ropa-maintenance-workflow
Installation
SKILL.md
RoPA Maintenance Workflow
Overview
Creating a RoPA is a point-in-time exercise; maintaining it is a continuous obligation. GDPR Art. 5(2) accountability requires that processing records reflect current reality at all times. The Belgian DPA in Decision 21/2022 sanctioned an organisation whose RoPA had not been updated for over two years despite significant processing changes. This skill establishes the governance framework, triggers, workflows, and verification procedures to keep the RoPA accurate, current, and audit-ready.
Update Triggers
A RoPA update must be initiated when any of the following events occur:
Mandatory Triggers (Immediate Update Required)
| Trigger Event | Affected Fields | Update Deadline |
|---|---|---|
| New processing activity introduced | All Art. 30(1) fields for new entry | Before processing commences |
| Processing activity discontinued | Entire entry archived | Within 30 days of cessation |
| Change in processing purpose | Art. 30(1)(b) — purposes | Before new purpose is acted upon |
| New category of data subjects added | Art. 30(1)(c) — data subjects | Before data collection from new category |
| New special category data processed | Art. 30(1)(c) — personal data; Art. 9(2) condition | Before processing begins |
Related skills