vaulytica

Records of Processing Activities (GDPR Art. 30) review

GDPR Art. 30 records of processing activities for controllers / processors.

Review your document — free → See a sample report

What it checks

Controller / DPO identification — Art. 30(1)(a)

ROPA must identify controller (and joint controller / representative / DPO).

Critical · PRV-015

Purposes of processing — Art. 30(1)(b)

ROPA must state the purposes of processing.

Critical · PRV-016

Categories of data subjects and personal data — Art. 30(1)(c)

ROPA must describe the categories of data subjects and the categories of personal data.

Critical · PRV-017

Recipients — Art. 30(1)(d)

ROPA must enumerate categories of recipients.

Critical · PRV-018

International transfers — Art. 30(1)(e)

ROPA must identify transfers to third countries with the safeguards in place.

Critical · PRV-019

Retention periods and security measures — Art. 30(1)(f)–(g)

ROPA must state retention periods (where possible) and a general description of Art. 32 security measures.

Critical · PRV-020

Every run also applies 103 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.

How it works

  1. Open vaulytica.com — no account, nothing to install.
  2. Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
  3. Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
Review your document — free →

More privacy & data protection documents

Every document type →