Vendors & ROPA: the vendor list and records of processing activities
- Written for
- + Written for
- Deprecated
- + Deprecated
- Applies to
- + Applies to
Vendors & ROPA: the vendor list and records of processing activities
What it's for
Dashboard → Privacy → Governance covers two GDPR-driven recordkeeping obligations that sit behind your banner: a Record of Processing Activities (RoPA) — Article 30's requirement to document what personal data you process and why — and a vendor register with automatic risk scoring for every third party you share data with. Both exist so "what do you process, under what legal basis, and who do you share it with" — one of the most common questions in a regulator inquiry or a customer's security/procurement review — has a five-minute answer instead of a scramble through old spreadsheets.
The tab shows two independent tables, one above the other: Record of processing activities first, then Vendors.
Step-by-step: adding a RoPA entry
Go to Dashboard → Privacy → Governance.
In the RoPA card, click New record.
Fill in:
Field
Description
Activity name
What the processing activity is called internally
Purpose
Why you're processing this data
Legal basis
consent,contract,legal-obligation,vital-interests,public-task,legitimate-interestsRetention (days)
How long the data is kept, as a whole number of days
Cross-border transfer
Checkbox — whether this activity moves data outside your home region
Click Add.
The table displays retention in a friendly, human-readable format — once retention crosses 365 days it's shown in years (e.g. "1.5 years") rather than a raw day count — and a Transfers out / In region badge per record, so a compliance reviewer can scan the whole RoPA at a glance without doing day-to-year math themselves.
Step-by-step: adding a vendor
In the Vendors card, click New vendor.
Fill in:
Field
Description
Vendor name
e.g. "Google Analytics"
Category
e.g. "Analytics", "Advertising" — free text
Region
Where the vendor processes data (dropdown, see below)
DPA signed
Checkbox — whether you have a Data Processing Agreement in place, checked by default
Click Add.
The region dropdown offers: United States, European Union, EEA, United Kingdom, Switzerland, Canada, Japan, New Zealand, and an Other / non-adequate catch-all — pick "Other" for any vendor whose region isn't independently GDPR-adequate.
Risk scoring
Every vendor gets an automatic risk score (0–100) and band — Low (under 30), Medium (30–59), or High (60+) — shown as columns in the vendor table, so you can prioritize which relationships need attention first.
The scoring model, applied additively and then clamped to 0–100, is:
Factor | Effect |
|---|---|
No DPA on file | +40 (the single biggest driver — processing without a contract is the largest legal exposure) |
Shares special-category data (health, biometric, genetic, religion, race, political, etc.) | +25 flat |
Subprocessor depth | +0 (none) / +5 (1–4) / +10 (5–19) / +15 (20+) |
Region not GDPR-adequate | +20 |
Recognized certifications | credit against the score, capped at −25 total: ISO 27001 (−15), SOC 2 (−10) |
In practice, through the dashboard's New Vendor dialog, only two of these factors are exposed and vary per vendor: DPA signed and region. Special category data, subprocessor count, and certifications aren't fields in the dashboard form — they default to none — so a vendor's score there is driven entirely by whether you checked DPA signed and which region you picked. The fuller model (special-category surcharge, subprocessor depth, certification credits) applies if those fields are set through the Developer API instead, using the Vendors scope (vendors:read/vendors:write).
GDPR-adequate regions (no extra transfer safeguard needed) are: EU, EEA, UK, US, Switzerland, Canada, Japan, New Zealand. A vendor whose region falls outside that set is scored as a higher-risk cross-border transfer, since it typically requires Standard Contractual Clauses or another Article 46 transfer mechanism to stay compliant — which is exactly why "Other / non-adequate" is a separate, deliberately unflattering option in the dropdown rather than being folded into a generic "elsewhere."
What the data means
A High risk band is a prioritization signal, not an automatic violation — it tells you where to focus a DPA renewal push or a transfer mechanism review first, not that you're necessarily out of compliance.
Transfers out on a RoPA entry and a vendor's non-adequate region score are related but separate concepts: the RoPA flag is about a specific processing activity moving data across borders; the vendor score is about where a specific third party processes data. A single activity can legitimately involve multiple vendors in different regions.
Export and compliance value
Together, RoPA and the vendor register are what let you produce, on short notice, the two documents almost every privacy audit asks for first: a list of what you process and why (Art. 30), and a list of who else touches that data and how exposed each relationship is. Keeping both current as you add new tools and vendors — rather than reconstructing them under deadline pressure when a regulator or enterprise customer asks — is the entire point of having them live in the dashboard next to DSAR and Preferences rather than in an offline spreadsheet nobody remembers to update.
See also: DSAR requests · Consent log