The building blocks of Compliance e: stonearch@protonmail.com t: 01706 559 022
The building blocks of Compliance e: stonearch@protonmail.com t: 01706 559 022

Records management
Our qualified and experienced records manager is here to support you with all your records and information management requirements. We can support with:
Record of Processing Activity
It may be a legal requirement for your organisation to maintain and up to date record of your uses of personal data, a Record of Processing Activities (ROPA). The GDPR is very prescriptive about who this obligation applies to and what the register of your processing activities should contain. If this requirement applies to your organisation, the Information Commissioner’s Office can ask to see your register at any point, with a risk of regulatory action if you do not have it in place.
The ROPA is an excellent way to demonstrate how you are compliant with the legislation or identify gaps to be addressed. Stone Arch have undertaken this activity with our clients and have the templates and knowledge to support you through what can otherwise be a complex process.
ROPA creation makes up part of our recommended five steps to compliance - please see below for further information about this aspect of your compliance journey. And don't forget to reach out to ask us about our "5 Steps to Compliance" course!
🟡 Medium
Record of Processing Activities (ROPA) provides a central inventory of how personal data is processed within your organisation. The fact of the matter is this: it's a legal requirement for most businesses to have.
Think of the ROPA as a map of your business's personal data processing activities. It provides visibility over where personal data enters the organisation, how it is used, who has access to it and how long it is retained.
A well-maintained ROPA supports compliance activities such as audits, DPIAs, privacy notice creation, vendor reviews and responses to data subject requests. It also allows you to identify gaps in your compliance, which you can tackle when you're ready.
Without an accurate ROPA:
Organisations cannot effectively manage privacy risks if they do not understand how personal data is being processed.
A ROPA is typically created by working through how your business processes personal data, and documenting the key information about that activity. If you appoint Stone Arch to help you with this, we will conduct a series of interviews with key individuals in your organisation to extract the information needed, and we'll drop that into our template so you have a complaint ROPA that is easy to understand and keep up to date. Alternatively, we can provide you with a template and instructions so you can get stuck into the activity yourself.
Information you need to record includes:
The objective is not to capture every operational detail. Instead, the aim is to provide sufficient information to understand the processing activity and assess compliance obligations.
Whenever a new process involving personal data is introduced, consideration should be given to whether a new ROPA entry is required. Existing entries should also be reviewed when significant changes occur.
Contact us today for help with this aspect of your compliance journey. We can give you a guiding hand, provide full templates, or compile your ROPA on your behalf.