Create and validate a Processing Activity record
How do I create and validate a processing activity record? You create a processing activity record from the ROPA module, describe what the activity is and why it happens, select the data involved fro…
How do I create and validate a processing activity record?
You create a processing activity record from the ROPA module, describe what the activity is and why it happens, select the data involved from your inventories, set retention, link any vendors or systems, and assign an owner. The owner reviews the record and submits it for validation. A higher-privilege user checks it and marks it Complete. Once Complete, the record counts towards your Article 30 register and appears in the ROPA export.
If you already hold a ROPA in a spreadsheet, import it first (see How do I import my existing records?). This article covers building a record by hand, which is what you do for new activities and for correcting imported ones.
What a processing activity is
A processing activity is one purpose for which your organisation handles personal data, described at a level a regulator would recognise. “Payroll”, “Recruitment”, “Customer support” and “Hosting client platforms” are processing activities. “Using Microsoft 365” is not; that is a system, and it will appear inside several activities.
If you are unsure how to split things up, the test is whether the purpose, the people whose data is involved and the retention period are all the same. If any of those differ, you probably have two activities.
Before you start
The record is mostly built by selecting from inventories rather than typing free text. That is what keeps the register consistent and reportable. Check the following inventories have what you need before you begin. Each can be added to as you go, but it is quicker to seed them first.
Inventory | What it holds | Where to find it |
Purposes | Why the processing happens |
|
Lawful bases | Article 6 bases, plus Article 9 conditions where relevant |
|
Data subjects | Who the data is about: employees, customers, applicants |
|
Data categories | What data is involved, with special category status flagged |
|
Systems | Where the data lives |
|
Vendors | Third parties that process on your behalf or receive data |
|
Business units | Which part of the organisation owns the activity |
|
The platform ships with starter content in several of these. Review it rather than accepting it as-is; a data category you do not use is harmless, but a missing one will send people off to create duplicates.
Special category data. Whether a data category is Article 9 data is set on the data category itself, not on the processing activity. If health data, biometric data or similar is not flagged as special category in the inventory, the record will not prompt you for an Article 9 condition and the risk treatment will be wrong. Fix it in the inventory, not on the record.
Creating the record
- Open ROPA and select New processing
activity
[CONFIRM 13 SEP: button label]. - Name and description. Use the plain name your colleagues would use. The description is for a reader who has never met you: two or three sentences on what happens and who is involved.
- Business unit. Select the unit that owns the activity. This drives who is asked to validate it later.
- Purpose and lawful basis. Select from the
inventories. You can select more than one purpose if the activity
genuinely serves several, but consider whether that means it should be
two records. If any data category selected is special category, an
Article 9 condition field appears and is mandatory.
[CONFIRM 13 SEP: field behaviour on Article 9 selection] - Data subjects and data categories. Select every category involved, not just the sensitive ones. Contact details and job titles count.
- Systems. Select the systems where this data is stored or processed.
- Vendors and recipients. Select any third party that receives or processes the data. Vendors are unique across your account by legal name and registration number, so if the one you need is missing, add it once and it becomes available to every record and every business unit.
- International transfers. If data leaves the UK,
record the destination and the transfer mechanism.
[CONFIRM 13 SEP: whether a provisional or "under review" transfer state is available at GA] - Retention. See the section below.
- Processing Activity Owner. Select the person who will be accountable for confirming the record is accurate. This is normally someone in the business unit, not the privacy team.
- Save. The record is created in the Not Started validation state.
You do not need to complete everything in one sitting. A saved record can be returned to at any time.
Setting retention
Retention is recorded as three parts: a trigger, a period, and an action.
Part | Meaning | Example |
Trigger | The event that starts the clock | End of relationship, end of financial year, date of collection |
Period | How long after the trigger | 6 years, 12 months, indefinite |
Action | What happens at the end | Delete, anonymise, return to controller, review |
So a typical HR record reads: trigger end of employment, period 6 years, action delete. A contract file might be trigger contract end, period 6 years, action delete. A record with no fixed end can use indefinite as the period paired with review as the action, which is defensible where you can explain why.
The trigger, unit and action lists are fixed reference values. Your administrator can change how they are labelled but not what they are, because reports depend on them.
Validating the record
Validation is how the record moves from “the privacy team thinks this is what happens” to “the person who does it has confirmed it”. Every record moves through four states.
State | Who acts | What it means |
Not Started | Nobody yet | The record exists but nobody has reviewed it |
In Progress | Processing Activity Owner | The owner is reviewing and has logged at least one piece of feedback or edit |
Under Review | Processing Activity Owner submits | The owner is satisfied and has passed it up for checking |
Complete | Higher-privilege user | The privacy lead or administrator has confirmed the record and closed it |
The Processing Activity Owner receives a notification when a record
is assigned to them
[CONFIRM 13 SEP: notification channel and content]. They
open the record, correct anything that is wrong, add comments where they
are unsure, and submit it. A user with higher privileges then reviews it
and marks it Complete.
If the reviewer is not satisfied, they return it with comments and it
moves back to In Progress
[CONFIRM 13 SEP: return-to-owner mechanism].
A shortcut to be aware of. If you hold both the Platform Admin role and the Processing Activity Owner role on a record, the Under Review step is skipped and your submission goes straight to Complete. That is correct behaviour for a small team where one person does everything, but it also means nobody has independently checked the record. If independent validation matters to you, assign owners who are not administrators.
After validation
Complete records appear in the ROPA dashboard and in the Article 30 export. From the record you can:
- Link it to a DPIA, LIA or TIA, or start a screening questionnaire
from it
[CONFIRM 13 SEP: which links are available from the record page at GA] - Set a review date so the owner is prompted to re-validate
[CONFIRM 13 SEP: review reminder behaviour] - Archive it if the activity stops. Archived records leave the live register but are retained for audit.
A record is not frozen once Complete. Edits after completion are
permitted; whether they reset the validation state is
[CONFIRM 13 SEP: does a post-Complete edit reopen validation?].
Common problems
The Article 9 condition field is not appearing. The data category you selected is not flagged as special category in the inventory. Fix the inventory entry.
I cannot find the vendor. Search by legal name, not trading name. If it is genuinely missing, add it from the Vendors inventory; you need the legal name and registration number.
The record went straight to Complete without review. You are both the administrator and the owner. See the shortcut note above.
My owner says they never received anything. Check
the owner’s user account is active and their email is correct.
[CONFIRM 13 SEP: whether owners need a platform login to validate, or whether a one-time passcode link is used as it is for vendors]
I have one activity that spans several business units. Create one record, owned by the unit that leads the process. Do not create one per unit unless the purpose, data or retention actually differ.
If a question here needs a judgement call about your own processing, for example which lawful basis applies, that is advisory work rather than product support. Contact your account manager about Privacy Operations support.
How did we do?
ROPA Import