Building Your Data Processing Register (ROPA)
How to document all personal data processing activities as required by GDPR Article 30.
Building Your Data Processing Register
GDPR Article 30 requires a Record of Processing Activities (ROPA). The Plenix GDPR module gives you a structured way to create and maintain it, log and fulfil subject requests, track consent, and deliver exported data to the people who asked for it.
What is a processing activity?
A processing activity is any distinct purpose for which you use personal data β for example "Payroll Processing", "Marketing Email List", or "Support Ticket Handling". Article 30 requires you to document, for each one: what data you hold, why, on what legal basis, how long you keep it, who you share it with, and whether it ever leaves the UK/EU.
Step 1: Open the GDPR module
Go to Compliance & QHSE β GDPR / Data Privacy in the sidebar. The page has four tabs: Subject Requests, Consent Records, Processing Register, and Data Export.
Step 2: Add a processing activity
Switch to the Processing Register tab and click Add Record. Fill in:
| Field | Example |
|---|---|
| Activity name | Payroll Processing |
| Purpose | Pay employees correctly and comply with HMRC |
| Legal basis | Legal obligation |
| Data categories (comma-separated) | Financial data, national insurance numbers |
| Retention period | 7 years |
| Recipients (comma-separated) | HMRC, pension provider |
| International transfers (comma-separated countries) | leave blank if none |
Every record you save appears as a card showing its legal basis, retention period, data categories, and β where filled in β who it's shared with and where it's transferred to.
Legal basis options
- Consent β the individual has actively agreed (e.g. marketing opt-in)
- Contract β necessary to perform a contract with the individual
- Legal obligation β required by law (e.g. HMRC payroll reporting)
- Vital interest β necessary to protect someone's life
- Public task β necessary to perform a task in the public interest
- Legitimate interest β necessary for your legitimate business interests, balanced against the individual's rights
Managing Subject Requests (DSARs)
Switch to the Subject Requests tab to handle a request from someone asking what data you hold on them, or asking you to correct, erase, or export it (their rights under GDPR Articles 15β21).
- Click New Request.
- Choose the request type: access, erasure, portability, restriction, or objection.
- Enter the requestor's name and email, and an optional description.
- Click Create. Plenix sets a due date 30 calendar days out; requests past that date are flagged Overdue on the card.
Work a request through its lifecycle with the buttons on its card: Start moves it to In Progress, then Complete when you're done, or Reject if it doesn't qualify.
Fulfilling an access or portability request
For access and portability requests, click Fulfil via Export on the request card. This opens a modal where you:
- Choose the scope β Whole tenant or One company, searching for the specific CRM company if scoping to one.
- Confirm or edit the recipient name and email β pre-filled from the request, but editable, since the person who should actually receive the data (e.g. a company's data protection contact) isn't always the named requestor.
- Click Start Export.
The export runs in the background β find it on the Data Export tab once it finishes.
Delivering the data
If you gave a recipient email β either fulfilling a DSAR or starting an export directly β Plenix emails that person a secure download link once the export completes. The link works without a Plenix login and expires after 7 days.
You can also start exports directly from the Data Export tab, for the whole tenant or a single CRM company, with the same optional recipient name/email fields. Leave them blank to keep the export dashboard-only, same as before. Use New Schedule on that tab to set up a recurring export (daily, weekly, or monthly) instead of running one-off exports manually β recurring exports support the same recipient delivery.
Data Officers
Also on the Data Export tab, an admin or super admin can grant a user the Data Officer flag so they can export CRM company data without needing full admin rights. Only an admin/super admin can grant or revoke this.
Where to go next
- Understand the whole module β How Compliance & QHSE Works
- Next in this module β Managing Non-Conformances (QMS)
- Compliance β Deadlines, Audits & QHSE Training
- Run an Audit
- See where this fits in the bigger picture β Start Here: What Plenix Is and How It Fits Together
Was this article helpful?