How to create a ROPA (Record of processing activity), GDPR Article 30

  Рет қаралды 6,702

iSTORM®️ Privacy-Security-Pentesting

iSTORM®️ Privacy-Security-Pentesting

Күн бұрын

In this weeks video, we take a look at Article 30 of the GDPR and the Record of processing activities or ROPA! What it is, why it's important and how you can document your own!
Help us reach 500 subscribers: kzbin.info...

Пікірлер: 31
@DeanJenkins-ji7pr
@DeanJenkins-ji7pr Ай бұрын
great video really helpful
@devaguru-ww5yg
@devaguru-ww5yg Жыл бұрын
Really useful keep updating regarding ropa
@benanabunny
@benanabunny 3 жыл бұрын
Thank you. Very clearly explained.
@iSTORMDiaries
@iSTORMDiaries 3 жыл бұрын
Thank you for watching
@nireshg6141
@nireshg6141 Жыл бұрын
Thank you so much brother. Very useful
@KirkpatrickSounds
@KirkpatrickSounds 3 жыл бұрын
Fantastic channel and great content!
@iSTORMDiaries
@iSTORMDiaries 3 жыл бұрын
Thank you!
@mileswood637
@mileswood637 3 жыл бұрын
Thank you
@rinredasakiyalak3210
@rinredasakiyalak3210 3 жыл бұрын
Dear Richard, I am a law undergradute student from Thailand and I would like to express my sincere gratitude for your videos as they have immensely deepen my understanding about Personal Data Protection Law. I am now participating in a university competition which I have to collaborate with engineering and business students to comeup with a software or technology that would solve or better a legal issue. I would like to ask if you have any recommendation regarding any issue or area in Data Protection that a software or technology could solve or could improve the status quo? My team would be extremely grateful for you answers and insight. Yours respectfully. :)
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
I'm sorry for the incredibly delayed reply! There are a few areas that can benefit from automation under the GDPR, the main one being the management of third party suppliers and supplier assurance. This is a time consuming process that requires a lot of administrative support so any efforts to reduce that burden is often welcomed. There are a couple of tools that would aid your research in this area, mainly OneTrust and also The Compliance Space www.thecompliancespace.com/. If you can make a user friendly supplier assurance tool, you'd be in a great place! Good luck with your studies
@adaorachidinma1660
@adaorachidinma1660 Жыл бұрын
Very insightful video. I’m happy we have people like you in the industry to guide us. Please can I use share point to create a ROPA?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
You're very kind, thank you! You can use anything you like, excel is usually the easiest to manage but sharepoint is a great option to allow more people to access and manage the content.
@arjunmohandas8870
@arjunmohandas8870 Жыл бұрын
Really helpful
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Thanks for watching!
@webbac8491
@webbac8491 3 жыл бұрын
A further and very informative video - thank you Richard. Just one question, I understand the ROPA, as you say, is an 'organic living document', but how long must an organisation retain their ROPA, i.e. would it be until such a time that the organisation ceases to exist?
@iSTORMDiaries
@iSTORMDiaries 3 жыл бұрын
The ROPA should always be updated with new processing activities, third parties, controls etc. so it will always exist for as long as the processing activities are carried out. Arguably, yes, it will be around for as long as the organisation itself.
@webbac8491
@webbac8491 3 жыл бұрын
@@iSTORMDiaries Thank you Richard. Most appreciated.
@strigliariko
@strigliariko 2 жыл бұрын
Very informative. May I ask which online tools you would suggest using to an EU lawyer who has GDPR certification but never used an online tool for a small company? I am interested in having a tool that is straightforward even for a non lawyer, easy to use (you do not lose half of your life registering activities) and where you can register all the information needed for complying with records of processing activity .
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
Thanks for watching. There are a couple of tools that are either free or inexpensive and very useful. I would check out www.thecompliancespace.com and Keepable keepabl.com both are very good tools for small businesses!
@strigliariko
@strigliariko 2 жыл бұрын
@@iSTORMDiaries thanks a lot!
@Awesomeite4life
@Awesomeite4life 2 жыл бұрын
Hi Richard, great video. Is ROPA and Data Mapping used interchangeably?
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
Hey, very often yes. They can be one and the same as the process of completing both is very similar. A ROPA has very clear requirements whereas a data map is not defined and will often be more of technical diagram. In my experience, people are talking about the same thing though
@omprakashyadav9272
@omprakashyadav9272 Жыл бұрын
What's the difference between Ropa and DPIA
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
RoPA is your Record of Processing Activity, this is where you document what data you process in the business, who it belongs to and why you have it. Think of it like an information register. A DPIA is risk assessment essentially. DPIA's are carried out on processing activities such as background checks for employees. We want to see what the checks are, why they need to be done, how the individual will be effected and what can be done to protect and inform them.
@Amelia-qm6bk
@Amelia-qm6bk 2 жыл бұрын
Is this part of the DPO responsibly?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
It’s not actually part of the DPO’s ‘tasks’ under article 39 although it is within our responsibility to review and oversee such documents. In reality, it’s usually the DPO that leads if not creates the RoPA but it needs input from all areas of the business to be effective
@Amelia-qm6bk
@Amelia-qm6bk Жыл бұрын
@@iSTORMDiaries thank you very much
@mskri55i
@mskri55i Жыл бұрын
Do I need separate IAR and ROPA?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Information asset register and RoPA are different documents with different purposes but they can easily be combined by adding the information assets into your RoPA. Personally I’d use a separate tab as there’ll be assets that aren’t used for processing but many of them will overlap
@yog4ever
@yog4ever 2 жыл бұрын
You lost me at David Goggins :)
@malamdikereta
@malamdikereta Ай бұрын
Takeaways 📝 A Record of Processing Activities (RoPA) is a requirement under Article 30 of the GDPR, documenting how organizations process personal data. 🔎 RoPA can help organizations understand what personal data they process, who they share it with, the purposes, and the security measures in place. 📝 Many organizations find RoPA confusing and are unsure where to start, but it's essential for regulatory compliance and organizational insight. 🚀 Starting a RoPA involves not being afraid of the process, understanding it's a timely task that requires effort and buy-in from the organization. 🛠 There are tools and privacy management software available to help create a RoPA, but simple templates can also be effective, especially those provided by the ICO. 📚 RoPA should document all processing activities, including HR, marketing, and third-party processing, where personal data is handled. 📋 A questionnaire can be a useful tool to gather information from different departments about the data they hold, its usage, protection, and retention period. 🔑 Keeping the RoPA simple and avoiding over-complication is key to making it accessible and easy to manage. 🔄 RoPA is a living document that needs regular updates to reflect changes in data processing activities and third-party relationships. 📅 It's recommended to have a defined review period for the RoPA, such as quarterly, semi-annually, or annually, to ensure accuracy and relevance. ✉ If you have questions or need assistance with creating a RoPA, reaching out to experts or checking resources like the ICO's website can provide guidance and support.
Starting your Data Protection career journey!
10:08
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 9 М.
5 key steps to kick start your journey to Data Protection compliance
10:55
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 372
WHAT’S THAT?
00:27
Natan por Aí
Рет қаралды 14 МЛН
Clowns abuse children#Short #Officer Rabbit #angel
00:51
兔子警官
Рет қаралды 77 МЛН
AI and the GDPR (1): Making sense of AI and data protection
30:35
Fieldfisher Silicon Valley
Рет қаралды 7 М.
Article 6 GDPR: the 6 legal bases & 9 top tips
13:06
Privacy Kitchen
Рет қаралды 10 М.
DSAR’s how to prepare your business and enforcement notices!
12:07
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 205
GDPR explained: How the new data protection act could change your life
5:40
Virtual Session: GDPR without the Hype
58:34
RSA Conference
Рет қаралды 61 М.
Process mapping - 5 steps for you to follow today!
9:43
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 337
Google Analytics & GDPR - 3 Cases, 9 Takeaways and 4 Alternatives
8:40
Privacy Kitchen
Рет қаралды 4,7 М.
How to do a Data Protection Impact Assessment.  What is a DPIA & why they’re beneficial (GDPR)
6:53
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 7 М.
£3,000 fine for unlawful access of patient records, 3 lessons for your business
13:15
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 182