Skip to main content

How To Import A ROPA CSV

This guide will show you how to import your ROPA quickly and efficiently

Step 1

Navigate to the ROPA page. If your ROPA is empty, select 'Import CSV' from the empty state. If you already began work on your ROPA, go to the 3 dot menu on the ROPA page and select 'Import CSV'.

Step 2

Download the CSV template. If you already have a completed template, skip the download and proceed to upload.

Step 3

Open the CSV file. You will see the following columns.

Three fields are mandatory and must be completed for every row - the import will fail without them:

  • Department

  • Activity Name

  • Purpose

All other columns are optional but recommended for a complete and accurate ROPA.

When you open the CSV, you'll see a second row with information.

This row is there to help you and includes guidance on what to fill in for each column.

It includes if a field has a specific set of accepted values or is free text. Where accepted values are listed, make sure to use only those exact values to avoid any import errors.

Once you've filled everything in, simply delete that row before uploading your file.

Columns accepting free text:

  • Department (required)

  • Activity Name (required)

  • Purpose (required)

  • Data Subject Type (e.g. Employee, Candidates, Customer, Prospective Customer, Contractors, Suppliers)

  • Personal Data Type (e.g. name, email address, CV, salary details)

  • Data Subject Volume (e.g. 1–100, 100–500, 500–1000)

  • Data Subject Country (e.g. EU, US, UK, Israel)

  • Data Retention

Columns with accepted values:

  • Personal Data Source: Data Subject, Third party

  • Children's Data: Yes, No

  • Special Categories of Personal Data: Yes, No

  • Special Categories of Personal Data Authorisation (Note: ONLY relevant if your answer for Special Categories Of Personal Data was 'yes'): Explicit consent / Employment / Social security and social protection (if authorised by law) / Vital interests / Not-for-profit bodies / Made public by the data subject / Legal claims or judicial acts / Reasons of substantial public interest (with a basis in law) / Health or social care (with a basis in law) / Public health (with a basis in law) / Archiving / Research and statistics (with a basis in law)

  • Legal Basis for Processing: Consent, Contract, Legal Obligation, Legitimate Interest

  • Processing Role: Controller, Processor, Sub-processor

  • Technical and Organizational Processes: Access Control / Monitoring and Logging / Encryption / Data backup / Breach detection tools / Firewalls / User access management / Email scanning / Internal awareness and training / Internal policies and plans / Vendor risk management / Multi-factor authentication / Mobile device management tools / Network authentication / Anonymization / Regular software updates

Step 4

Remove the placeholder text and fill in the details of all your processing activities. Do not remove the column titles.

Once complete, save the file as a CSV.

Step 5

Go back to Scytale and upload the completed CSV file.

Your ROPA should now be imported.

If there was a problem with your file, an error message will appear. It will specify which row has the issue and what the problem is. Correct the issues and re-upload the CSV.

Did this answer your question?