Data Mapping

Generating ROPA Reports

Produce a GDPR Article 30 Record of Processing Activities from your Data Mapping, edit it as a draft, finalize a point-in-time record, and export it.

Overview

A Record of Processing Activities (ROPA) is the register GDPR Article 30 asks you to keep: what personal data you process, why, and how. Concord builds this register from the data you already maintain in Data Mapping, so you can generate a compliant draft in one step and refine it, rather than filling in a spreadsheet by hand.

ROPA reports are a Premium add-on. Generating a report uses Actions from your organization's shared pool.

What a report contains

A ROPA report has two parts:

  • A summary — rich text describing the register, with insertable tokens (for example, a live processing-activity count) that resolve to real values when you finalize.
  • Rows — one Article 30 record per processing activity, each capturing the purposes, data subjects, data categories, recipients and transfers, origins, legal basis, and security measures.

The lifecycle: draft, finalize, export

  1. Generate a draft. From Data Mapping → ROPA reports, generate a report. Concord selects your processing activities, turns each into an Article 30 row, and seeds the summary from a template.
  2. Edit the draft. While a report is a draft, you can edit the summary and the rows freely. You can also exclude a row you don't want in this report — it's hidden from the counts and the export but kept for your audit trail.
  3. Finalize. Finalizing freezes a point-in-time record: the summary's tokens are resolved to their values and the rows become read-only. A finalized report can't be returned to draft, which is what makes it a defensible snapshot.
  4. Export. Export the finalized report for your records or to share with a regulator or auditor.

Cross-border transfers

Each row reflects where the data systems behind an activity are located, so the register surfaces cross-border transfers as part of the Article 30 record. Keep your data systems' geography accurate in Data Mapping and it flows through to the report.

Editing a report

The report detail page organizes the work into tabs — the report's details, its summary (the rich-text editor), and its activities (the rows). Edits to a report stay local to that report; they don't change your underlying Data Mapping.

Who can generate reports

Owners and Admins can generate, edit, and finalize reports. A Limited user can view them. See User Roles & Permissions.

Next steps