Legal bases as a catalogue rather than a letter code, retention periods with a trigger rather than free text, a third-country check that warns, and a field-level record that outlives the deletion of the processing activity.
# Processing activity: recruitment management Legal basis Art. 6(1)(b) └─ Specific statute § 26 BDSG Data subjects × data Applicants × Health data Art. 9 → check Applicants × Contact data Retention 6 months from purpose ceasing to apply Recipient Applicant portal (US) DPF evidence?
The record of processing activities (RoPA) is the documentation required by Art. 30 GDPR of every operation in which an organisation processes personal data – with purpose, legal basis, categories of data subjects and data, recipients, third-country transfers and retention periods.
As a rule it is the first piece of evidence a supervisory authority asks for – and at the same time the one where it most often becomes apparent that the documentation has not matched reality for years.
Practically every organisation. The much-quoted exemption for bodies with fewer than 250 employees hardly ever applies: it lapses as soon as the processing is not occasional , where there is a risk to data subjects, or where special categories under Art. 9 are processed. Anyone who employs staff normally meets the first condition already.
A spreadsheet template accepts any entry. It accepts „legitimate interest“ without the balancing test that then becomes mandatory. It allows a recipient in a third country without asking for the safeguard under Chapter V. And it keeps no record of who changed which field from which value to which, and when.
Those are precisely the three points a supervisory authority checks. Ordivis Platform therefore enforces them in the workflow instead of mentioning them in a set of filling instructions.
Pure data protection tools keep a record of their own with no link to the IT landscape. „Applicant portal“ then stands there as text, and nobody notices when the system behind it is replaced. In Ordivis Platform the record sits alongside the CMDB and ISMS – technical and organisational measures do not have to be documented twice, and changes to the landscape stay visible.
No add-on module – included in the full feature set of every licence.
Not from the incident. This confusion regularly costs compliance with the deadline, because internally the count starts from the date of the event. Ordivis Platform runs the clock from awareness and does not let a case be closed while a reporting duty is open.
Under the Data Privacy Framework for the USA it is not the country that is certified but the individual company. An entry „USA – DPF“ without evidence for the specific recipient is therefore worthless. Ordivis Platform asks for the evidence per recipient and warns on a third-country transfer without a safeguard under Art. 44.
The record of processing activities (RoPA) is the documentation required by Art. 30 GDPR of every operation in which an organisation processes personal data – with purpose, legal basis, categories of data subjects and data, recipients, third-country transfers and retention periods. It is the first piece of evidence a supervisory authority asks for.
Practically every organisation. The much-quoted exemption for fewer than 250 employees hardly ever applies: it lapses as soon as the processing is not occasional, where there is a risk to data subjects, or where special categories under Art. 9 are processed. Anyone who employs staff as a rule meets the first criterion already.
A template checks nothing. It accepts „legitimate interest“ without the balancing test that then becomes mandatory, it does not notice when a third-country recipient is entered without a safeguard under Chapter V, and it keeps no record of who changed which field and when. Those are precisely the three points a supervisory authority asks about.
Retention periods are not captured as free text but as a duration plus a trigger – from collection, end of contract, end of year, purpose ceasing to apply or withdrawal – and per data category rather than in the round per processing activity. That is the difference between a statement you can act on and one that merely looks good.
The reporting process under Art. 33 and 34 runs the 72-hour deadline from becoming aware – not from the incident, which is regularly confused. While a reporting duty is open the case cannot be closed; a deliberate decision not to report requires a documented justification under Art. 33(5).
Yes. A wizard in the self-service portal asks in everyday language what a department knows about its processing. The submission goes as a draft to the data protection officer, who reviews and approves it – so the record is created where the knowledge sits, without giving up expert control.
An export as PDF, CSV or JSON. It shows existing gaps rather than papering over them – a record that looks complete but has silent blanks is the worse outcome in a conversation with a supervisory authority.
No. It structures their work, keeps the record and prevents typical formal errors. The legal assessment – whether a balancing test holds, for instance – remains an expert decision.
Technical and organisational measures and risks in the same system – no duplicate documentation.
Processing activities hang on real systems – not on free text in a spreadsheet.
Why public administrations have to think of the record, Grundschutz and budget predictability together.
From the legal basis through the retention logic to the export for the authority – in a demo by video conference.