Privacy (GDPR)
Keel gives you two GDPR privacy tools: a Records of Processing Activities (RoPA) register and a DPIA threshold screener. Both live under Controls & risk in the sidebar.
Records of Processing Activities (RoPA)
Section titled “Records of Processing Activities (RoPA)”Your RoPA is the GDPR Article 30 register — a record of each activity where you process personal data. Each record captures the Article 30(1) fields:
- Purpose and lawful basis
- Data subjects and data categories
- Recipients
- Retention
- International transfers and safeguards
- Security measures
Records are marked Active or Archived, and owners/admins can add, edit, or remove them.
Auto-populate then adapt
Section titled “Auto-populate then adapt”Use Auto-populate starter records to add the processing activities most companies run — HR, recruitment, customer accounts, billing, marketing, support, and website analytics — each pre-filled with sensible placeholder values. It only adds activities not already in your register and is safe to run more than once. These are generic starting points: review every record against how your business actually handles personal data before relying on it.
DPIA threshold screener
Section titled “DPIA threshold screener”The screener answers “does this processing need a Data Protection Impact Assessment?” Tick what applies to the activity and the result updates live. It weighs two things:
- Mandatory cases — GDPR Article 35(3). The three cases where a DPIA is always legally required (systematic, extensive automated evaluation with legal or similar effects; large-scale special-category or criminal-offence data; large-scale systematic monitoring of a publicly accessible area). Any one makes a DPIA required.
- EDPB criteria — WP248. The nine EDPB criteria. Meeting two or more means a DPIA is required in most cases; meeting exactly one returns recommended; none returns not indicated on these criteria.
The screener is an aid, not legal advice, and it doesn’t save anything — record your screening decision (and check your supervisory authority’s own mandatory and exempt DPIA lists) either way.
Next steps
Section titled “Next steps”- Frameworks & crosswalks: map privacy work to the frameworks you’re pursuing.
- Policies: the privacy and data-retention policies behind these records.