| name | controller-ropa-creation |
| title | Controller RoPA Creation |
| description | Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and contact details, processing purposes, data subject categories, personal data categories, recipient categories, third country transfers, and retention periods. Includes Python generator for automated RoPA creation. Activate for controller RoPA, Art. 30(1), processing records, data mapping. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/controller-ropa-creation |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
Controller RoPA Creation
Overview
GDPR Article 30(1) requires every controller to maintain a written record of processing activities carried out under its responsibility. This skill provides a complete methodology for creating controller RoPA entries that satisfy all seven mandatory field requirements specified in Art. 30(1)(a) through (g), ensuring the organisation can demonstrate accountability under Art. 5(2) and respond to supervisory authority requests under Art. 30(4).
Mandatory Field Requirements
Field 1: Controller Identity and Contact Details — Art. 30(1)(a)
This field must identify:
- Legal entity name: The registered name of the controller as it appears in the national business register (e.g., Companies House, Handelsregister, Registre du Commerce).
- Registered address: The official registered office address.
- Contact details: General contact email and telephone for data protection inquiries.
- Joint controller(s): Where processing is jointly determined under Art. 26, the identity and contact details of each joint controller and a reference to the Art. 26 arrangement.
- EU Representative: Where the controller is not established in the EEA, the identity and contact details of the Art. 27 representative.
- Data Protection Officer: Name, email, and telephone of the DPO appointed under Art. 37, or a statement that no DPO is required with justification.
Example for Helix Biotech Solutions:
| Sub-field | Value |
|---|
| Legal entity name | Helix Biotech Solutions GmbH |
| Registered address | Leopoldstraße 42, 80802 Munich, Germany |
| Registration | HRB 267891, Amtsgericht Munich |
| Contact email | privacy@helix-biotech.eu |
| DPO | Dr. Elena Voss, dpo@helix-biotech.eu, +49 89 7654 3210 |
| EU Representative | Not applicable (established in EEA) |
| Joint controllers | None for this processing activity |
Field 2: Purposes of Processing — Art. 30(1)(b)
Each processing activity must have one or more specific, explicit, and legitimate purposes documented. Purposes must be granular enough to demonstrate compliance with the purpose limitation principle under Art. 5(1)(b).