PRACTICAL GUIDE · RoPA

Records of processing activities.
A worked example.

See how one recruitment activity becomes a structured record, what questions to ask your team and what to revisit when the process changes.

Illustrative controller-side record for a fictional organisation. It shows selected fields and working questions, not a complete Article 30 template. Bracketed entries require real project information.

Example: recruitment for an open role

Keep the processing description separate from individual applications. This record describes the activity, not a list of candidates.

Organisation and contacts
[Controller name and contact details; representative and DPO where applicable.]
Purpose
Review applications and select a candidate for an advertised role.
People and data categories
Applicants; contact details, CVs, employment history and interview notes.
Recipients
Recruitment staff, the hiring manager and the recruitment service provider. Confirm the actual categories and their access.
International transfers
[Check provider locations and support access; record relevant destinations and safeguards where applicable.]
Retention
[Record the reviewed retention period or criteria for this recruitment purpose.] A talent pool is a separate question.
Security measures
Example measures to verify: access restricted to the hiring team and access reviewed when team members change.

Field reference: EDPB guidance on records of processing activities. ↗

Questions for a RoPA questionnaire

  1. 01

    HR: how does the process start and end?

    List the sources of applications, the people who use them and what happens after a vacancy closes.

  2. 02

    IT and procurement: which services are involved?

    Confirm the provider, storage arrangements, access and relevant contractual information. Link the service record instead of copying its description into every activity.

  3. 03

    Privacy specialist: what still needs review?

    Review the purpose, applicable legal basis, retention and transfer information. Keep open questions visible; a completed form does not settle them.

How to maintain a RoPA as work changes

Revisit the record when the process, business conditions, laws or internal requirements change. Keep the purpose, participants, risks and measures under review, not just the document.

A new recruitment service

Recheck the system, provider, recipients and transfer information. In LogicPrivacy, configured rules can update related records from the information entered.

Changes in requirements and standards

If requirements or a group retention standard change, ask the specialist to assess the effect on each participating company. Update the relevant process, risks, measures and documents.

A risk requiring a measure

Keep the issue linked to its source process. Review the configured risk record and select an applicable measure; accepting a risk does not fulfil an unmet requirement.

Put the example into a working process