects, lawful basis, sensitive data, recipients, transfers and retention, with the Article 30 gaps flagged.
- Every activity in full. One page per activity with each Article 30(1) content and its article reference, the lawful basis and any Article 9 or 10 condition, the source, processors and contracts, systems, signs of high risk, and the DPIA or LIA behind it.
- Your processor record, Article 30(2). Each controller you act for, the categories of processing, sub-processors, transfers, security measures and the contract in place.
- Every finding, with what closes it. Special category data without an Article 9 condition, transfers without a safeguard, missing Article 30 contents, legitimate interests without an LIA, likely high-risk processing without a DPIA, processors without a contract and retention with no real limit, each with the document from the GDPR Toolkit that closes it.
- Ownership and approval. Who keeps the record, the DPO’s review, the approval and the next review date.
- An AI-assisted analysis and 30/60/90-day roadmap. A one-sentence verdict, where you stand and what it means, a statement for senior management, three to five priorities and a roadmap, written from your own entries and checked automatically against them.
The Excel register
Processing changes whenever a process, a system or a supplier does, so you also get the record as a working file:
- Register: one row per activity in the column order supervisory authorities’ templates use, with drop-downs for the lawful basis, Article 9 conditions and transfer tools, and a check column that counts missing Article 30 contents as you type.
- Controller: the Article 30(1)(a) details, the Article 30(5) check and the approval.
- Transfers and Retention: the transfer schedule by country and tool, and the retention schedule with each time limit checked.
- Processor record and Findings: your Article 30(2) entries, and every finding with columns for an owner, a due date and completion.
How to get it
- Build your record with the free ROPA template: check whether Article 30 applies in full, add your activities from the library, complete each one, add your processor record and sign it off.
- Choose Get the full record. The PDF and workbook are in your account straight away, and they rebuild from your latest entries whenever you download them.
Built for controllers and processors under the EU GDPR and the UK GDPR. One record covers one organization.
One payment covers this record. Edit it as often as you like and download the updated files at no extra cost. This is a self-assessment built from the information you enter; it is not a certification, an audit opinion or legal advice.
NIST Cyber Risk Management Toolkit 







Reviews
There are no reviews yet