{"uid":"cap_9A60ixQQJ121dsHrKQ9oh","slug":"gdpr-article-30-1-record-of-processing-activities-generator-5d075e23","name":"GDPR Article 30(1) Record of Processing Activities Generator","description":"Takes an inventory — the controller, and one entry per processing activity with its purposes, the stated legal basis, the categories of data subjects and of personal data, the categories of recipients, any third-country transfers, the erasure periods and the security measures — and returns it laid out as a draft record of processing activities under Article 30(1) GDPR.","url":"https://buero.halowerk.com/v1/processing-record","method":"POST","headers":{},"bodySchema":null,"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.004","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"registry","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.004/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ruJNis9yYQq2KW8sNn6Jw","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.004","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Generates a draft Record of Processing Activities (RoPA) under GDPR Article 30(1) from structured inventory inputs including controller details, processing purposes, legal bases, data categories, recipients, transfers, retention periods, and security measures.","exampleAgentPrompt":"Generate a draft GDPR Article 30(1) record of processing activities for Acme GmbH as controller. We have two processing activities: (1) 'Customer CRM' — purpose: contract fulfilment, legal basis: Article 6(1)(b), data subjects: customers, personal data: name/email/purchase history, recipients: Salesforce (US, SCCs in place), erasure period: 7 years, security: encryption at rest; (2) 'Employee Payroll' — purpose: payroll, legal basis: Article 6(1)(c), data subjects: employees, personal data: name/IBAN/salary, recipients: DATEV (Germany), no third-country transfer, erasure period: 10 years, security: access control and audit logs.","exampleUseCases":[{"title":"SaaS startup GDPR compliance prep","prompt":"We're a Berlin-based SaaS startup called Loopify and need to produce our first GDPR Article 30(1) record. We have three processing activities: user authentication (legal basis Art 6(1)(b), data: email and hashed password, recipients: AWS Frankfurt, erasure: account deletion + 30 days), product analytics (legal basis Art 6(1)(f), data: pseudonymous usage events, recipients: Mixpanel US with SCCs, erasure: 2 years), and marketing emails (legal basis Art 6(1)(a), data: name and email, recipients: Mailchimp US with SCCs, erasure: until consent withdrawn). Can you draft the RoPA for us?"},{"title":"HR department annual DPA audit","prompt":"Our HR department needs to submit a record of processing activities to the company DPO before our annual audit. The controller is Müller AG. Processing activities are: recruitment (purpose: hiring, legal basis Art 6(1)(b), data subjects: applicants, data: CV/name/contact, recipients: internal HR only, no third-country transfer, erasure: 6 months after rejection, security: role-based access); and performance reviews (purpose: personnel management, legal basis Art 6(1)(b), data subjects: employees, data: ratings and comments, recipients: line managers, no transfer, erasure: 3 years, security: encrypted storage). Please generate the Article 30(1) draft."},{"title":"E-commerce shop third-country transfers doc","prompt":"I run an online shop called NordStyle and need a proper GDPR processing record because we use several US-based tools. Controller is NordStyle UG. One processing activity: order fulfilment — purpose: contract performance, legal basis Art 6(1)(b), data subjects: buyers, personal data: name/address/payment reference, recipients: Stripe (US, SCCs) and DHL (Germany), erasure: 10 years per commercial law, security: TLS and tokenised payment data. Can you draft the Article 30(1) record for this?"}],"resultDescription":"A structured draft Record of Processing Activities document formatted in accordance with GDPR Article 30(1), covering controller identity and all provided processing activity entries with their purposes, legal bases, data subject and personal data categories, recipient categories, third-country transfer safeguards, erasure/retention periods, and security measures — ready for review by a DPO or submission to a data protection authority.","failureModes":["Missing required controller information returns a validation error","Incomplete processing activity entries (e.g. missing legal basis) may result in partial or flagged output","Unsupported document format or malformed input causes a 400 error","Ambiguous or contradictory legal basis values may produce a generic placeholder in the output","Third-country transfer details without adequacy mechanism specified may generate a warning in the draft"],"whenToPreferThis":"Choose this endpoint when you need to produce a GDPR Article 30(1)-compliant draft Record of Processing Activities from a structured inventory of your processing activities. It is specifically designed for the Article 30(1) RoPA format — prefer it over generic document generators when you need legally-framed output covering all mandatory Article 30 fields. It sits alongside sibling endpoints on halowerk.com for contract analysis, meeting scheduling, and document summarisation, but this endpoint is the one to use exclusively for data protection compliance documentation.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:42:45.602Z","isFirstParty":false}