Skip to main content

Development trial ยท sample information only

Manage privacy records and assessments

What you'll achieve

You'll maintain a Record of Processing Activities (RoPA), the data it uses and the categories of people it affects. You'll also know where a Data Protection Impact Assessment (DPIA) or Fundamental Rights Impact Assessment (FRIA) fits into that work.

Who this is for

This guide is for an Organisation Collaborator with the permission or assigned action described below. If the navigation or action is missing, check the selected organisation, effective account level, feature state and role before assuming the product is unavailable.

Before you start

Check that you have:

  • The processing purpose, owner and systems involved.
  • Data categories, subjects, recipients, locations and retention facts.
  • Legal or privacy-owner input for lawful basis and transfer questions.

1. Build the processing record

Open RoPA and create or update the processing activity. Record purpose, legal context, data subjects, data, recipients, systems, locations, retention and transfers using verified source information.

2. Link governed data records

Use Data Entities for the information objects being governed and Data Subjects for the categories of people affected. Reuse canonical records where they already exist.

3. Decide whether an assessment is needed

Open DPIA for high-risk personal-data processing and FRIA for the fundamental-rights assessment context shown by the product. Record the screening decision and its owner.

4. Assess with evidence

Work through context, risks, controls, consultation and residual position. Keep unresolved questions visible and link the source records that support each conclusion.

5. Review and maintain

Use RoPA annual review and analytics where enabled. A completed assessment can become stale after a material change; set the next review and watch linked incidents or AI changes.

Check it worked

  • The RoPA is complete enough to explain the actual processing.
  • DPIA or FRIA decisions are attributable.
  • Retention, transfer and safeguard claims have owners and evidence.
  • Review dates reflect current processing, not the original project plan.

If something goes wrong

What you see What to do
Lawful basis is uncertain Stop and ask the privacy or legal owner; do not select the closest-looking option.
A data entity already exists Link it rather than creating a duplicate.
Processing changed Reopen the affected RoPA and assessment; do not rely on the old completion state.

Human judgement, security and privacy

Regulatory forms are structured aids. The organisation remains responsible for accuracy, consultation and the judgement that residual risk is acceptable.

What's next

Link the final controls and schedule the next review against the live processing owner.

Need help?

Use your organisation's approved Backstory support route. Include the organisation, page and action that failed, but do not include passwords, invitation links, secret keys or unnecessary personal or confidential content.

Was this article helpful?