Introduction
All data controllers are required to keep a record of processing activities (RoPA) to comply with general data protection regulation (GDPR). The record should include:
- name and contact details of the data controller
- purpose of processing the data
- categories of the data subjects and types of personal data
- categories of data recipients, including those who have already received a user’s data and those who will receive a user’s data in the future
- transfers of data to a third country or an international organisation
- time limits for erasure of different categories of data
- a general description of technical and organisational security measures.
Service documents
You can find the record of processing activities for each service below: