Processing Activities
A processing activity is one purpose for which personal data is handled: payroll, newsletter, video surveillance of the car park, recruitment. The register is the list of these activities, and each one carries the information Article 30 asks for — purpose, legal basis, data, data subjects, retention, recipients, transfers, security.
Activities are created and edited from the dashboard in Edit mode, by administrators. In View mode every member can read them.
Active and inactive
An activity is either active — part of the official register, shown on the dashboard and printed in the documents — or inactive: a draft that is not finished yet, or a processing that has stopped and is kept for the record.
- A new activity always starts inactive.
- It can only be activated once every compulsory field is filled in, so a half-finished entry never reaches your official record.
- An activity with an expiry date in the past is deactivated automatically.
- Only an inactive activity with no pending changes can be deleted.
Inactive activities are hidden by default; Show inactive activities in the sidebar reveals them.
Do not try to capture every activity on day one. Start with the five or six obvious ones — payroll, customer records, the website, the newsletter — activate them, and generate your first document. A register that exists and grows as you go is worth more than a perfect one that never leaves the planning stage.
Fewer activities also mean a register that is easier to manage. Keep the list short, and add a new activity only when none of the existing ones fits a new need.
Default values for new activities
If most of your activities share the same answers — the same security measures, the same retention rule, the same origin — set them once under Organization settings → Activity default values. Every new activity is pre-filled with those values, and you only change what differs.
The documents you get from each activity
Once an activity is active, the application writes two ready-to-use documents for it, in every language of the register — no extra work on your part:
- the Art. 30 declaration — what you hand to the supervisory authority if it asks about this processing. Open it in the browser or download it as PDF or RTF;
- the Art. 13 information clause — what you show the people whose data you process. It has a permanent link and an embed snippet, so you can point to it from a privacy policy, a consent form or a web page and it always shows the current text. It can also be downloaded as PDF or RTF.
Publishing the documents
Every way of sharing a document is gathered in one place. In Edit mode, open the activity and choose Activity data at the bottom: Activity declaration shows the publication methods of the Art. 30 declaration, Activity information those of the Art. 13 information clause. Both offer the same four methods:
| Method | What you get | Use it for |
|---|---|---|
| View | Open the document in a new tab, save it as an editable RTF, or download it as PDF | Checking how it reads, printing it, sending it to the supervisory authority or to a colleague |
| Direct link | The document's permanent address, with Copy URL, and its QR code, with Copy QR | A link in a privacy policy, an email, a contract or a consent form; the QR code on a poster, a printed form or a reception desk |
| iframe embedding | A ready-made HTML snippet, with Copy code | Showing the document inside your own website — WordPress, Wix and other website builders accept it as-is |
| Web component | A two-line snippet that loads a small script, with Copy code | The same result as the iframe, as a single custom tag whose language and size are set by attributes — handy when a web developer maintains the site |
Copy QR does not copy the bare code: it puts a ready-to-print card on the clipboard — your organization's name, the activity's name, the QR code and the document type ("Activity declaration" or "Information clause") — so that whoever scans it knows what they are about to open. Paste it straight into a document, a slide or a poster.
Links, QR codes and embeds all point to the live document, never to a copy: when you change the activity, every page that links to it or embeds it shows the new text, with nothing to update. Each one is for the language you are viewing the activity in; switch the language to publish the other versions.
The information clause can be published in any organization. The declaration can be opened by anyone only if your organization is public (see Public and private organizations); in a private organization its link, QR code and embeds work for members only, so do not put them where outsiders will look.
Each document also has a predictable address outside the application, built from your organization's address and the activity's number, so it can be printed on a form, quoted in a contract or linked from a website:
| Document | Open in the browser |
|---|---|
| Information clause (Art. 13) | …/{language}/{activity-number} |
| Declaration (Art. 30) | …/{language}/a/{activity-number} |
where … stands for https://{short-name}.rat.gd. Adding /pdf or /rtf to the end of an address downloads the document in that format. Each address first shows a short "I am not a robot" check and then opens the document or starts the download. The PDF is the document exactly as it prints; the RTF is an editable copy that opens in Word or LibreOffice. The file is named {short-name}-info-{activity-number}-{language}.pdf (or .rtf) for the information clause and {short-name}-decl-{activity-number}-{language}.pdf (or .rtf) for the declaration.
The information clause is always reachable this way, because it exists to be read by people who are not members. The declaration is reachable by anyone only if the organization is configured as public; for a private organization it is shown to members only.
Both documents are generated from a default template that works out of the box. To use your own layout, wording or structure instead, you can create and edit your own organization level or processing activity level Templates.
What a processing activity holds
| Name | How the activity is listed on the dashboard and titled on its documents |
| Organizational unit | The OU the activity belongs to — exactly one. It decides how the activity is grouped, filtered and coloured on the dashboard and in the ROPA PDF |
| Data controller(s) | The organization — or organizations, when there are joint controllers — that decides why and how the data is processed |
| Data processor(s) | If any, the organization — or organizations — that process the data on the controller's behalf. Your own organization must be either a data controller or a data processor of every activity |
| Purpose and details | One line saying what the processing is for, and as much explanation as an auditor would need |
| Legal basis | Article 6 legal basis for the processing activity |
| Special categories legal basis | Article 9 legal basis for the processing activity, if applicable |
| Data categories | Identification, personal characteristics, financial, professional, social circumstances, commercial — and the special categories |
| Data subject categories | Who the data is about: employees, customers, applicants, visitors… |
| Activity categories | What is done with the data: collection, storage, communication, dissemination, erasure… |
| Data origin | Where the data comes from |
| Preservation | How long the data is kept and the rule that decides it |
| Data communications | Who receives the data, with a free-text detail |
| Profiling | Yes or no |
| International transfers | Yes or no, with the detail of where and under which safeguard |
| Security level and measures | Low, medium or high risk, and the additional measures in place |
| Expiry date | Optional; once it has passed, the activity is deactivated automatically (see "Active and inactive" above) |
| Status | Active or inactive (see "Active and inactive" above), and whether the deactivation was automatic — because the expiry date passed — or done by hand |