Skip to main content

Create and validate a Processing Activity record

How do I create and validate a processing activity record? You create a processing activity record from the ROPA module, describe what the activity is and why it happens, select the data involved fro…

Pete Ansell
Updated by Pete Ansell
How do I create and validate a processing activity record?

You create a processing activity record from the ROPA module, describe what the activity is and why it happens, select the data involved from your inventories, set retention, link any vendors or systems, and assign an owner. The owner reviews the record and submits it for validation. A higher-privilege user checks it and marks it Complete. Once Complete, the record counts towards your Article 30 register and appears in the ROPA export.

If you already hold a ROPA in a spreadsheet, import it first (see How do I import my existing records?). This article covers building a record by hand, which is what you do for new activities and for correcting imported ones.


What a processing activity is

A processing activity is one purpose for which your organisation handles personal data, described at a level a regulator would recognise. “Payroll”, “Recruitment”, “Customer support” and “Hosting client platforms” are processing activities. “Using Microsoft 365” is not; that is a system, and it will appear inside several activities.

If you are unsure how to split things up, the test is whether the purpose, the people whose data is involved and the retention period are all the same. If any of those differ, you probably have two activities.


Before you start

The record is mostly built by selecting from inventories rather than typing free text. That is what keeps the register consistent and reportable. Check the following inventories have what you need before you begin. Each can be added to as you go, but it is quicker to seed them first.

Inventory

What it holds

Where to find it

Purposes

Why the processing happens

[CONFIRM 13 SEP: menu path]

Lawful bases

Article 6 bases, plus Article 9 conditions where relevant

[CONFIRM 13 SEP]

Data subjects

Who the data is about: employees, customers, applicants

[CONFIRM 13 SEP]

Data categories

What data is involved, with special category status flagged

[CONFIRM 13 SEP]

Systems

Where the data lives

[CONFIRM 13 SEP]

Vendors

Third parties that process on your behalf or receive data

[CONFIRM 13 SEP]

Business units

Which part of the organisation owns the activity

[CONFIRM 13 SEP]

The platform ships with starter content in several of these. Review it rather than accepting it as-is; a data category you do not use is harmless, but a missing one will send people off to create duplicates.

Special category data. Whether a data category is Article 9 data is set on the data category itself, not on the processing activity. If health data, biometric data or similar is not flagged as special category in the inventory, the record will not prompt you for an Article 9 condition and the risk treatment will be wrong. Fix it in the inventory, not on the record.


Creating the record
  1. Open ROPA and select New processing activity [CONFIRM 13 SEP: button label].
  2. Name and description. Use the plain name your colleagues would use. The description is for a reader who has never met you: two or three sentences on what happens and who is involved.
  3. Business unit. Select the unit that owns the activity. This drives who is asked to validate it later.
  4. Purpose and lawful basis. Select from the inventories. You can select more than one purpose if the activity genuinely serves several, but consider whether that means it should be two records. If any data category selected is special category, an Article 9 condition field appears and is mandatory. [CONFIRM 13 SEP: field behaviour on Article 9 selection]
  5. Data subjects and data categories. Select every category involved, not just the sensitive ones. Contact details and job titles count.
  6. Systems. Select the systems where this data is stored or processed.
  7. Vendors and recipients. Select any third party that receives or processes the data. Vendors are unique across your account by legal name and registration number, so if the one you need is missing, add it once and it becomes available to every record and every business unit.
  8. International transfers. If data leaves the UK, record the destination and the transfer mechanism. [CONFIRM 13 SEP: whether a provisional or "under review" transfer state is available at GA]
  9. Retention. See the section below.
  10. Processing Activity Owner. Select the person who will be accountable for confirming the record is accurate. This is normally someone in the business unit, not the privacy team.
  11. Save. The record is created in the Not Started validation state.

You do not need to complete everything in one sitting. A saved record can be returned to at any time.


Setting retention

Retention is recorded as three parts: a trigger, a period, and an action.

Part

Meaning

Example

Trigger

The event that starts the clock

End of relationship, end of financial year, date of collection

Period

How long after the trigger

6 years, 12 months, indefinite

Action

What happens at the end

Delete, anonymise, return to controller, review

So a typical HR record reads: trigger end of employment, period 6 years, action delete. A contract file might be trigger contract end, period 6 years, action delete. A record with no fixed end can use indefinite as the period paired with review as the action, which is defensible where you can explain why.

The trigger, unit and action lists are fixed reference values. Your administrator can change how they are labelled but not what they are, because reports depend on them.


Validating the record

Validation is how the record moves from “the privacy team thinks this is what happens” to “the person who does it has confirmed it”. Every record moves through four states.

State

Who acts

What it means

Not Started

Nobody yet

The record exists but nobody has reviewed it

In Progress

Processing Activity Owner

The owner is reviewing and has logged at least one piece of feedback or edit

Under Review

Processing Activity Owner submits

The owner is satisfied and has passed it up for checking

Complete

Higher-privilege user

The privacy lead or administrator has confirmed the record and closed it

The Processing Activity Owner receives a notification when a record is assigned to them [CONFIRM 13 SEP: notification channel and content]. They open the record, correct anything that is wrong, add comments where they are unsure, and submit it. A user with higher privileges then reviews it and marks it Complete.

If the reviewer is not satisfied, they return it with comments and it moves back to In Progress [CONFIRM 13 SEP: return-to-owner mechanism].

A shortcut to be aware of. If you hold both the Platform Admin role and the Processing Activity Owner role on a record, the Under Review step is skipped and your submission goes straight to Complete. That is correct behaviour for a small team where one person does everything, but it also means nobody has independently checked the record. If independent validation matters to you, assign owners who are not administrators.


After validation

Complete records appear in the ROPA dashboard and in the Article 30 export. From the record you can:

  • Link it to a DPIA, LIA or TIA, or start a screening questionnaire from it [CONFIRM 13 SEP: which links are available from the record page at GA]
  • Set a review date so the owner is prompted to re-validate [CONFIRM 13 SEP: review reminder behaviour]
  • Archive it if the activity stops. Archived records leave the live register but are retained for audit.

A record is not frozen once Complete. Edits after completion are permitted; whether they reset the validation state is [CONFIRM 13 SEP: does a post-Complete edit reopen validation?].


Common problems

The Article 9 condition field is not appearing. The data category you selected is not flagged as special category in the inventory. Fix the inventory entry.

I cannot find the vendor. Search by legal name, not trading name. If it is genuinely missing, add it from the Vendors inventory; you need the legal name and registration number.

The record went straight to Complete without review. You are both the administrator and the owner. See the shortcut note above.

My owner says they never received anything. Check the owner’s user account is active and their email is correct. [CONFIRM 13 SEP: whether owners need a platform login to validate, or whether a one-time passcode link is used as it is for vendors]

I have one activity that spans several business units. Create one record, owned by the unit that leads the process. Do not create one per unit unless the purpose, data or retention actually differ.


If a question here needs a judgement call about your own processing, for example which lawful basis applies, that is advisory work rather than product support. Contact your account manager about Privacy Operations support.

How did we do?

ROPA Import

Contact