Skip to main content

Processing Activities

A processing activity is one purpose for which personal data is handled: payroll, newsletter, video surveillance of the car park, recruitment. The register is the list of these activities, and each one carries the information Article 30 asks for — purpose, legal basis, data, data subjects, retention, recipients, transfers, security.

Activities are created and edited from the dashboard in Edit mode, by administrators. In View mode every member can read them.


Active and inactive

An activity is either active — part of the official register, shown on the dashboard and printed in the documents — or inactive: a draft that is not finished yet, or a processing that has stopped and is kept for the record.

  • A new activity always starts inactive.
  • It can only be activated once every compulsory field is filled in, so a half-finished entry never reaches your official record.
  • An activity with an expiry date in the past is deactivated automatically.
  • Only an inactive activity with no pending changes can be deleted.

Inactive activities are hidden by default; Show inactive activities in the sidebar reveals them.

Start with what you know

Do not try to list every activity on day one. Enter the five or six obvious ones — payroll, customer records, the website, the newsletter — activate them, and produce a first document. A register that exists and grows is worth more than a perfect one that is still being planned.


Default values for new activities

If most of your activities share the same answers — the same security measures, the same retention rule, the same origin — set them once under Organization settings → Activity default values. Every new activity is pre-filled with those values, and you only change what differs.


The documents you get from each activity

Once an activity is active, the application writes two ready-to-use documents for it, in every language of the register — no extra work on your part:

  • the Art. 30 declaration — what you hand to the supervisory authority if it asks about this processing. Open it in the browser or download it as PDF or RTF;
  • the Art. 13 information clause — what you show the people whose data you process. It has a permanent link and an embed snippet, so you can point to it from a privacy policy, a consent form or a web page and it always shows the current text.

You will find both documents on the activity's own page, where you can also copy their links and embed snippets.

Every document has a permanent address

Each document also has a predictable address outside the application, built from your organization's address and the activity's number — https://{short-name}.rat.gd/{language}/{activity-number} for the information clause, with ?type=activity-declaration added for the declaration — so it can be printed on a form, quoted in a contract or linked from a website.

The information clause is always reachable this way, because it exists to be read by people who are not members. The declaration is reachable by anyone only if the organization is configured as public; for a private organization it is shown to members only.

Both documents come with a sensible default layout; if you would rather they carried your own wording, structure or logo, that is what Templates are for.


What a processing activity holds

Purpose and detailsOne line saying what the processing is for, and as much explanation as an auditor would need
Legal basisConsent, contract, legal obligation, vital interests, public interest or legitimate interest, with a free-text detail. Activities that touch special categories of data (health, biometrics, beliefs, union membership…) also need one of the Article 9 grounds
Data categoriesIdentification, personal characteristics, financial, professional, social circumstances, commercial — and the special categories
Data subject categoriesWho the data is about: employees, customers, applicants, visitors…
Activity categoriesWhat is done with the data: collection, storage, communication, dissemination, erasure…
Data originWhere the data comes from
PreservationHow long the data is kept and the rule that decides it
Data communicationsWho receives the data, with a free-text detail
Controllers and processorsThe partners involved and their roles
ProfilingYes or no
International transfersYes or no, with the detail of where and under which safeguard
Security level and measuresLow, medium or high risk, and the additional measures in place