Standards playbooks

GDPR playbook: build the RoPA buyers will accept

Record of Processing Activities, subprocessor list, DSAR workflow, breach playbook — all inside the same workspace as your ISMS.

9 min read · updated July 2026

Step-by-step

  1. 1

    Populate the RoPA

    Assets → filter to 'Personal data'. Set purpose, lawful basis, retention, recipients. RoPA exports from here.

  2. 2

    Publish subprocessors

    Subprocessors are asset type 'Third-party service' — the Trust Center subprocessors page reads from this.

  3. 3

    Set up DSAR intake

    Trust Center → DSAR form. Requests land in Tasks with a 30-day SLA.

  4. 4

    Rehearse the breach playbook

    Policies → Breach playbook. Log an internal tabletop drill in Audits — evidence for buyers.

What corporate buyers look for
  • "Can you share your Record of Processing Activities?"
  • "Who is your DPO or data protection lead?"
  • "Have you had any personal data breaches in the last 12 months?"

What this workflow produces: A current RoPA plus a signed DPA is the fastest way to close a GDPR-heavy procurement round.

FAQ

Do we need a DPO?

Only if Article 37 triggers apply. Otherwise a named data protection lead is enough.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation