What is a ROPA?
ROPA stands for “record of processing activities” – if you don’t have one, you should.
A ROPA is, essentially, a record of the personal information that comes into your business (staff, customers, suppliers, etc.) and it helps you keep track of what you do with it.
Because internal processes can be haphazard early on, you may not have sufficient visibility of the personal data you hold, why you need it and where it is going. Which is why a ROPA is a good idea, as well as a legal requirement for many. Plus, putting a ROPA in place doesn’t need to be complex, particularly early on. But you do need to keep it under review and update it regularly.
Why do you need a ROPA?
LegalEdge’s data protection consultant Rhian Burke explains why:
- For some companies it is a legal requirement (Article 30 of the GDPR).
- Even if it isn’t a legal requirement, the UK Information Commissioner’s Office (ICO) expects companies to be transparent and accountable for what they do with personal data and be able to demonstrate the steps taken to protect it – and a ROPA can be evidence that you have done this.
- In order to process data lawfully in the UK, you need to know the basis for which you are using it – a ROPA can help you justify your use of data and document your lawful basis.
- A ROPA is a great risk assessment tool; by taking stock of what personal information you have, where it is kept and what you are doing with it, you can check where you are with your data protection compliance and flag up areas where you may be at risk of a breach.
- No-one wants to have to deal with the reputational fallout from a data breach, nor find themselves facing a fine or compensation claim. A ROPA can help you deal with any issues before they become a problem requiring a more resource heavy/ expensive response.
- A ROPA makes it much easier to improve information governance and comply with other aspects of data protection law (such as creating a privacy notice and keeping personal data secure).
- If you’re considering certifying to ISO 27001, you need to be GDPR compliant and have a Data Asset Register. A ROPA forms the bedrock of this and can act as a Data Asset Register, reducing the burden on your journey to ISO 27001.
- A ROPA feeds into data and information security policies, which customers often require.
How can we help?
We can help you put a ROPA in place, train your staff on how to implement it, and help you keep your ROPA up to date. We can also help with privacy notices and other relevant data protection and information security policies and terms. Get in touch at info@legaledge.co.uk to find out more.
