Organizations
A register names organizations all the time: the one it belongs to, and every other one that touches the data — the payroll provider that processes it, the sister company that shares a purpose, the client on whose behalf you work. ROPA describes all of them with the same kind of record: a name, an address, contact persons, a colour, a logo. What differs is the role each one plays.
- Your own organization is the legal entity that answers for the register. Its details go on every document, it holds the license, and it is the default data controller of every new activity.
- Every other organization is a partner: a data processor you engage, a joint controller you share a purpose with, or a controller you process data for. Partners are entered once and then picked wherever they play a role.
All of them are listed together in Edit mode under Organization settings → Configure partners, your own organization first. Your own is also reachable directly under Organization settings → Organization data; both routes edit the same record. Only administrators can make changes.
What is special about your own organization
| Your organization | A partner | |
|---|---|---|
| Role in activities | Default controller of every new activity; must be a controller or processor in each one and cannot be removed | Controller, processor or joint controller, as you assign it — or absent |
| On documents | Name, address and contact on every declaration, every information clause and the ROPA PDF | Named where it plays a role in the activity |
| Address on the web | {short-name}.rat.gd | — |
| Can be deleted | No | Yes, once it plays no role in any activity |
Because your own organization's details are repeated on every document you hand out, check that record first and keep it current: a wrong address or an outdated contact there is wrong everywhere.
Public and private organizations
Your own organization is either public or private, and that decides who can read the register at {short-name}.rat.gd.
- A public organization is open to anyone: visitors can browse the register in View mode, read each activity's Art. 30 declaration and download it as PDF or RTF, and download the full ROPA PDF — all without an account. This is the right setting for a register you are happy to show — a public body, a company that publishes its register as part of its transparency policy, or the demo organization.
- A private organization is visible to its members only. Anyone else who opens its address is told the organization is not available, and its declarations and the ROPA PDF are not served outside the application.
The Art. 13 information clause is the exception: it is reachable by anyone in both cases, because it exists precisely to be read by the people whose data you process, who are not members and never sign in.
Whatever the setting, editing is always reserved to administrators, and the partners' details, contacts and contracts are never exposed beyond what the documents themselves print.
The setting is part of the organization's configuration and is not changed from the settings screens; your test organization is private. Contact support@gdpr-labs.com to make an organization public.
What an organization holds
| Short name | The identifier used in lists and, for your own organization, in its address ({short-name}.rat.gd). Lowercase letters, numbers and hyphens only |
| Full name | The legal name, as it should appear on documents |
| VAT number | Enter it and choose Look up: the registered company name and address are retrieved and offered to fill the form. If the number cannot be verified you can still continue and type the details yourself |
| Address | Typed as a single line and interpreted automatically into street, city, postal code and country; if the interpretation fails, the parts can be entered by hand |
| Contacts | At least one person — for your own organization typically the data protection officer, for a partner the person you deal with there. See Contacts |
| Colour | Identifies the organization wherever several are shown side by side — in an activity's controllers and processors, in contracts |
| Logo | Optional, but worth adding for every partner, not just your own organization: it is shown wherever the partner appears across the application, and a familiar logo is recognised far faster than a name in a list. For your own organization it also appears in the top bar and on the documents |
| Website | Optional; for your own organization it becomes a link in the top bar |
| Notes | Free text for what the register cannot express in a field: projects you are about to start with this organization, an agreement under negotiation, an audit finding to follow up, a reason it was chosen or is being phased out. People belong in contacts, not here. Never printed on documents |