Skip to content
DPAFlow

Blog category

gdpr

DPAFlow blog posts in gdpr.

Search this category

Showing 1–9 of 9.

Posts

2026-07-29 · gdpr

How to Create a Record of Processing Activities

The Article 30 field list is the easy part. This is the practical build: discovering the processing nobody wrote down, deciding what counts as one activity, running interviews that produce facts rather than guesses, and sequencing a first register so it becomes usable before it is finished.

2026-07-29 · gdpr

RoPA vs DPIA: What Is the Difference and Which Do You Need?

A RoPA is an inventory of all your processing; a DPIA is a risk assessment of the high-risk parts, completed before that processing starts. What Article 30 and Article 35 each require, the five differences that matter, how to tell whether a DPIA is needed, and why vendor changes affect one document far more than the other.

2026-07-29 · gdpr

Records of Processing Activities: What Article 30 Actually Requires

What GDPR Article 30 requires in a record of processing activities, field by field, who the small-organisation exemption really covers, and why the recipient and third-country transfer fields go out of date without anyone in your organisation changing anything.

2026-07-25 · gdpr

What Evidence Should You Retain From Vendor Reviews?

Keeping everything forever and keeping nothing both fail. How to set retention by purpose, why most of this material is not personal data, a workable schedule, and how to dispose of evidence defensibly without erasing former vendors.

2026-07-25 · gdpr

Processor Audit Rights Under GDPR Article 28

Article 28(3)(h) contains two rights that behave very differently: a standing information right you will use constantly, and an inspection right that standard contracts narrow heavily. What each gives you, and what to negotiate.

2026-07-25 · gdpr

Keeping a RoPA Accurate as Vendors Change

Vendor and subprocessor changes are the main way Article 30 records drift out of date. What belongs in a RoPA, how entries silently go stale, and a maintenance loop that keeps the record aligned with reality.

2026-07-25 · gdpr

Audit-Ready Vendor Evidence

Accountability means being able to demonstrate vendor compliance, not just assert it. The evidence worth keeping, the qualities that make it audit-ready, and how dated captures reconstruct what a vendor disclosed on a given date.

2026-07-25 · gdpr

Controller, Processor, and Sub-processor: GDPR Roles Explained

Controller, processor, and sub-processor are distinct GDPR roles with different obligations. This guide explains each role with SaaS-shaped examples, covers joint controllership, and shows why classification matters.

2026-07-25 · gdpr

How to Build a Vendor and Subprocessor Inventory

Every GDPR vendor duty starts from one question: who has our data? Here is how to build a vendor and subprocessor inventory that answers it — scoping, minimal fields, collection sources, and the maintenance rhythm that keeps it true.

Monitor subprocessor changes before they become audit work.

Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.

View evidence workflow