ROPA Records
by Formiti's Global DPO Team
A structured register of processing activities (Article 30 GDPR) with entity-level ownership, legal basis tracking, data flow mapping, processor linkage, and AI Processor disclosure aligned to EU AI Act Article 50.
Who uses this module?
DPOs, Data Protection Managers, Compliance Analysts, Entity Controllers, AI Governance Leads.
What governance problem does it solve?
Privacy teams now face a dual obligation: maintaining an accurate Article 30 GDPR record of processing activities and, where AI systems are involved, disclosing AI processors in line with EU AI Act Article 50 transparency requirements. ROPA Records centralises both into a single living register with entity-level ownership, legal basis tracking, processor and AI processor linkage, DPIA triggers and audit trails — so the record supports Article 30(2)(d) processor disclosure and Article 50 AI transparency without duplicated tooling.
What are the key workflows?
- Create and manage processing activity records per entity
- Assign legal basis (Article 6) with supporting justification
- Map data categories, data subjects, recipients, and retention periods
- Link processors and sub-processors to specific activities
- Disclose AI processors with Article 50 status, DPIA triggers, and tier classification
- Track review dates and flag overdue records
- Automatically open and pre-fill linked DPIA, LIA, transfer and AI governance assessments from the record's own data
Create and manage processing activity records per entity
Assign legal basis (Article 6) with supporting justification
Map data categories, data subjects, recipients, and retention periods
Link processors and sub-processors to specific activities
Disclose AI processors with Article 50 status, DPIA triggers, and tier classification
Track review dates and flag overdue records
Automatically open and pre-fill linked DPIA, LIA, transfer and AI governance assessments from the record's own data
AI Processor disclosure
Where a processing activity uses an AI system or AI-enabled vendor, ROPA Records captures the additional detail needed to evidence Article 30(2)(d) processor disclosure alongside EU AI Act Article 50 transparency obligations — in the same record, without a parallel spreadsheet.
- Identify AI processors from the shared AI Governance vendor library, avoiding duplicated vendor entries
- Record Article 50 transparency status (in scope, out of scope, or pending assessment)
- Capture tier classification (prohibited, high-risk, limited-risk, minimal-risk) aligned to EU AI Act categories
- Flag DPIA triggers automatically where AI use, profiling, or automated decision-making elevates risk
- Attach model, purpose, input data category and output usage notes for each AI processor
- Maintain change history so AI processor additions, removals, and reclassifications remain auditable
AI Processor fields sit inside the standard Article 30 record rather than in a separate register. That means one activity, one owner, one review cycle — with the AI-specific detail visible to DPOs, AI Governance Leads and auditors without switching context.
Exports include both the standard Article 30 columns and the AI Processor fields, so evidence packs for regulators, internal audit or client due diligence combine GDPR and EU AI Act reporting in a single artefact.
One record in, the right assessments out
Most privacy teams hold the same facts in four places — the ROPA, then a DPIA, then an LIA, then a transfer assessment — and re-key them every time something changes. Privacy360 treats the ROPA record as the source of truth. As the record is completed, the platform recognises the obligations it triggers, opens the correct assessment as a linked draft, and carries the ROPA data straight into it.
Source of truth
ROPA Record
DPIA
Data Protection Impact Assessment
Drafted & pre-filledLIA
Legitimate Interests Assessment
Drafted & pre-filledTIA
Transfer Impact Assessment
Drafted & pre-filledAI Gov
AI register entry and framework assessment
Drafted & pre-filled- Legitimate interests selected as the Article 6 basis — a draft Legitimate Interests Assessment is created and pre-filled with the factual fields from the record, leaving the necessity, balancing and safeguards tests for human judgement
- High-risk indicators present, such as large-scale special category data, systematic monitoring or profiling with legal effects — a draft Data Protection Impact Assessment is created and populated from the record
- Personal data leaving the jurisdiction — a Transfer Impact Assessment is opened against that transfer, with recipient, destination and safeguard already carried across
- An AI system in the processing chain — the activity flows into the AI Governance register with an assessment mapped to the relevant framework, alongside the Article 50 transparency and tier fields already held on the record
- Purpose, data categories, data subjects, recipients, retention periods and transfer destinations populate the assessment automatically — the team completes the judgement, not the data entry
Every generated assessment stays linked to the ROPA record that created it and inherits that record's data residency region, so no assessment is written outside the data plane its parent record lives in.
When a triggering field on the ROPA record changes, the linked assessment is superseded or archived with a reason rather than deleted. The accountability trail survives the change, which is what a regulator or a customer's due-diligence team will ask to see.
Mandatory assessments are gating. A ROPA record cannot be approved while a required linked assessment remains incomplete, so the register cannot quietly drift into a state where the record says one thing and the evidence says another.
What evidence and reporting does it produce?
Built-in outputs for accountability and regulatory readiness
Complete Article 30 register exportable per entity or group-wide (29 columns including AI Processor fields)
Legal basis distribution analytics
Data flow summaries by category and jurisdiction
Review-date compliance dashboard
AI Processor register exportable alongside standard ROPA data for combined Article 30 / Article 50 reporting
Linked assessment trail showing which record triggered which assessment, when, and why — with superseded versions retained
How does it connect to other Privacy360 modules?
- Entities feed into Assessments, Breach Management, and AI Governance
- Processor linkages mirror Processor Records
- Processing activities automatically create linked DPIA, LIA, transfer and AI assessments, pre-filled from the record and blocking approval until complete
- AI Processor selections draw from the AI Governance vendor library
- AI Processor tier and Article 50 status inform DPIA triggers automatically
- ROPA data populates Privacy Document templates
What are some example use cases?
A multinational maps 120 processing activities across 4 EU entities, each with distinct legal bases and retention schedules, in a single register.
A DPO filters ROPA records by 'Consent' legal basis to audit all consent-dependent processing ahead of a regulatory review.
A DPO reviews all processing activities using generative AI vendors, filtering by Article 50 transparency status and tier classification, to identify which require DPIA refreshes under the EU AI Act.
An entity controller flags three activities as overdue for review, triggering internal remediation tasks.
A DPO logs a new marketing analytics activity under legitimate interests with a US transfer; Privacy360 opens a pre-filled LIA and a pre-filled transfer assessment against that record, and blocks approval until both are signed off.
Frequently asked questions
Does Privacy360 complete the DPIA and LIA for me?
No. Privacy360 creates the assessment and populates the factual fields already held on the ROPA record — purpose, data categories, data subjects, recipients, retention and transfers. The judgement elements, including necessity, proportionality, balancing and safeguards, remain with your privacy team. The platform removes the re-typing, not the accountability.
What happens to a linked assessment if the ROPA record changes?
The linked assessment is superseded or archived with a recorded reason rather than deleted, so the earlier version and the change that caused it remain available as evidence.
Can a ROPA record be approved with an outstanding assessment?
No, where the assessment is mandatory. Approval is gated until the linked assessment is complete, which prevents a register of approved records sitting alongside unfinished risk work.
Where is the generated assessment stored?
In the same regional data plane as the ROPA record that created it. Assessments inherit the parent record's residency, so a record held in a given region does not generate assessment data elsewhere.
Related modules
Privacy Assessments
Run global privacy gap assessments, DPIAs, LIAs, transfer reviews and vendor assessments against 150+ controls — with structured rationale, evidence and AI-assisted review.
Processor Records
Maintain structured processor and sub-processor records with contract status, ownership and review evidence.
DSAR Requests
Manage data subject requests with workflow tracking, ownership, deadlines and response evidence.
Breach Management
Log, assess, and manage data breaches with incident workflows, notification tracking, and AI-assisted Breach Guidance.

From data mapping to a reliable ROPA
A useful processing record starts with a clear view of where personal data comes from, how it moves and who owns each activity. Keep those details current and your ROPA becomes a foundation for reviews and assessments, not another static spreadsheet.
Read the data mapping guideROPA Records guides
Practical articles from Formiti's Global DPO team on running this work well.