GDPR playbook: build the RoPA buyers will accept
Record of Processing Activities, subprocessor list, DSAR workflow, breach playbook — all inside the same workspace as your ISMS.
Step-by-step
- 1
Populate the RoPA
Assets → filter to 'Personal data'. Set purpose, lawful basis, retention, recipients. RoPA exports from here.
- 2
Publish subprocessors
Subprocessors are asset type 'Third-party service' — the Trust Center subprocessors page reads from this.
- 3
Set up DSAR intake
Trust Center → DSAR form. Requests land in Tasks with a 30-day SLA.
- 4
Rehearse the breach playbook
Policies → Breach playbook. Log an internal tabletop drill in Audits — evidence for buyers.
- "Can you share your Record of Processing Activities?"
- "Who is your DPO or data protection lead?"
- "Have you had any personal data breaches in the last 12 months?"
What this workflow produces: A current RoPA plus a signed DPA is the fastest way to close a GDPR-heavy procurement round.
FAQ
Only if Article 37 triggers apply. Otherwise a named data protection lead is enough.
Ready to run this in your workspace?
Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.
