Building Your Data Processing Register (ROPA)

How to document all personal data processing activities as required by GDPR Article 30.

Building Your Data Processing Register

GDPR Article 30 requires a Record of Processing Activities (ROPA). The Plenix GDPR module gives you a structured way to create and maintain it, log and fulfil subject requests, track consent, and deliver exported data to the people who asked for it.

What is a processing activity?

A processing activity is any distinct purpose for which you use personal data β€” for example "Payroll Processing", "Marketing Email List", or "Support Ticket Handling". Article 30 requires you to document, for each one: what data you hold, why, on what legal basis, how long you keep it, who you share it with, and whether it ever leaves the UK/EU.

Step 1: Open the GDPR module

Go to Compliance & QHSE β†’ GDPR / Data Privacy in the sidebar. The page has four tabs: Subject Requests, Consent Records, Processing Register, and Data Export.

Step 2: Add a processing activity

Switch to the Processing Register tab and click Add Record. Fill in:

FieldExample
Activity namePayroll Processing
PurposePay employees correctly and comply with HMRC
Legal basisLegal obligation
Data categories (comma-separated)Financial data, national insurance numbers
Retention period7 years
Recipients (comma-separated)HMRC, pension provider
International transfers (comma-separated countries)leave blank if none

Every record you save appears as a card showing its legal basis, retention period, data categories, and β€” where filled in β€” who it's shared with and where it's transferred to.

  • Consent β€” the individual has actively agreed (e.g. marketing opt-in)
  • Contract β€” necessary to perform a contract with the individual
  • Legal obligation β€” required by law (e.g. HMRC payroll reporting)
  • Vital interest β€” necessary to protect someone's life
  • Public task β€” necessary to perform a task in the public interest
  • Legitimate interest β€” necessary for your legitimate business interests, balanced against the individual's rights

Managing Subject Requests (DSARs)

Switch to the Subject Requests tab to handle a request from someone asking what data you hold on them, or asking you to correct, erase, or export it (their rights under GDPR Articles 15–21).

  1. Click New Request.
  2. Choose the request type: access, erasure, portability, restriction, or objection.
  3. Enter the requestor's name and email, and an optional description.
  4. Click Create. Plenix sets a due date 30 calendar days out; requests past that date are flagged Overdue on the card.

Work a request through its lifecycle with the buttons on its card: Start moves it to In Progress, then Complete when you're done, or Reject if it doesn't qualify.

Fulfilling an access or portability request

For access and portability requests, click Fulfil via Export on the request card. This opens a modal where you:

  1. Choose the scope β€” Whole tenant or One company, searching for the specific CRM company if scoping to one.
  2. Confirm or edit the recipient name and email β€” pre-filled from the request, but editable, since the person who should actually receive the data (e.g. a company's data protection contact) isn't always the named requestor.
  3. Click Start Export.

The export runs in the background β€” find it on the Data Export tab once it finishes.

Delivering the data

If you gave a recipient email β€” either fulfilling a DSAR or starting an export directly β€” Plenix emails that person a secure download link once the export completes. The link works without a Plenix login and expires after 7 days.

You can also start exports directly from the Data Export tab, for the whole tenant or a single CRM company, with the same optional recipient name/email fields. Leave them blank to keep the export dashboard-only, same as before. Use New Schedule on that tab to set up a recurring export (daily, weekly, or monthly) instead of running one-off exports manually β€” recurring exports support the same recipient delivery.

Data Officers

Also on the Data Export tab, an admin or super admin can grant a user the Data Officer flag so they can export CRM company data without needing full admin rights. Only an admin/super admin can grant or revoke this.

Where to go next

Was this article helpful?

Building Your Data Processing Register (ROPA) β€” Compliance & QHSE | Plenix Docs | Plenix Docs