Skip to content

Privacy (GDPR)

Keel gives you two GDPR privacy tools: a Records of Processing Activities (RoPA) register and a DPIA threshold screener. Both live under Controls & risk in the sidebar.

Your RoPA is the GDPR Article 30 register, a record of each activity where you process personal data. Each record captures the Article 30(1) fields:

  • Purpose and lawful basis
  • Data subjects and data categories
  • Recipients
  • Retention
  • International transfers and safeguards
  • Security measures

Records are marked Active or Archived, and owners/admins can add, edit, or remove them.

Use Auto-populate starter records to add the processing activities most companies run (HR, recruitment, customer accounts, billing, marketing, support, and website analytics), each pre-filled with sensible placeholder values. It only adds activities not already in your register and is safe to run more than once. These are generic starting points: review every record against how your business actually handles personal data before relying on it.

The screener answers “does this processing need a Data Protection Impact Assessment?” Tick what applies to the activity and the result updates live. It weighs two things:

  • Mandatory cases, GDPR Article 35(3). The three cases where a DPIA is always legally required (systematic, extensive automated evaluation with legal or similar effects; large-scale special-category or criminal-offence data; large-scale systematic monitoring of a publicly accessible area). Any one makes a DPIA required.
  • EDPB criteria, WP248. The nine EDPB criteria. Meeting two or more means a DPIA is required in most cases; meeting exactly one returns recommended; none returns not indicated on these criteria.

The screener is an aid, not legal advice, and it doesn’t save anything, so record your screening decision (and check your supervisory authority’s own mandatory and exempt DPIA lists) either way.