Source: https://logicprivacy.com/guides/records-of-processing-activities-example/
Language: en
Updated: 2026-10-04T05:45:16+00:00

PRACTICAL GUIDE · RoPA

# Records of processing activities.
A worked example.

See how one recruitment activity becomes a structured record, what questions to ask your team and what to revisit when the process changes.

Illustrative controller-side record for a fictional organisation. It shows selected fields and working questions, not a complete Article 30 template. Bracketed entries require real project information.

## Example: recruitment for an open role

Keep the processing description separate from individual applications. This record describes the activity, not a list of candidates.

**Organisation and contacts:** [Controller name and contact details; representative and DPO where applicable.]

**Purpose:** Review applications and select a candidate for an advertised role.

**People and data categories:** Applicants; contact details, CVs, employment history and interview notes.

**Recipients:** Recruitment staff, the hiring manager and the recruitment service provider. Confirm the actual categories and their access.

**International transfers:** [Check provider locations and support access; record relevant destinations and safeguards where applicable.]

**Retention:** [Record the reviewed retention period or criteria for this recruitment purpose.] A talent pool is a separate question.

**Security measures:** Example measures to verify: access restricted to the hiring team and access reviewed when team members change.

[Field reference: EDPB guidance on records of processing activities. ↗](https://www.edpb.europa.eu/sme/be-compliant/be-compliant_en)

## Questions for a RoPA questionnaire

1. 01

### HR: how does the process start and end?

List the sources of applications, the people who use them and what happens after a vacancy closes.

2. 02

### IT and procurement: which services are involved?

Confirm the provider, storage arrangements, access and relevant contractual information. Link the service record instead of copying its description into every activity.

3. 03

### Privacy specialist: what still needs review?

Review the purpose, applicable legal basis, retention and transfer information. Keep open questions visible; a completed form does not settle them.

## How to maintain a RoPA as work changes

Revisit the record when the process, business conditions, laws or internal requirements change. Keep the purpose, participants, risks and measures under review, not just the document.

### A new recruitment service

Recheck the system, provider, recipients and transfer information. In LogicPrivacy, configured rules can update related records from the information entered.

### Changes in requirements and standards

If requirements or a group retention standard change, ask the specialist to assess the effect on each participating company. Update the relevant process, risks, measures and documents.

### A risk requiring a measure

Keep the issue linked to its source process. Review the configured risk record and select an applicable measure; accepting a risk does not fulfil an unmet requirement.

## Put the example into a working process
