Skip to main content

How To Build Your ROPA

This guide walks you through everything you need to know to build and manage your ROPA in Scytale

How To Start

When you first arrive at the ROPA page with no activities added, you will see an empty state with two options: Add Manually or Import CSV.

  1. Add Manually - build your ROPA directly in Scytale by adding activities one by one. This is a good option if you are starting your ROPA from scratch.

  2. Import CSV - upload your existing ROPA using Scytale's CSV template. If you already have a ROPA, this is the fastest way to get your data into the platform. See our separate guide on importing your ROPA via CSV.

Department Tabs

The ROPA is organized into department tabs. Each tab groups the processing activities that belong to that department. By default, Scytale provides common department tabs including HR, Finance, Marketing, Legal, Sales, Customer Success, and IT. You can:

  • Add a new department tab using the add department option

  • Edit an existing tab name

  • Delete a tab you no longer need

Filling In An Activity

To create an activity, three fields are mandatory:

  • Department

  • Activity Name

  • Purpose

Once the activity has been created, you will need to click 'Edit' to open the remaining fields and complete them to build out a full and accurate record. These include:

  • Data Subject Type: whether your organization acts as a Controller, Processor, or Sub-processor

  • Personal Data Type: the sensitivity level of the data (values 1–5)

  • Personal Data Source: where the data comes from (Activity, Data Subject, or Third Party)

  • Data Subject Volume: an estimated range of how many data subjects are affected

  • Data Subject Country: the countries or regions where data subjects are located

  • Children's Data: whether the activity involves data belonging to minors

  • Special Categories of Personal Data: whether sensitive categories of data are processed, and the authorisation basis

  • Legal Basis for Processing: Consent, Contract, Legal Obligation, or Legitimate Interest

  • Data Retention: how long the data is retained

  • Technical and Organizational Processes: the security measures in place for this activity

Fields are saved automatically as you fill them in.

Comments And Flags

Comments can be added to an activity to communicate notes or context to the Scytale privacy team or your internal team. These are added per activity.

Flags are used to highlight specific issues with a field that needs attention within an activity. To add a flag:

  1. Click 'Add Flag' on the activity.

  2. Write the details of the flag and save it.

Note that only one flag can be active on an activity at a time. Both you and the Scytale team can resolve a flag once the issue has been addressed.

Activity Status

Each activity has a status that reflects where it is in the review process:

  • In Progress: not all fields of the activity have been completed.

  • Ready for Review: all fields of the activity have been completed

  • In Review: the activity has been submitted as part of a ROPA review

  • Approved: the activity has been reviewed and approved by the Scytale privacy team.

Submitting for Review

Note: You need to complete all fields across all activities in order to submit your ROPA for review.

Once you have completed your processing activities, click 'Send to Review'. This will notify the Scytale privacy team, who will review your ROPA and add comments or flags to any activities that need attention.

Once you have addressed any flags or comments and made the necessary corrections, the Scytale team will approve your ROPA and all activities will move to Approved status. You will receive an email notification when your ROPA has been approved.

Evidence for Monitoring

Once your ROPA has been approved by the Scytale team, it will automatically populate as evidence to the relevant control and monitoring in Scytale - no manual action required.

Did this answer your question?