Skip to content

Privacy (GDPR)

Keel gives you two GDPR privacy tools: a Records of Processing Activities (RoPA) register and a DPIA threshold screener. Both live under Controls & risk in the sidebar.

Your RoPA is the GDPR Article 30 register — a record of each activity where you process personal data. Each record captures the Article 30(1) fields:

  • Purpose and lawful basis
  • Data subjects and data categories
  • Recipients
  • Retention
  • International transfers and safeguards
  • Security measures

Records are marked Active or Archived, and owners/admins can add, edit, or remove them.

Use Auto-populate starter records to add the processing activities most companies run — HR, recruitment, customer accounts, billing, marketing, support, and website analytics — each pre-filled with sensible placeholder values. It only adds activities not already in your register and is safe to run more than once. These are generic starting points: review every record against how your business actually handles personal data before relying on it.

The screener answers “does this processing need a Data Protection Impact Assessment?” Tick what applies to the activity and the result updates live. It weighs two things:

  • Mandatory cases — GDPR Article 35(3). The three cases where a DPIA is always legally required (systematic, extensive automated evaluation with legal or similar effects; large-scale special-category or criminal-offence data; large-scale systematic monitoring of a publicly accessible area). Any one makes a DPIA required.
  • EDPB criteria — WP248. The nine EDPB criteria. Meeting two or more means a DPIA is required in most cases; meeting exactly one returns recommended; none returns not indicated on these criteria.

The screener is an aid, not legal advice, and it doesn’t save anything — record your screening decision (and check your supervisory authority’s own mandatory and exempt DPIA lists) either way.