# Record of processing activities (ROPA)

## Definition of the record of processing activities

The record of data processing activities provides a clear and structured mapping of all personal data processing operations and will be the starting point for control by the Data Protection Authority.

The record is provided for in [Article 30 of the GDPR](https://eur-lex.europa.eu/eli/reg/2016/679/oj#d1e3265-1-1). It participates in the documentation of compliance.&#x20;

As an inventory and analysis document, it must reflect the reality of your personal data processing and allow you to precisely identify:&#x20;

* the **stakeholders** (representative, subcontractors, co-managers, etc.) involved in the data processing,
* the **categories of data processed**,
* **what the data is used for** (what you do with it), **who accesses** the data and **to whom it is communicated**,
* **how long you keep it**,
* **how it is secured**.

## Why a registry?

The record is made **mandatory** by Article 30 of the RGPD. Beyond the response to the obligation provided for by Article 30, the record is a **tool for monitoring and demonstrating your compliance with the RGPD**.&#x20;

It allows you to document your data processing and to ask yourself the right questions: do I really need this data for my processing? Is it relevant to keep all the data for so long? Is the data sufficiently protected? Etc.&#x20;

Its creation and updating are thus an opportunity to **identify and prioritize the risks** with regard to the RGPD. This **essential step** will allow you to deduce an action **plan for the compliance** of your processing with the data protection rules.

## Which companies are affected by the obligation to complete a record?

All companies processing personal data of European citizens are concerned by the obligation to fill a register.

{% hint style="info" %}
Companies with less than 250 employees benefit from a derogation with regard to record keeping. **They are required to record only the following data processing operations**:&#x20;

* Non-occasional processing (e.g. payroll management, customer/prospect and supplier management, etc.);&#x20;
* processing operations likely to involve a risk to the rights and freedoms of individuals (e.g. geolocation systems, video surveillance, etc.);&#x20;
* processing that involves sensitive data (e.g. health data, offenses, etc.).&#x20;

In practice, **this exemption is therefore limited to very specific cases of processing**, implemented on an occasional and non-routine basis, such as a communication campaign for the opening of a new establishment, provided that such processing does not raise any risk for the data subjects. If there is any doubt as to whether this exemption applies to a processing operation, the CNIL recommends that you include it in your record.
{% endhint %}

## Content of the processing record

Article 30 of the GDPR sets out specific obligations for the *personal data controller record* and the *processor record*. If your organization acts as both a processor and a data controller, your record must therefore clearly distinguish the two categories of activities.&#x20;

**In practice, in this case, the CNIL recommends that you keep 2 records:**&#x20;

1. one for the processing of personal data for which you yourself are responsible,&#x20;
2. another for the processing operations that you carry out, as a processor, on behalf of your clients.

### The "Data controller" record in Dastra

For each processing operation, the record of a data controller shall indicate at least:&#x20;

1. where applicable, **the name and contact details** of the [joint controller](https://eur-lex.europa.eu/eli/reg/2016/679/oj#d1e3083-1-1) of the processing carried out,
2. the **purposes** of the processing, the objective for which you have collected the data,&#x20;
3. the categories of **persons concerned** (customer, prospect, employee, etc.),
4. the categories of **personal data** (e.g. identity, family, economic or financial situation, banking data, connection data, location data, etc.),
5. the categories of **recipients** to whom the personal data has been or will be communicated, including the processors you use,
6. **transfers** of personal data to a third country or to an international organization and, in certain very specific cases, the guarantees provided for these transfers,
7. the **time limits for the deletion** of the various categories of data, i.e. the retention period, or failing that the criteria for determining it,
8. to the extent possible, **a general description** of the technical and organizational **security** **measures** that you implement.

<figure><img src="https://2697025545-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LvBxs22wUMicv9uWp6C-1972196547%2Fuploads%2FCM1uKN1uySTuJHIytKU0%2FCapture%20d%E2%80%99e%CC%81cran%202023-05-03%20a%CC%80%2014.30.23.png?alt=media&#x26;token=b7deabea-bef1-442c-80f6-ff447c79e07c" alt="" width="182"><figcaption><p>A processing as controller in Dastra</p></figcaption></figure>

#### Stakeholders

* The identity and contact information of the data controller&#x20;
* The identity and contact information of the DPO if applicable&#x20;
* The identity and contact information of the representative, if any&#x20;
* The joint controller(s), if any

#### Purposes

* All purposes related to the activity involving the processing

#### Legal basis

* Compliance with a legal obligation&#x20;
* Fulfillment of a contract&#x20;
* Legitimate interest of the company or a third party&#x20;
* Public interest&#x20;
* Consent&#x20;
* Safeguarding the vital interests of the data subject or another person

#### Inventory of data and data subjects

* Type of data subjects&#x20;
* Categories of data&#x20;
* Time limits for deleting data or applicable rule

#### Recipients and data transfers outside the EEA

* Identification of recipients including internal recipients (department concerned by the processing); external bodies (commercial or institutional partners); subcontractors (host, solution provider); data subject where applicable and joint managers&#x20;
* For each recipient, identification of transfers outside the European Economic Area (EEA) and the legal tools used (Binding corporate rules in the case of transfers outside the EU with subsidiaries, standard contractual clauses, country recognized as adequate, etc.)

#### Security measures

* Technical and organizational measures implemented to secure each data processing&#x20;
* For example, data encryption, pseudonymization, access limitation

### The "Processor" record in Dastra

Each processor is required to fill out a less extensive record.&#x20;

This record contains:&#x20;

* the **contact details of the processor**, its representative, if any, and its DPO&#x20;
* the **contact details of all data controllers on whose behalf the processor acts** (usually the clients)&#x20;
* the **categories** of data processed&#x20;
* the **recipients**&#x20;
* **transfers** outside the EEA&#x20;
* the **security measures**

<figure><img src="https://2697025545-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LvBxs22wUMicv9uWp6C-1972196547%2Fuploads%2FBthLQzIpId3c0fodhGqA%2FCapture%20d%E2%80%99e%CC%81cran%202023-05-03%20a%CC%80%2014.40.55.png?alt=media&#x26;token=dfa43ce6-e834-475b-ae45-fd9881cb4768" alt="" width="151"><figcaption><p>A processing as processor in Dastra</p></figcaption></figure>

## For more information

{% content-ref url="../../features/editer-le-registre" %}
[editer-le-registre](https://doc.dastra.eu/en/features/editer-le-registre)
{% endcontent-ref %}

{% content-ref url="../../features/editer-le-registre/establish-your-record" %}
[establish-your-record](https://doc.dastra.eu/en/features/editer-le-registre/establish-your-record)
{% endcontent-ref %}

{% content-ref url="../../features/editer-le-registre/remplir-le-questionnaire" %}
[remplir-le-questionnaire](https://doc.dastra.eu/en/features/editer-le-registre/remplir-le-questionnaire)
{% endcontent-ref %}


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://doc.dastra.eu/en/le-rgpd-en-bref/rgpd-en-bref/registre-de-traitement.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
