Modules/Privacy Operations

ROPA Records

by Formiti's Global DPO Team

A structured register of processing activities (Article 30 GDPR) with entity-level ownership, legal basis tracking, data flow mapping, processor linkage, and AI Processor disclosure aligned to EU AI Act Article 50.

Who uses this module?

DPOs, Data Protection Managers, Compliance Analysts, Entity Controllers, AI Governance Leads.

What governance problem does it solve?

Privacy teams now face a dual obligation: maintaining an accurate Article 30 GDPR record of processing activities and, where AI systems are involved, disclosing AI processors in line with EU AI Act Article 50 transparency requirements. ROPA Records centralises both into a single living register with entity-level ownership, legal basis tracking, processor and AI processor linkage, DPIA triggers and audit trails — so the record supports Article 30(2)(d) processor disclosure and Article 50 AI transparency without duplicated tooling.

What are the key workflows?

  • Create and manage processing activity records per entity
  • Assign legal basis (Article 6) with supporting justification
  • Map data categories, data subjects, recipients, and retention periods
  • Link processors and sub-processors to specific activities
  • Disclose AI processors with Article 50 status, DPIA triggers, and tier classification
  • Track review dates and flag overdue records
  • Automatically open and pre-fill linked DPIA, LIA, transfer and AI governance assessments from the record's own data
Workflow sequence
1

Create and manage processing activity records per entity

2

Assign legal basis (Article 6) with supporting justification

3

Map data categories, data subjects, recipients, and retention periods

4

Link processors and sub-processors to specific activities

5

Disclose AI processors with Article 50 status, DPIA triggers, and tier classification

6

Track review dates and flag overdue records

7

Automatically open and pre-fill linked DPIA, LIA, transfer and AI governance assessments from the record's own data

AI Processor disclosure

Where a processing activity uses an AI system or AI-enabled vendor, ROPA Records captures the additional detail needed to evidence Article 30(2)(d) processor disclosure alongside EU AI Act Article 50 transparency obligations — in the same record, without a parallel spreadsheet.

  • Identify AI processors from the shared AI Governance vendor library, avoiding duplicated vendor entries
  • Record Article 50 transparency status (in scope, out of scope, or pending assessment)
  • Capture tier classification (prohibited, high-risk, limited-risk, minimal-risk) aligned to EU AI Act categories
  • Flag DPIA triggers automatically where AI use, profiling, or automated decision-making elevates risk
  • Attach model, purpose, input data category and output usage notes for each AI processor
  • Maintain change history so AI processor additions, removals, and reclassifications remain auditable

AI Processor fields sit inside the standard Article 30 record rather than in a separate register. That means one activity, one owner, one review cycle — with the AI-specific detail visible to DPOs, AI Governance Leads and auditors without switching context.

Exports include both the standard Article 30 columns and the AI Processor fields, so evidence packs for regulators, internal audit or client due diligence combine GDPR and EU AI Act reporting in a single artefact.

One record in, the right assessments out

Most privacy teams hold the same facts in four places — the ROPA, then a DPIA, then an LIA, then a transfer assessment — and re-key them every time something changes. Privacy360 treats the ROPA record as the source of truth. As the record is completed, the platform recognises the obligations it triggers, opens the correct assessment as a linked draft, and carries the ROPA data straight into it.

Source of truth

ROPA Record

High-risk processing

DPIA

Data Protection Impact Assessment

Drafted & pre-filled
Art. 6(1)(f) basis

LIA

Legitimate Interests Assessment

Drafted & pre-filled
Cross-border transfer

TIA

Transfer Impact Assessment

Drafted & pre-filled
AI system involved

AI Gov

AI register entry and framework assessment

Drafted & pre-filled
  • Legitimate interests selected as the Article 6 basis — a draft Legitimate Interests Assessment is created and pre-filled with the factual fields from the record, leaving the necessity, balancing and safeguards tests for human judgement
  • High-risk indicators present, such as large-scale special category data, systematic monitoring or profiling with legal effects — a draft Data Protection Impact Assessment is created and populated from the record
  • Personal data leaving the jurisdiction — a Transfer Impact Assessment is opened against that transfer, with recipient, destination and safeguard already carried across
  • An AI system in the processing chain — the activity flows into the AI Governance register with an assessment mapped to the relevant framework, alongside the Article 50 transparency and tier fields already held on the record
  • Purpose, data categories, data subjects, recipients, retention periods and transfer destinations populate the assessment automatically — the team completes the judgement, not the data entry

Every generated assessment stays linked to the ROPA record that created it and inherits that record's data residency region, so no assessment is written outside the data plane its parent record lives in.

When a triggering field on the ROPA record changes, the linked assessment is superseded or archived with a reason rather than deleted. The accountability trail survives the change, which is what a regulator or a customer's due-diligence team will ask to see.

Mandatory assessments are gating. A ROPA record cannot be approved while a required linked assessment remains incomplete, so the register cannot quietly drift into a state where the record says one thing and the evidence says another.

What evidence and reporting does it produce?

Built-in outputs for accountability and regulatory readiness

Complete Article 30 register exportable per entity or group-wide (29 columns including AI Processor fields)

Legal basis distribution analytics

Data flow summaries by category and jurisdiction

Review-date compliance dashboard

AI Processor register exportable alongside standard ROPA data for combined Article 30 / Article 50 reporting

Linked assessment trail showing which record triggered which assessment, when, and why — with superseded versions retained

How does it connect to other Privacy360 modules?

  • Entities feed into Assessments, Breach Management, and AI Governance
  • Processor linkages mirror Processor Records
  • Processing activities automatically create linked DPIA, LIA, transfer and AI assessments, pre-filled from the record and blocking approval until complete
  • AI Processor selections draw from the AI Governance vendor library
  • AI Processor tier and Article 50 status inform DPIA triggers automatically
  • ROPA data populates Privacy Document templates

What are some example use cases?

Privacy Team

A multinational maps 120 processing activities across 4 EU entities, each with distinct legal bases and retention schedules, in a single register.

Scenario 1
DPO

A DPO filters ROPA records by 'Consent' legal basis to audit all consent-dependent processing ahead of a regulatory review.

Scenario 2
DPO

A DPO reviews all processing activities using generative AI vendors, filtering by Article 50 transparency status and tier classification, to identify which require DPIA refreshes under the EU AI Act.

Scenario 3
Controller

An entity controller flags three activities as overdue for review, triggering internal remediation tasks.

Scenario 4
DPO

A DPO logs a new marketing analytics activity under legitimate interests with a US transfer; Privacy360 opens a pre-filled LIA and a pre-filled transfer assessment against that record, and blocks approval until both are signed off.

Scenario 5

Frequently asked questions

Does Privacy360 complete the DPIA and LIA for me?

No. Privacy360 creates the assessment and populates the factual fields already held on the ROPA record — purpose, data categories, data subjects, recipients, retention and transfers. The judgement elements, including necessity, proportionality, balancing and safeguards, remain with your privacy team. The platform removes the re-typing, not the accountability.

What happens to a linked assessment if the ROPA record changes?

The linked assessment is superseded or archived with a recorded reason rather than deleted, so the earlier version and the change that caused it remain available as evidence.

Can a ROPA record be approved with an outstanding assessment?

No, where the assessment is mandatory. Approval is gated until the linked assessment is complete, which prevents a register of approved records sitting alongside unfinished risk work.

Where is the generated assessment stored?

In the same regional data plane as the ROPA record that created it. Assessments inherit the parent record's residency, so a record held in a given region does not generate assessment data elsewhere.

Formiti processing records dashboard with a data map on a tablet

From data mapping to a reliable ROPA

A useful processing record starts with a clear view of where personal data comes from, how it moves and who owns each activity. Keep those details current and your ROPA becomes a foundation for reviews and assessments, not another static spreadsheet.

Read the data mapping guide

See the operational platform in action

Book a demo to see how Privacy360 brings assessments, records, consent, contracts, AI governance, training and evidence into one operational system tailored to your programme.

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.