What’s the Difference Between Article 30, Extended and Processor RoPA?
Your platform supports three types of RoPA exports. Each is designed for a different use case or legal role.
dot.legal supports three RoPA types to match your organisation's role and reporting needs. This article explains which type applies to your situation and what each one records. Quick answer: Choose the Standard Article 30 RoPA if you are a data controller, the Extended RoPA for internal governance, or the Processor RoPA if your organisation acts as a data processor under GDPR Article 30(2).
1. Standard Article 30 RoPA (Controller)This is the standard compliance version required under GDPR for data controllers:
- Follows the structure of GDPR Article 30(1)
- Includes data subject types, categories, recipients, legal basis and retention
2. Extended RoPA (Internal Use)
This type builds on the Standard Article 30 RoPA and adds fields for internal governance purposes:
- Linked systems
- Risk classification
- Security measures
- Task assignment and validation status
Tip: Use this version for internal quality checks, Data Protection Officer (DPO) reviews, or management reporting. Note: this type is not required for regulatory submission to a supervisory authority.
3. Processor RoPA (Article 30(2))
Designed for organisations acting as data processors under GDPR Article 30(2) — that is, organisations processing personal data on behalf of a controller — this version records:
- Instructions from the controller
- Security measures implemented
- Sub-processors used
How to Change Your RoPA Type in dot.legal
To change the RoPA type for an existing processing activity, open the activity, navigate to the Settings or Type field, and select the appropriate RoPA type from the dropdown. Changes take effect immediately. If you are unsure which type to select, refer to the descriptions above.
Related Articles
