Data Compliance Tracker · Data protection compliance software

Data protection compliance: your data inventory and Records of Processing Activities

What you hold data about and what you do with it — entities, the records kept on each with their attributes and owners, and a Record of Processing Activities for every activity, its compliance checklist answered item by item.

Included in Small business, Mid business, Large business, Dedicated Hosting

What Data Compliance Tracker does

Entities and records

  • Entities — Customer, Employee, Supplier — each with a business owner and a data owner
  • The records kept on each: login information, a profile, health records, attendance, behaviour — owners inherited from the entity unless one is named
  • Every record's attributes maintained one by one: what the field is, how it is classified, whether it is personal or a special category

Records of processing activities

  • A RoPA for each activity: its purpose, its owners, and the records it processes — what they hold read beside it
  • A compliance checklist copied from your own template — consent, personal data, third-party processing, retention and the rest — answered yes, no or not applicable, with notes
  • Items added, renamed and removed on the RoPA itself; a change to the template reaches new RoPAs and never one already answered
  • Retired with a reason and kept for the record; the number never reused

Data Compliance Tracker: questions and answers

What is a Record of Processing Activities (RoPA)?
A RoPA documents one processing activity: its purpose, who owns it and the personal data it uses. Data protection laws such as the GDPR expect organizations to keep them. In AI Pazz Govnex each RoPA names the records it processes, shows what they hold, and carries a compliance checklist answered item by item.
How do we build a personal data inventory?
Start with entities — Customer, Employee, Supplier — each with a business owner and a data owner. Add the records you keep on each, and maintain every record's attributes: what the field is, how it is classified, and whether it is personal or special-category data.
Can we use our own RoPA checklist?
Yes. Each RoPA's checklist is copied from your organization's own template — consent, personal data, third-party processing, retention and the rest. A change to the template reaches new RoPAs and never one already answered.