Skip to main content

Getting Started

Article 30 of the GDPR asks every organization that handles personal data to keep a Record of Processing Activities β€” a written inventory of what personal data it processes, why, on which legal basis, for whom, for how long and with whom it is shared. Supervisory authorities can ask for it at any time, and it is the first document they look at.

Most organizations keep that record in a spreadsheet that nobody enjoys updating. ROPA replaces the spreadsheet with a structured register that stays consistent, can be kept in several languages at once, and produces the documents you actually have to hand out: the Art. 30 declaration for the authority, and the Art. 13 information clause for the people whose data you process.

This page explains what you get when you sign up, how a register is put together, and how to find your way around. Each building block has its own guide under Features, and billing explains what happens after the free trial.


What you get when you sign up​

Signing up takes an email address and nothing else β€” no card, no company details.

Two things happen the moment your account exists:

  1. You join the demo organization. It is a fully populated register of a fictional company, kept in every supported language, that you can browse straight away to see what a finished register looks like.
  2. A private test organization is created for you. Within a few seconds a dialog announces that your test environment is ready. Choose Visit my workspace to open it, or Return to demo site to keep exploring and come back later.

The test organization is a copy of the demo data that belongs to you alone: it lives at its own address, you are its administrator, nobody else can see it, and you can change or delete anything in it. Use it as a playground, or replace the sample data with your own and turn it into your real register β€” see Building your register below. If you ever want the sample data back, Organization settings β†’ Reset organization data reloads it.

Every organization starts with a 90-day free trial in which everything is unlocked. What happens after that is described in How billing works.

Each organization has its own address

An organization is reached at {name}.rat.gd. The demo lives at demo.rat.gd; your test organization gets a name such as test-4821.rat.gd. Bookmark yours β€” it is the address of your workspace.


How a register is organized​

Everything in ROPA hangs off a small number of building blocks.

Organizations​

Your own organization β€” the legal entity whose register this is, whose name, address and contacts appear on every document β€” and every other organization the register refers to, all described by the same kind of record. β†’ Organizations

Organizational units​

The departments, teams or functions inside the organization β€” Human Resources, Marketing, IT, a subsidiary. Each unit has a colour, and every processing activity belongs to exactly one unit. Units are what you filter the register by, and they are how the finished document is grouped. β†’ Organizational units

Processing activities​

The heart of the register. One activity is one purpose for which personal data is handled β€” payroll, newsletter, video surveillance of the car park, recruitment. For each activity the register records the purpose, the legal basis, the categories of data and of data subjects, where the data comes from, how long it is kept, who receives it, whether it leaves the EU, and how it is secured.

An activity is either active β€” part of the official register β€” or inactive, a draft or a retired activity that is kept but not published. A new activity always starts inactive, and it can only be activated once all compulsory fields are filled in, so a half-finished entry never reaches your official record. β†’ Processing activities

Partners​

The other organizations that appear in your activities: data processors you engage, joint controllers you share a purpose with, and controllers you process data for. Each partner is entered once, with its address and contact persons, and then picked from a list wherever it plays a role. Your own organization is a partner too β€” the first one in the list. β†’ Partners

Contacts​

The people behind each organization: your data protection officer, and the privacy contact at each partner. Every organization has at least one, with a role, an email and a phone. β†’ Contacts

Contracts​

Optional. A contract links partners to the activities it covers β€” a data processing agreement, for instance β€” with a name, a link to the document and an expiry date, so the register shows not just who handles the data but under which agreement. β†’ Contracts

Languages​

A register can be kept in several languages at the same time, one full copy per language, with one of them set as the default. When you add a language, the existing texts are machine-translated to give you a starting point; you then review them. Visitors, auditors and members each read the register in the language they choose from the flag menu. β†’ Languages


Finding your way around​

View mode and Edit mode​

The register has two faces, and the switch between them sits in the top bar.

  • View mode is the register as a reader sees it: the dashboard of activity cards, the details of each activity, and the documents. Every member has it.
  • Edit mode is where activities, units, partners and settings are changed. Only administrators of the organization have it; other members see the switch greyed out.

You are the administrator of your test organization, so both modes are yours.

The dashboard​

The main page lists the activities as cards, one per activity, grouped and coloured by organizational unit. Click a card for the full details. The sidebar on the left filters the list β€” by unit, by your organization's role in the activity (controller, processor or joint controller), and by whether inactive activities are shown β€” and the search box narrows it further. Active filters are shown as chips above the cards and can be removed one by one.

Organization settings​

In Edit mode, Organization settings gathers everything that is not an individual activity: organization details, languages, partners, contracts, default values for new activities, document templates, data export and restore, and β€” once billing is live β€” the subscription.

Language and account​

The flag menu in the top bar switches the language of both the interface and the register. The account button next to it manages your profile and signs you out.


Building your register​

Your test organization comes filled with the sample data, which is the quickest way to learn the forms: open a sample activity, see how its fields are filled, then edit it into one of your own or delete it. When you build your own, work in this order β€” each step feeds the next:

  1. Organizations β€” your name, address and logo; they print on every document.
  2. Languages β€” pick the default language before you write anything.
  3. Organizational units β€” the departments the register is grouped by.
  4. Partners and their contacts β€” the processors and other organizations your activities will refer to, and whom to reach there.
  5. Processing activities β€” the register itself; create, fill in, activate.
  6. Contracts β€” optional: the agreements behind each partner.
  7. Templates β€” optional: your own wording and layout for the documents.
Start with what you know

Do not try to list every activity on day one. Enter the five or six obvious ones β€” payroll, customer records, the website, the newsletter β€” activate them, and produce a first document. A register that exists and grows is worth more than a perfect one that is still being planned.


The documents you get out​

Once activities are active, every one of them produces two documents, in every language of the register:

  • Art. 30 declaration β€” the formal record of that activity for the supervisory authority. Open it from the activity's details, and download it as PDF or RTF.
  • Art. 13 information clause β€” the notice you owe to the people whose data you process. Each activity has a direct link to it, and an embed snippet, so you can point to it from a privacy policy, a consent form, an email footer or a web page and it always shows the current text.

The complete register β€” every active activity, grouped by unit, with a front page and a summary β€” is available as a single PDF from the dashboard.

Your data is never locked in. Organization settings β†’ Organization data exports the whole organization as JSON or as a ZIP of spreadsheets, and the same page restores it; see Import / Export.


Where to go next​

I want to…Go to
See a finished registerThe demo organization, from the flag of any language
Build my ownVisit my workspace, then follow Building your register
Collect activity details from colleagues with a formGoogle Forms add-on
Use the register from a phone or tabletMobile access
Know what happens when the trial endsHow billing works and the Billing FAQ
Ask a questionsupport@gdpr-labs.com