How To Start
When you first arrive at the ROPA page with no activities added, you will see an empty state with two options: Add Manually or Import CSV.
Add Manually - build your ROPA directly in Scytale by adding activities one by one. This is a good option if you are starting your ROPA from scratch.
Import CSV - upload your existing ROPA using Scytale's CSV template. If you already have a ROPA, this is the fastest way to get your data into the platform. See our separate guide on importing your ROPA via CSV.
Department Tabs
The ROPA is organized into department tabs. Each tab groups the processing activities that belong to that department. By default, Scytale provides common department tabs including HR, Finance, Marketing, Legal, Sales, Customer Success, and IT. You can:
Add a new department tab using the add department option
Edit an existing tab name
Delete a tab you no longer need
Filling In An Activity
To create an activity, three fields are mandatory:
Department
Activity Name
Purpose
Once the activity has been created, you will need to click 'Edit' to open the remaining fields and complete them to build out a full and accurate record. These include:
Data Subject Type: whether your organization acts as a Controller, Processor, or Sub-processor
Personal Data Type: the sensitivity level of the data (values 1–5)
Personal Data Source: where the data comes from (Activity, Data Subject, or Third Party)
Data Subject Volume: an estimated range of how many data subjects are affected
Data Subject Country: the countries or regions where data subjects are located
Children's Data: whether the activity involves data belonging to minors
Special Categories of Personal Data: whether sensitive categories of data are processed, and the authorisation basis
Legal Basis for Processing: Consent, Contract, Legal Obligation, or Legitimate Interest
Data Retention: how long the data is retained
Technical and Organizational Processes: the security measures in place for this activity
Fields are saved automatically as you fill them in.
Comments And Flags
Comments can be added to an activity to communicate notes or context to the Scytale privacy team or your internal team. These are added per activity.
Flags are used to highlight specific issues with a field that needs attention within an activity. To add a flag:
Click 'Add Flag' on the activity.
Write the details of the flag and save it.
Note that only one flag can be active on an activity at a time. Both you and the Scytale team can resolve a flag once the issue has been addressed.
Activity Status
Each activity has a status that reflects where it is in the review process:
In Progress: not all fields of the activity have been completed.
Ready for Review: all fields of the activity have been completed
In Review: the activity has been submitted as part of a ROPA review
Approved: the activity has been reviewed and approved by the Scytale privacy team.
Submitting for Review
Note: You need to complete all fields across all activities in order to submit your ROPA for review.
Once you have completed your processing activities, click 'Send to Review'. This will notify the Scytale privacy team, who will review your ROPA and add comments or flags to any activities that need attention.
Once you have addressed any flags or comments and made the necessary corrections, the Scytale team will approve your ROPA and all activities will move to Approved status. You will receive an email notification when your ROPA has been approved.
Evidence for Monitoring
Once your ROPA has been approved by the Scytale team, it will automatically populate as evidence to the relevant control and monitoring in Scytale - no manual action required.








