The creation and maintenance of a Register of Processing Activities (ROPA) is an essential process for the demonstration of GDPR compliance. We analyse ROPA templates from six EU Data Protection Regulators and show that template scope and granularity vary widely between jurisdictions. We then propose a flexible, consolidated data model for consistent processing of ROPAs (CSM-ROPA). We analyse the extent that the Data Privacy Vocabulary (DPV) can be used to express CSM-ROPA. We find that it does not directly address modelling ROPAs, and so needs additional concept definitions. We provide a mapping of our CSM-ROPA to an extension of the Data Privacy Vocabulary.
翻译:建立和维持处理活动登记册(ROPA)是表明GDPR合规性的一个必要过程,我们分析了欧盟6个数据保护监管机构的ROPA模板,并表明模板范围和颗粒性在各法域之间差异很大,然后我们提出一个灵活、综合的数据模型,用于连贯一致地处理ROPA(CSM-ROPA),我们分析了数据隐私词汇(DPV)可用于表达CSM-ROPA的程度,我们发现它没有直接处理模拟ROPA的模板,因此需要更多的概念定义,我们提供了CSM-ROPA的地图,以扩展数据隐私词汇。