Records of Processing FAQs

Expand All

Helpful Videos for You

Need help? Check out videos for quick assistance!

What is the difference between Records of Processing (RoP) and Records of Processing Activity (RoPA)? RoP (Area & Activity)

Records of Processing (RoP) refers to the broader departments or areas within your organisation where data processing activities occur. It provides a high-level view of the different processing areas and the overall purposes and nature of the processing within them, such as HR, admissions, alumni or IT.

A Record of Processing Activity (RoPA) records the detail of a specific processing activity within that area, including what personal data is used, whose data it is, why it is processed and whether it is transferred.

In summary, RoP is the different areas where processing occurs, while RoPA is the individual processing activity within it.

 
 

Who can see and edit a Record of Processing area or activity? RoP (Area & Activity)

Being granted access to Records of Processing lets you create new processing areas, but it does not give you access to every existing area or activity.

For a processing area, you can be the Owner or a Member. For a processing activity, you can be the Owner, Member, Reviewer, Attachment Reviewer or Notified User. Owners and members of a processing area can also access the activities within that area.

The Owner can edit and delete the area or activity they own. Other assigned roles can edit it but cannot delete it.

If you need access to an area or activity you cannot find in the relevant log, ask your organisation’s 9ine Platform Administrator to review your access

 
 

How do I move a record of processing activity to a different area? RoP (Area & Activity)

If you have permission to move the activity, you can move it directly to another processing area.

If you do not have permission to move it directly, a request is sent to the Owner of the destination area to approve or reject. The Platform shows you who will receive the request before you send it.

While a move request is outstanding, the activity cannot be edited and its quick actions are unavailable. The request can be withdrawn before it is approved. Moving the activity keeps all of its existing content.

 
 

What is the Quickstart for Records of Processing? RoP (Area & Activity)

Quickstart provides pre-configured processing areas and activities designed for schools, which you can add to your organisation and then customise.

Quickstart is available when you create a processing area and can also be used within an existing area. Activities added through Quickstart are identified until they have been edited and saved, helping you see which records still contain template wording that needs to be reviewed by your organisation.

 
 

What happens if I close or delete a record of processing area? RoP (Area & Activity)

Closing a processing area also closes its activities and their associated risks, issues, lessons and tasks. Deleting the area deletes them.

If you reopen a closed area, its associated items are restored: activities, risks, issues and lessons return to Open, while tasks return to Not Started.

 
 

What does duplicating a Record of Processing Activity copy? RoP (Area & Activity)

Duplicate creates a copy of the processing activity with Copy Of added to the title.

It does not copy associated risks, issues, lessons or tasks, and it does not duplicate a linked DPIA. These can be added separately to the new activity where needed.

 
 

The link is created from the vendor record.

Open the vendor from the Processing Operation Assessment Log and use Link RoP(s) and Link RoPA(s) to select the processing areas and activities the vendor processes data for.

Once linked, the vendor is shown against the relevant processing area and activity records.

 
 

What happens when a Record of Processing Activity is linked to a DPIA? RoP (Area & Activity)

Information shared by the Record of Processing Activity (RoPA) and Data Protection Impact Assessment (DPIA) is kept in sync, so the same information does not need to be entered twice. Changes to shared information are reflected in both records.

A DPIA can be started from the activity’s review step, or an activity can be linked from the DPIA screening step.

Linking also shares access to that activity: users who can access the DPIA can view and edit the linked activity, but this does not give them access to other activities in the same processing area.

 
 

How do I see only the Records of Processing I am responsible for? RoP (Area & Activity)

Use My Areas on the processing area log or My Activities on the processing activity log.

Each filters the relevant log to items that are not closed and where you are the Owner, Member or Notified User. For more specific criteria, use Filter.

 
 

What can I download from Records of Processing? RoP (Area & Activity)

You can download:

  • Log from the area log: Exports the processing areas currently displayed.
  • Advanced from the area log: Exports processing areas together with their activities.
  • Log from the activity log: Exports the processing activities currently displayed.
  • Advanced from the activity log: Provides the detailed activity export.
  • Download from an individual activity: Creates the completed form as a Word document.

Your search, filter, view and toggle selections affect what is included in a log export, so set them before downloading.

Exports are generated in the background. You receive an email and an in-Platform notification with the download link when the export is ready.