EmberHound ROPA Workspace

A record of processing that earns its keep.

Keep a record of processing your team actually maintains. Start from worked examples, put every entry through review and sign-off, and hand over a signed evidence pack when someone asks. When a subject access request arrives, the register supplies the purposes and legal bases for the response.

  • Every Article 30(1) field
  • 14 worked example templates
  • Role-gated sign-off
  • Signed evidence pack export

The problem

Written for the audit, then left to rot.

If a register exists at all, it's usually a spreadsheet filled in before an audit, by someone who has since moved on. Nobody owns its review, nobody trusts its contents, and when a regulator, a customer, or a data subject asks a question, the answer gets assembled from scratch.

Written once, trusted never

The register described the organisation as it was the week it was written. Processing changed; the spreadsheet did not.

No review discipline

A spreadsheet has no draft state, no sign-off, and no next review date. There is no way to tell a considered entry from a placeholder.

Disconnected from real requests

When a subject access request arrives, the register should supply the purposes and legal bases. A file in a drawer supplies nothing.

The workflow

Start from examples, sign off, put it to work.

  1. 01

    Start from worked examples

    Load any of 14 template activities, from payroll to CCTV, as drafts.

  2. 02

    Adapt each entry

    Correct the legal basis, recipients, retention, and transfers to match your organisation.

  3. 03

    Review and sign off

    A permitted reviewer signs the entry off. The record keeps who reviewed it and when it's next due.

  4. 04

    Answer requests from it

    Signed-off entries feed your Article 15 responses with purposes and legal bases.

  5. 05

    Export the signed pack

    Generate a signed evidence pack whenever someone asks for the register.

The record

Every Article 30(1) field, one entry at a time.

Each processing activity is a structured record with a controlled legal-basis choice mapped to the Article 6(1) sub-paragraphs. Transfer countries and safeguards live in the same entry, so a transfer can't be claimed without saying what protects it.

  • Process name and purpose
  • Controller
  • Legal basis, mapped to Art. 6(1)
  • Categories of personal data
  • Categories of data subjects
  • Recipients
  • Retention period
  • Transfer countries and safeguards
  • Security measures
  • Status and next review date

The example library

Start from processing you'll recognise.

14 worked examples cover activities that recur across organisations, from payroll to CCTV. Each arrives as a draft with a plausible legal basis, data categories, recipients, and retention period already argued through. Each one is a starting point: every template stays in draft until someone who knows your processing has corrected it and signed it off.

  • Employee payroll
  • Recruitment
  • CCTV
  • Marketing emails
  • Customer support
  • Website analytics
  • Supplier management
  • Endpoint security
  • CRM
  • Employee HR files
  • Health & safety
  • Expenses
  • Access control
  • IT helpdesk

Review discipline

Sign-off that can't be quietly forged.

Every entry moves through an explicit lifecycle - draft, complete, needs review - and the database itself enforces the transitions. Only a role with review authority can mark an entry complete; doing so records who signed it off and schedules the next review a year out. The same change attempted with a raw API call is refused.

Who can do what

Access follows the role, in the app and at the database layer:

  • Admin · full control
  • Privacy officer · full control
  • Security analyst · edit
  • Auditor · read only
  • Helpdesk · no access

Reviews that come back

Each signed-off entry carries a next review date, and the compliance dashboard surfaces how many entries need review and how long until the next one is due. A register that is never re-read is just a spreadsheet with better formatting.

Connected to DSARs

The register your DSAR responses actually use.

This is what makes the register worth keeping. When a subject access request produces matches, the relevant signed-off processing activities are pulled into the Article 15 response document to supply the purposes and the legal bases, and the data subject portal presents the same processing activities alongside the disclosure. Only entries marked complete are eligible: sign-off is the gate between an internal draft and a statement made to a data subject.

Article 15 responses

The response document takes its purposes and legal bases straight from the register.

Data subject portal

The portal's processing activities section cites the same register the response was built from.

One source of truth

Update the register once and every downstream response reflects it. No parallel spreadsheet to reconcile.

Evidence pack

Hand over a pack the recipient can verify.

One click produces a ZIP containing the full register, your controller details, and a cover sheet, together with a manifest of SHA-256 hashes and an RSA signature over the lot. The recipient can verify that nothing in the pack was altered after export.

  • The full register as CSV and JSON
  • Your controller details and a cover-sheet PDF
  • A manifest recording a SHA-256 hash for every file
  • An RSA signature over the manifest, with the signing key identified
  • A download link that expires after an hour

Honesty and ownership

Your team authors the record.

EmberHound doesn't write your register for you, and it doesn't derive entries from a scan: a scan can't tell you your legal basis or your retention period. What the platform provides is the structure, the worked examples, the review discipline, and the connection to real requests. The judgements stay with your team, and so does the data.

  • No AI-generated or scan-derived entries. Every record is authored and signed off by your team.
  • Your register is isolated to your organisation, and access follows your roles, enforced in the database.
  • Export everything, any time, in open formats. The signed pack is yours to keep and verify.

Frequently asked questions

No, and be wary of anything that claims to. It gives you the register, every Article 30(1) field, 14 worked examples to adapt, and a review lifecycle. A scan can't tell you your legal basis or your retention period, so your team authors the entries and signs them off.

Only roles with review authority: admins and privacy officers. Sign-off records who reviewed the entry and schedules the next review. The database enforces the restriction, so calling the API directly can't bypass it.

If the request produces matches, the relevant signed-off processing activities are pulled into the Article 15 response document to supply the purposes and legal bases, and the data subject portal shows the same activities alongside the disclosure. Draft entries are never used.

The full register as CSV and JSON, your controller details, and a cover-sheet PDF, plus a manifest of SHA-256 hashes and an RSA signature so the recipient can verify nothing was altered after export. The download link expires after an hour.

Most controllers do. Article 30(5) contains a narrow exemption for some organisations under 250 employees, but it falls away where processing is regular, risky, or involves special category data, which in practice covers most organisations processing personal data at any scale. The ICO's documentation guidance is the authority on where the line sits - our ROPA guide links to it.

No. It gives you a maintained, reviewable register and audit-ready evidence that the record exists and is kept current. Compliance is a judgement your organisation makes, with advice where it needs it.

New to Article 30? Read the ROPA guide.

Put your register to work.

Tell us where your record of processing stands today, and we'll take you through how the workspace handles it.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy