Docs

Vendors & ROPA

AdminUpdated Sep 15, 2026

Vendors & ROPA

Dashboard → Privacy → Governance covers two GDPR-driven recordkeeping obligations that sit behind your banner: a Record of Processing Activities (RoPA) — Art. 30's requirement to document what you process and why — and a vendor register with automatic risk scoring for every third party you share data with.

Record of Processing Activities (RoPA)

Click New record and document a processing activity:

Field

Description

Activity name

What the processing activity is called internally

Purpose

Why you're processing this data

Legal basis

consent, contract, legal-obligation, vital-interests, public-task, legitimate-interests

Retention (days)

How long the data is kept

Cross-border transfer

Whether this activity moves data outside your home region

The table shows retention in a friendly format (e.g. "1.5 years" once it crosses 365 days) and a Transfers out / In region badge per record, so a compliance review can scan the whole RoPA at a glance.

Vendor register

Click New vendor to add a third party your site shares data with:

Field

Description

Vendor name

e.g. "Google Analytics"

Category

e.g. "Analytics", "Advertising"

Region

Where the vendor processes data — see the region list below

DPA signed

Whether you have a Data Processing Agreement in place

Risk scoring

Every vendor gets an automatic risk score and band (Low / Medium / High) so you can prioritize which vendor relationships need attention first. Scoring weighs:

  • Whether a DPA is on file (no DPA raises risk).

  • Whether the vendor's region is GDPR-adequate.

GDPR-adequate regions (no extra transfer safeguard needed) are:

EU, EEA, UK, US, Switzerland, Canada, Japan, New Zealand

A vendor whose region falls outside that set is scored as a higher-risk cross-border transfer, since it typically requires Standard Contractual Clauses or another Art. 46 transfer mechanism to stay compliant.

Note: The region dropdown in the vendor dialog matches this exact adequacy list plus an Other / non-adequate catch-all — pick "Other" for any vendor whose region isn't independently GDPR-adequate.

Why this matters

A regulator (or a customer's procurement/security review) asking "what do you process, under what legal basis, and who do you share it with" is one of the most common privacy audits. Keeping RoPA and the vendor register current means that question has a five-minute answer instead of a scramble.

See also: DSAR requests · Geo-targeting & regional rules

Was this page helpful?
Vendors & ROPA