Skip to main content

ROPA Import

How do I import my existing records? You import existing records from an Excel workbook. Download the template for the module you are populating, fill it in, upload it, review the validation summary,…

Pete Ansell
Updated by Pete Ansell

How do I import my existing records?

You import existing records from an Excel workbook. Download the template for the module you are populating, fill it in, upload it, review the validation summary, then confirm. Rows that pass validation are created as records. Rows with errors are listed back to you with the reason, so you can correct them and upload again. Most customers start with their ROPA.

Importing is the fastest way to get from a spreadsheet-based privacy programme to a working one. A typical first ROPA import of 20 to 60 processing activities takes under an hour, including the time spent tidying the source data.


What you can import

Module

What it covers

Template

ROPA

Processing activities, with purpose, lawful basis, data categories, retention and transfer detail

ROPA Import Template

Risk

Existing risk register entries with scoring and owners

Risk Import Template

Vendor

Processors and suppliers with contact and contract detail

Vendor Import Template

[CONFIRM 13 SEP: which importers are live at GA. Delete rows for anything not shipped, and add Incidents if it is in scope.]

Each module has its own template. You cannot combine modules in a single workbook.


Before you start

Fifteen minutes of preparation removes most of the problems people hit on their first attempt.

Decide what you are bringing across. You do not need to import everything you have ever recorded. Bring across processing that is current and that you would be willing to show a regulator. Historic or superseded entries are better left behind, or imported and set to Inactive so they remain visible without cluttering your live register.

Nominate one person to run it. Imports are quick to repeat but awkward to unpick if two people load overlapping data. One owner for the first pass, then open the module up to the wider team.

Look at your inventory values first. The platform uses controlled lists for fields such as lawful basis, data categories and post-retention action. Your import needs to use those values exactly. Open the relevant inventory in the platform before you start filling in the template so you know what the accepted values are, and add any of your own that are missing.

Tidy the obvious problems in your source file. Merged cells, records split across multiple rows, and a single cell containing three different purposes will all cause trouble. One record per row.


Why the template matters

This is the single largest cause of failed rows, so it is worth being explicit.

The platform does not accept free text into fields that are backed by a controlled list. If your spreadsheet says “consent (staff opted in during onboarding)” where the platform expects “Consent”, that row will fail. The same applies to data categories, retention actions, and the record’s status.

The template includes a reference sheet listing every accepted value for every controlled field. Use it. If a value you need is not on the list, add it to the relevant inventory in the platform first, then use it in your import.

Free-text fields such as the activity description and any internal notes accept whatever you put in them.


Running the import

  1. Go to the module you are importing into and select Import. [CONFIRM 13 SEP: exact navigation path and button label]
  2. Download the current template. Always download it fresh rather than reusing an older copy, because the accepted values can change as you build out your inventories.
  3. Fill in one record per row. Leave the header row exactly as it is, including column order.
  4. Save as .xlsx and upload it. [CONFIRM 13 SEP: file size and row limits]
  5. Review the validation summary. This tells you how many rows passed, how many failed, and why each failure occurred.
  6. Confirm the import. Rows that passed are created as records.
  7. Correct any failed rows in your workbook and upload again. Successfully imported rows are not duplicated on a second upload. [CONFIRM 13 SEP: duplicate handling behaviour]

You can run an import as many times as you need. There is no penalty for going in stages, and importing twenty records to check the shape before doing the remaining two hundred is a sensible approach.


What the import checks, and what it does not

The import validates format. It confirms that required fields are present, that controlled values match the accepted list, and that dates and numbers are the right type.

It does not validate judgement. The platform will accept a processing activity recorded under the wrong lawful basis, a retention period that has no justification, or a data category that does not reflect what you actually hold. A clean import is not the same as a correct ROPA.

This matters most on the fields where the regulatory consequence is real: lawful basis, special category data, retention, and whether you are acting as controller or processor for the activity. Get those right in the spreadsheet, because the import will not catch them and neither will the export.

If you need help deciding what is correct rather than what is valid, that is a privacy question rather than a support question, and our team can advise separately.


After the import

Three things are worth doing straight away.

Check the ROPA dashboard and your ROPA Health indicator. A large import will usually surface a batch of records with missing fields. That is normal and it is useful, because it tells you where your existing spreadsheet was thin.

Assign owners. Imported records arrive without an owner unless you populated that column. Records with no owner do not appear in anyone’s queue and will not be picked up by review reminders.

Set review dates so the register stays current rather than becoming another static document.


Common questions

Can I import into a module that already has records? Yes. Imports add to what is already there.

What happens if I upload the same file twice? [CONFIRM 13 SEP]

Can I undo an import? [CONFIRM 13 SEP: is there a bulk rollback, or is deletion record by record? This will be asked constantly, so it needs a clear answer.]

Do I need to include every column? Required columns are marked in the template. Optional columns can be left blank, though records with gaps will show as incomplete on the dashboard.

Can I import a record and link it to a vendor or an assessment at the same time? No. Import creates the records; linking is done in the platform afterwards.

My file has 500 rows. Is that a problem? [CONFIRM 13 SEP: row limit]

Can I use a CSV instead of Excel? [CONFIRM 13 SEP]


  • Preparing your ROPA spreadsheet for import
  • ROPA import template: field by field
  • Import validation errors and what they mean
  • Managing your inventories and controlled values
  • Recording controller and processor activities

How did we do?

Create and validate a Processing Activity record

Contact