What is ROPA under the LGPD? Learn about the Records of Data Processing Activities.

Estimated reading time: 4 minutes

Summary

If you are in the process of adapting your company to the General Data Protection Law, or entering this area of ​​privacy and becoming a DPO/Data Protection OfficerYou need to be familiar with the terminology involved in this topic.

One of them is the acronym ROPA (Record Of Processing Activities), which means Records of Processing Activities. In other words, they are proof of how data is collected, what is done with this information, and how deletion is handled, if it occurs.

This information is extremely useful should there be a need to respond to the ANPD, which is the National Data Protection Authority.

Even for smaller companies, these records can be kept with limited resources. However, for larger companies and businesses, automating the process makes more sense, as this is a living document; the records require constant attention as the company's business evolves and changes in the handling of personal data occur.

What is ROPA?

The ROPA is a document, generated by a system or not, where you record all personal data processing activities. Every purpose, every reason why you need to process personal data, security criteria, legal basis, retention period, among other criteria, are included in the ROPA.

LGPD Privacy Tools

Is it the same thing as Data Mapping?

Not necessarily, as mapping involves a somewhat larger ecosystem consisting of a series of ROPAs (Regional Operating Procedures), a visual map of the flow of personal data, maps of systems and international transfers, compliance with ISO and NIST standards, mechanisms for generating a DPIA (Data Protection Impact Assessment), among other various means of mapping data processing.

ROPA is from the treatment activity, the Data Mapping It is the responsibility of the processing agent. In short, creating a complete Data Mapping can involve much more than just ROPA, but registration is the essential foundation for a well-executed data mapping.

What should a ROPA look like?

According to ICO (Information Commissioner's Office) a ROPA must have at least:

  • Contact details and information for data processing agents and entities involved (controllers, processors, sub-processors, DPO, etc.)
  • What are the purposes of the processing, that is, what is the objective to be achieved with this processing of personal data?
  • Description of the categories and types of personal data that are necessary to achieve the purpose.
  • Details regarding international data transfers and measures and safeguards for the protection of personal data.
  • Retention period and other information related to the purging or anonymization date.
  • Description of the technical and organizational measures for data protection.

When compared with the technical recommendations of Federal government It has a very similar structure, see below:

  • Actors involved (treatment agents and the person in charge);
  • Purpose (what the institution does with the personal data);
  • Hypothesis (articles 7 and 11 of the LGPD) and Legal Provision;
  • Personal data processed by the institution and category of personal data subjects;
  • Personal data retention period;
  • Institutions with which personal data is shared;
  • International data transfer (art. 33 LGPD);
  • Security measures currently in place

This similarity between ICO and the GOVERNMENT This gives us guidance on what the ANPD (National Data Protection Authority) can define as standards and best practices.

How to make a ROPA?

If you're just starting out and want to experiment, or even if your business is too small to justify simpler control, use spreadsheets. Gov.br itself has excellent ready-made templates with examples to help.

However, larger, digital, and dynamic businesses need a privacy management platform that makes the job easier. This type of tool generates alerts and can automate workflows; otherwise, the company will not have a well-done and up-to-date mapping, or will need a team dedicated solely to this.

Here are some helpful links below:

The models above can be helpful, but you can build your own ROPA according to the context of your business. The important thing is to ensure there is clarity regarding the purpose of processing personal data that justifies its use for the business.

The mere act of conducting this exercise forces the company to rethink the real need for certain types of personal data, and at the end of the ROPA process, the company itself concludes that it does not need some of the data, but was only collecting it with the intention of enriching its database for a supposed future purpose.

Begin your adaptation process.

Using good tools is essential to understand the personal data processed by your company, its lifecycle, and what may pose a risk in terms of data protection and privacy.

In this sense, the functionalities of Privacy Tools are great allies in the compliance process, as they automate privacy management and data management.

By registering, it is possible Take a free trial of the platform. to learn in practice tools such as Data Mapping and Blockchain Auditing to take data protection to the next level in your organization.

Questions and Answers

About the Author

Meet the author of this article.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also