How to create a ROPA (Record of processing activity), GDPR Article 30

  Рет қаралды 7,247

iSTORM®️ Privacy-Security-Pentesting

iSTORM®️ Privacy-Security-Pentesting

Күн бұрын

Пікірлер: 37
@mahli12
@mahli12 2 ай бұрын
thank you brother, the information is very detailed about ROPA. thank you for helping me to understand what ROPA is.
@iSTORMDiaries
@iSTORMDiaries 2 ай бұрын
Thank you for watching, I’m pleased you found it useful
@fr33PS
@fr33PS Ай бұрын
This is absolutely top notch info. Thanks
@iSTORMDiaries
@iSTORMDiaries Ай бұрын
Glad it was helpful! Thanks for watching
@mozcakir
@mozcakir 3 ай бұрын
Thank you very much information about RoPA processes.
@iSTORMDiaries
@iSTORMDiaries 2 ай бұрын
Thanks for watching
@benanabunny
@benanabunny 3 жыл бұрын
Thank you. Very clearly explained.
@iSTORMDiaries
@iSTORMDiaries 3 жыл бұрын
Thank you for watching
@rinredasakiyalak3210
@rinredasakiyalak3210 3 жыл бұрын
Dear Richard, I am a law undergradute student from Thailand and I would like to express my sincere gratitude for your videos as they have immensely deepen my understanding about Personal Data Protection Law. I am now participating in a university competition which I have to collaborate with engineering and business students to comeup with a software or technology that would solve or better a legal issue. I would like to ask if you have any recommendation regarding any issue or area in Data Protection that a software or technology could solve or could improve the status quo? My team would be extremely grateful for you answers and insight. Yours respectfully. :)
@iSTORMDiaries
@iSTORMDiaries 3 жыл бұрын
I'm sorry for the incredibly delayed reply! There are a few areas that can benefit from automation under the GDPR, the main one being the management of third party suppliers and supplier assurance. This is a time consuming process that requires a lot of administrative support so any efforts to reduce that burden is often welcomed. There are a couple of tools that would aid your research in this area, mainly OneTrust and also The Compliance Space www.thecompliancespace.com/. If you can make a user friendly supplier assurance tool, you'd be in a great place! Good luck with your studies
@cintakhutbah
@cintakhutbah 4 ай бұрын
Takeaways 📝 A Record of Processing Activities (RoPA) is a requirement under Article 30 of the GDPR, documenting how organizations process personal data. 🔎 RoPA can help organizations understand what personal data they process, who they share it with, the purposes, and the security measures in place. 📝 Many organizations find RoPA confusing and are unsure where to start, but it's essential for regulatory compliance and organizational insight. 🚀 Starting a RoPA involves not being afraid of the process, understanding it's a timely task that requires effort and buy-in from the organization. 🛠 There are tools and privacy management software available to help create a RoPA, but simple templates can also be effective, especially those provided by the ICO. 📚 RoPA should document all processing activities, including HR, marketing, and third-party processing, where personal data is handled. 📋 A questionnaire can be a useful tool to gather information from different departments about the data they hold, its usage, protection, and retention period. 🔑 Keeping the RoPA simple and avoiding over-complication is key to making it accessible and easy to manage. 🔄 RoPA is a living document that needs regular updates to reflect changes in data processing activities and third-party relationships. 📅 It's recommended to have a defined review period for the RoPA, such as quarterly, semi-annually, or annually, to ensure accuracy and relevance. ✉ If you have questions or need assistance with creating a RoPA, reaching out to experts or checking resources like the ICO's website can provide guidance and support.
@nireshg6141
@nireshg6141 Жыл бұрын
Thank you so much brother. Very useful
@devaguru-ww5yg
@devaguru-ww5yg Жыл бұрын
Really useful keep updating regarding ropa
@webbac8491
@webbac8491 3 жыл бұрын
A further and very informative video - thank you Richard. Just one question, I understand the ROPA, as you say, is an 'organic living document', but how long must an organisation retain their ROPA, i.e. would it be until such a time that the organisation ceases to exist?
@iSTORMDiaries
@iSTORMDiaries 3 жыл бұрын
The ROPA should always be updated with new processing activities, third parties, controls etc. so it will always exist for as long as the processing activities are carried out. Arguably, yes, it will be around for as long as the organisation itself.
@webbac8491
@webbac8491 3 жыл бұрын
@@iSTORMDiaries Thank you Richard. Most appreciated.
@adaorachidinma1660
@adaorachidinma1660 Жыл бұрын
Very insightful video. I’m happy we have people like you in the industry to guide us. Please can I use share point to create a ROPA?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
You're very kind, thank you! You can use anything you like, excel is usually the easiest to manage but sharepoint is a great option to allow more people to access and manage the content.
@strigliariko
@strigliariko 2 жыл бұрын
Very informative. May I ask which online tools you would suggest using to an EU lawyer who has GDPR certification but never used an online tool for a small company? I am interested in having a tool that is straightforward even for a non lawyer, easy to use (you do not lose half of your life registering activities) and where you can register all the information needed for complying with records of processing activity .
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
Thanks for watching. There are a couple of tools that are either free or inexpensive and very useful. I would check out www.thecompliancespace.com and Keepable keepabl.com both are very good tools for small businesses!
@strigliariko
@strigliariko 2 жыл бұрын
@@iSTORMDiaries thanks a lot!
@KirkpatrickSounds
@KirkpatrickSounds 3 жыл бұрын
Fantastic channel and great content!
@iSTORMDiaries
@iSTORMDiaries 3 жыл бұрын
Thank you!
@DeanJenkins-ji7pr
@DeanJenkins-ji7pr 4 ай бұрын
great video really helpful
@arjunmohandas8870
@arjunmohandas8870 Жыл бұрын
Really helpful
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Thanks for watching!
@Awesomeite4life
@Awesomeite4life 3 жыл бұрын
Hi Richard, great video. Is ROPA and Data Mapping used interchangeably?
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
Hey, very often yes. They can be one and the same as the process of completing both is very similar. A ROPA has very clear requirements whereas a data map is not defined and will often be more of technical diagram. In my experience, people are talking about the same thing though
@Amelia-qm6bk
@Amelia-qm6bk 2 жыл бұрын
Is this part of the DPO responsibly?
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
It’s not actually part of the DPO’s ‘tasks’ under article 39 although it is within our responsibility to review and oversee such documents. In reality, it’s usually the DPO that leads if not creates the RoPA but it needs input from all areas of the business to be effective
@Amelia-qm6bk
@Amelia-qm6bk 2 жыл бұрын
@@iSTORMDiaries thank you very much
@mileswood637
@mileswood637 3 жыл бұрын
Thank you
@omprakashyadav9272
@omprakashyadav9272 2 жыл бұрын
What's the difference between Ropa and DPIA
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
RoPA is your Record of Processing Activity, this is where you document what data you process in the business, who it belongs to and why you have it. Think of it like an information register. A DPIA is risk assessment essentially. DPIA's are carried out on processing activities such as background checks for employees. We want to see what the checks are, why they need to be done, how the individual will be effected and what can be done to protect and inform them.
@mskri55i
@mskri55i Жыл бұрын
Do I need separate IAR and ROPA?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Information asset register and RoPA are different documents with different purposes but they can easily be combined by adding the information assets into your RoPA. Personally I’d use a separate tab as there’ll be assets that aren’t used for processing but many of them will overlap
@yog4ever
@yog4ever 2 жыл бұрын
You lost me at David Goggins :)
5 essentials skills you need to be an effective Data Protection Officer
14:21
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 4,2 М.
Article 6 GDPR: the 6 legal bases & 9 top tips
13:06
Privacy Kitchen
Рет қаралды 11 М.
Всё пошло не по плану 😮
00:36
Miracle
Рет қаралды 6 МЛН
Ouch.. 🤕⚽️
00:25
Celine Dept
Рет қаралды 33 МЛН
ЛУЧШИЙ ФОКУС + секрет! #shorts
00:12
Роман Magic
Рет қаралды 21 МЛН
ROSÉ & Bruno Mars - APT. (Official Music Video)
02:54
ROSÉ
Рет қаралды 251 МЛН
Becoming a Data Privacy Expert is Actually Easy Peasy
14:44
Privacy Pros
Рет қаралды 642
AI and the GDPR (1): Making sense of AI and data protection
30:35
Fieldfisher Silicon Valley
Рет қаралды 7 М.
Protect your data today!!! The Mother of all data breaches is here
9:25
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 396
Starting your Data Protection career journey!
10:08
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 10 М.
What is a Transfer for GDPR?  5 Key Facts
6:58
Privacy Kitchen
Рет қаралды 6 М.
10 Steps to GDPR Compliance
8:40
Privacy Kitchen
Рет қаралды 25 М.
Vendor risk management - 4 tips to improve your process and overcome challenges
13:19
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 183
How to do a Data Protection Impact Assessment.  What is a DPIA & why they’re beneficial (GDPR)
6:53
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 7 М.
Pentesting for DPO’s
9:35
iSTORM®️ Privacy-Security-Pentesting
Рет қаралды 159
The Data Protection Act and the General Data Protection Regulation (GDPR)
34:41
Computer Science Lessons
Рет қаралды 36 М.
Всё пошло не по плану 😮
00:36
Miracle
Рет қаралды 6 МЛН