Vendors & ROPA
- Written for
- + Written for
- Deprecated
- + Deprecated
- Applies to
- + Applies to
Vendors & ROPA
Dashboard → Privacy → Governance covers two GDPR-driven recordkeeping obligations that sit behind your banner: a Record of Processing Activities (RoPA) — Art. 30's requirement to document what you process and why — and a vendor register with automatic risk scoring for every third party you share data with.
Record of Processing Activities (RoPA)
Click New record and document a processing activity:
Field | Description |
|---|---|
Activity name | What the processing activity is called internally |
Purpose | Why you're processing this data |
Legal basis |
|
Retention (days) | How long the data is kept |
Cross-border transfer | Whether this activity moves data outside your home region |
The table shows retention in a friendly format (e.g. "1.5 years" once it crosses 365 days) and a Transfers out / In region badge per record, so a compliance review can scan the whole RoPA at a glance.
Vendor register
Click New vendor to add a third party your site shares data with:
Field | Description |
|---|---|
Vendor name | e.g. "Google Analytics" |
Category | e.g. "Analytics", "Advertising" |
Region | Where the vendor processes data — see the region list below |
DPA signed | Whether you have a Data Processing Agreement in place |
Risk scoring
Every vendor gets an automatic risk score and band (Low / Medium / High) so you can prioritize which vendor relationships need attention first. Scoring weighs:
Whether a DPA is on file (no DPA raises risk).
Whether the vendor's region is GDPR-adequate.
GDPR-adequate regions (no extra transfer safeguard needed) are:
EU, EEA, UK, US, Switzerland, Canada, Japan, New ZealandA vendor whose region falls outside that set is scored as a higher-risk cross-border transfer, since it typically requires Standard Contractual Clauses or another Art. 46 transfer mechanism to stay compliant.
Note: The region dropdown in the vendor dialog matches this exact adequacy list plus an Other / non-adequate catch-all — pick "Other" for any vendor whose region isn't independently GDPR-adequate.
Why this matters
A regulator (or a customer's procurement/security review) asking "what do you process, under what legal basis, and who do you share it with" is one of the most common privacy audits. Keeping RoPA and the vendor register current means that question has a five-minute answer instead of a scramble.
See also: DSAR requests · Geo-targeting & regional rules