Data protection · Art. 30 GDPR

The record of processing activities in the system – not in a spreadsheet.

Legal bases as a catalogue rather than a letter code, retention periods with a trigger rather than free text, a third-country check that warns, and a field-level record that outlives the deletion of the processing activity.

Art. 30 fully covered 72 h notification deadline tracked PDF · CSV · JSON export for the authority
# Processing activity: recruitment management
Legal basis  Art. 6(1)(b)
 └─ Specific statute  § 26 BDSG

Data subjects × data
 Applicants × Health data  Art. 9 → check
 Applicants × Contact data

Retention   6 months from purpose ceasing to apply
Recipient Applicant portal (US)  DPF evidence?
Fundamentals

What is a record of processing activities?

The record of processing activities (RoPA) is the documentation required by Art. 30 GDPR of every operation in which an organisation processes personal data – with purpose, legal basis, categories of data subjects and data, recipients, third-country transfers and retention periods.

As a rule it is the first piece of evidence a supervisory authority asks for – and at the same time the one where it most often becomes apparent that the documentation has not matched reality for years.

Who has to keep one?

Practically every organisation. The much-quoted exemption for bodies with fewer than 250 employees hardly ever applies: it lapses as soon as the processing is not occasional , where there is a risk to data subjects, or where special categories under Art. 9 are processed. Anyone who employs staff normally meets the first condition already.

Why a template is not enough

A spreadsheet template accepts any entry. It accepts „legitimate interest“ without the balancing test that then becomes mandatory. It allows a recipient in a third country without asking for the safeguard under Chapter V. And it keeps no record of who changed which field from which value to which, and when.

Those are precisely the three points a supervisory authority checks. Ordivis Platform therefore enforces them in the workflow instead of mentioning them in a set of filling instructions.

The difference: processing activities hang on real systems

Pure data protection tools keep a record of their own with no link to the IT landscape. „Applicant portal“ then stands there as text, and nobody notices when the system behind it is replaced. In Ordivis Platform the record sits alongside the CMDB and ISMS – technical and organisational measures do not have to be documented twice, and changes to the landscape stay visible.

Feature scope

What the data protection module does

No add-on module – included in the full feature set of every licence.

  • A dedicated data protection officer role with its own hub in the client
  • Record under Art. 30(1): purpose, legal basis, categories, recipients, retention periods
  • Legal bases under Art. 6(1) as a catalogue – in plain words, not as a letter code
  • For legitimate interest (point f) the balancing test is mandatory – otherwise a finding is raised
  • Specific statutes can be added: BDSG, LDSG, works and group agreements with a citation
  • Special categories (Art. 9) and criminal-offence data (Art. 10) supplied as a catalogue
  • A matrix of data subject group × data category – „health data of applicants“, not two loose lists
  • Retention periods as duration + trigger (collection, end of contract, end of year, purpose ceasing to apply, withdrawal), per data category
  • Recipients & third countries (Art. 30(1)(d)/(e)): role under Art. 28/26, country of establishment, safeguard under Chapter V
  • A warning on a third country without a safeguard (Art. 44), and DPF evidence for the USA
  • Reporting of a personal data breach (Art. 33/34) with the 72-hour deadline running from becoming aware
  • No closure while a reporting duty is open; not reporting requires a justification (Art. 33(5))
  • Export for the supervisory authority as PDF, CSV or JSON – gaps are shown, not hidden
  • Field-level change record: who, when, which field, from which value to which (Art. 5(2))
  • The record outlives the deletion of the processing activity
  • Departments report for themselves: a portal wizard in everyday language, the draft going to the data protection officer
  • Audience profiles SME / enterprise / public administration per processing activity
Two details that make the difference

Where records fail an inspection

The 72-hour deadline runs from becoming aware

Not from the incident. This confusion regularly costs compliance with the deadline, because internally the count starts from the date of the event. Ordivis Platform runs the clock from awareness and does not let a case be closed while a reporting duty is open.

The adequacy decision applies to the body, not the country

Under the Data Privacy Framework for the USA it is not the country that is certified but the individual company. An entry „USA – DPF“ without evidence for the specific recipient is therefore worthless. Ordivis Platform asks for the evidence per recipient and warns on a third-country transfer without a safeguard under Art. 44.

Frequently asked questions about the record of processing activities

Answered briefly and honestly

What is a record of processing activities?

The record of processing activities (RoPA) is the documentation required by Art. 30 GDPR of every operation in which an organisation processes personal data – with purpose, legal basis, categories of data subjects and data, recipients, third-country transfers and retention periods. It is the first piece of evidence a supervisory authority asks for.

Who has to keep a record of processing activities?

Practically every organisation. The much-quoted exemption for fewer than 250 employees hardly ever applies: it lapses as soon as the processing is not occasional, where there is a risk to data subjects, or where special categories under Art. 9 are processed. Anyone who employs staff as a rule meets the first criterion already.

Why is a spreadsheet template not enough?

A template checks nothing. It accepts „legitimate interest“ without the balancing test that then becomes mandatory, it does not notice when a third-country recipient is entered without a safeguard under Chapter V, and it keeps no record of who changed which field and when. Those are precisely the three points a supervisory authority asks about.

How does Ordivis Platform support retention periods?

Retention periods are not captured as free text but as a duration plus a trigger – from collection, end of contract, end of year, purpose ceasing to apply or withdrawal – and per data category rather than in the round per processing activity. That is the difference between a statement you can act on and one that merely looks good.

What happens in the event of a personal data breach?

The reporting process under Art. 33 and 34 runs the 72-hour deadline from becoming aware – not from the incident, which is regularly confused. While a reporting duty is open the case cannot be closed; a deliberate decision not to report requires a documented justification under Art. 33(5).

Can departments report for themselves?

Yes. A wizard in the self-service portal asks in everyday language what a department knows about its processing. The submission goes as a draft to the data protection officer, who reviews and approves it – so the record is created where the knowledge sits, without giving up expert control.

What does the supervisory authority get?

An export as PDF, CSV or JSON. It shows existing gaps rather than papering over them – a record that looks complete but has silent blanks is the worse outcome in a conversation with a supervisory authority.

Does the software replace the data protection officer?

No. It structures their work, keeps the record and prevents typical formal errors. The legal assessment – whether a balancing test holds, for instance – remains an expert decision.

Related

Data protection hangs on the inventory data

ISMS software

Technical and organisational measures and risks in the same system – no duplicate documentation.

CMDB software

Processing activities hang on real systems – not on free text in a spreadsheet.

Municipal & critical infrastructure

Why public administrations have to think of the record, Grundschutz and budget predictability together.

See the record on real processing activities.

From the legal basis through the retention logic to the export for the authority – in a demo by video conference.