Blog category
gdpr
DPAFlow blog posts in gdpr.
Search this category
Showing 1–9 of 9.
Posts
2026-07-29 · gdpr
How to Create a Record of Processing Activities
The Article 30 field list is the easy part. This is the practical build: discovering the processing nobody wrote down, deciding what counts as one activity, running interviews that produce facts rather than guesses, and sequencing a first register so it becomes usable before it is finished.
2026-07-29 · gdpr
RoPA vs DPIA: What Is the Difference and Which Do You Need?
A RoPA is an inventory of all your processing; a DPIA is a risk assessment of the high-risk parts, completed before that processing starts. What Article 30 and Article 35 each require, the five differences that matter, how to tell whether a DPIA is needed, and why vendor changes affect one document far more than the other.
2026-07-29 · gdpr
Records of Processing Activities: What Article 30 Actually Requires
What GDPR Article 30 requires in a record of processing activities, field by field, who the small-organisation exemption really covers, and why the recipient and third-country transfer fields go out of date without anyone in your organisation changing anything.
2026-07-25 · gdpr
What Evidence Should You Retain From Vendor Reviews?
Keeping everything forever and keeping nothing both fail. How to set retention by purpose, why most of this material is not personal data, a workable schedule, and how to dispose of evidence defensibly without erasing former vendors.
2026-07-25 · gdpr
Processor Audit Rights Under GDPR Article 28
Article 28(3)(h) contains two rights that behave very differently: a standing information right you will use constantly, and an inspection right that standard contracts narrow heavily. What each gives you, and what to negotiate.
2026-07-25 · gdpr
Keeping a RoPA Accurate as Vendors Change
Vendor and subprocessor changes are the main way Article 30 records drift out of date. What belongs in a RoPA, how entries silently go stale, and a maintenance loop that keeps the record aligned with reality.
2026-07-25 · gdpr
Audit-Ready Vendor Evidence
Accountability means being able to demonstrate vendor compliance, not just assert it. The evidence worth keeping, the qualities that make it audit-ready, and how dated captures reconstruct what a vendor disclosed on a given date.
2026-07-25 · gdpr
Controller, Processor, and Sub-processor: GDPR Roles Explained
Controller, processor, and sub-processor are distinct GDPR roles with different obligations. This guide explains each role with SaaS-shaped examples, covers joint controllership, and shows why classification matters.
2026-07-25 · gdpr
How to Build a Vendor and Subprocessor Inventory
Every GDPR vendor duty starts from one question: who has our data? Here is how to build a vendor and subprocessor inventory that answers it — scoping, minimal fields, collection sources, and the maintenance rhythm that keeps it true.
Monitor subprocessor changes before they become audit work.
Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.