Skip to main content
Records of Processing Activities under Art. 30 GDPR

ROPA software: records of processing that almost write themselves

With the ROPA software in preeco | data protection you create and maintain your records of processing activities under Art. 30 GDPR in a structured system instead of Excel: AI suggests purposes, data categories, legal bases, recipients and retention periods, existing records import as XLSX or DOCX, and every approval creates an immutable PDF revision. Hosted in ISO 27001-certified data centers in Germany – no third-country transfers.

Hosted in Germany
ISO 27001 data center
Import from Excel & Word
No third-country transfers
app.preeco.de

What is ROPA software?

ROPA software is a tool that lets organizations create, maintain and evidence their records of processing activities (ROPA) under Art. 30 GDPR digitally. Unlike Excel spreadsheets, it guides you through every mandatory field – purposes, data categories, data subjects, legal bases, recipients, third-country transfers and retention periods –, keeps the records versioned and links each processing activity to systems, technical and organizational measures (TOMs) and data processing agreements.

preeco | data protection is exactly that kind of ROPA software: the structured form shows AI suggestions for individual sections, legally reviewed templates provide the starting point, and existing records import from DOCX or XLSX – or you derive a new processing activity directly from a plain-language task description. Every approval automatically produces a PDF revision with a SHA-256 checksum, so your records can be evidenced to supervisory authorities and auditors at any time.

Why preeco

What sets the preeco ROPA software apart

The records of processing activities are the heart of every GDPR documentation – and the first task where Excel-based approaches break down. preeco | data protection takes the most tedious steps off your plate.

Book a demo

AI suggestions for every section

Purposes, data categories, legal bases, recipients and retention periods are suggested based on the type of processing. You confirm or adjust – no empty fields.

Import from Excel and Word

Existing records import as XLSX or DOCX. Alternatively, the AI derives a new processing activity from a simple task description.

Revisions with integrity proof

Every approval creates a PDF revision. Two versions can be compared with color-coded changes, and stored SHA-256 checksums reveal any subsequent modification.

Linked to systems, TOMs and DPAs

Each processing activity shows its systems, safeguards and data processing agreements – as a graphical relationship view instead of isolated spreadsheet tabs.

Multi-tenant for external DPOs

External data protection officers manage the records of all clients centrally in one system – connected documents inherit content for cross-client standards.

Legally reviewed templates in 25 languages

Numerous reviewed templates as a starting point, interface and documents in 25 languages – with optional DeepL translation for international group companies.

Keep your ROPA in Excel or in software?

Many organizations start their records of processing activities in Excel – and quickly hit the same limits: there is no versioning, so nobody can prove which version applied at which point in time. Mandatory fields under Art. 30 GDPR are missing because the spreadsheet does not enforce them. Links to systems, TOMs and data processing agreements exist only as free text. And as soon as several people or group companies are involved, competing file versions start circulating.

Switching does not mean starting over

Moving to preeco | data protection does not mean rewriting your records: existing Excel and Word records import as XLSX or DOCX, the AI maps the content to the structured fields, and you only fill in what is missing. From then on, the system does what Excel cannot:

  • Completeness: the form guides you through every mandatory field under Art. 30(1) GDPR – nothing gets forgotten.

  • Evidence: automatic PDF revisions on every approval, color-coded version comparison and SHA-256 integrity verification.

  • Context: processing activities, systems, TOMs and DPAs stay permanently linked instead of living in separate spreadsheet tabs.

  • Collaboration: tasks, comments, checklists and an activity log replace files circulating by email.

  • Reports: status reports, procedure files and the BayLDA questionnaire are generated at the push of a button, with exports as PDF and DOCX.

Customer voice

fischerwerke relies on preeco | data protection

Referenz

By using preeco | data protection, we were able to quickly achieve significantly better data quality while considerably increasing the efficiency with which the companies and departments of the fischer group collaborate on data protection.
fischerwerke GmbH & Co. KG

Jonathan Haist

IT Security Manager

fischerwerke GmbH & Co. KG

Developed and hosted in Germany

Development, operations and support in Germany – backed by independent certifications and association memberships.

ISO 27001 Zertifizierte Rechenzentren Software Made in Germany Cloud Services - Made in Germany Berufsverband der Datenschutzbeauftragten Deutschlands e.V. Bundesverband IT-Mittelstand e.V. 100% Ökostrom im Rechenzentrum

Book your 30-minute demo

Choose a convenient time slot

We will get back to you within a few hours.

Privacy
Please see our privacy policy.

What to expect in the demo

30 focused minutes, no slide deck marathon. We demonstrate the ROPA software on your own processing activities and answer your questions live.

  • Live creation of a processing activity with AI suggestions – no standard pitch
  • Import of an existing record from Excel or Word (XLSX/DOCX)
  • Revisions, version comparison and integrity verification in the real system
  • Honest answers from data protection experts on hosting, AI, migration and pricing
  • No obligation and no sales pressure – simply see whether preeco fits your needs

FAQ

Frequently asked questions about ROPA software

The records of processing activities are the central documentation of all processes in which an organization processes personal data – from HR administration and CRM to newsletters. Art. 30 GDPR prescribes what they must contain: purposes of processing, categories of data subjects and data, recipients, third-country transfers, retention periods and a description of the technical and organizational measures. It is the first document supervisory authorities request in an audit.

In principle every controller and processor. The exemption in Art. 30(5) GDPR for organizations with fewer than 250 employees only applies if processing is merely occasional, poses no risk to data subjects and involves no special categories of data – even routine payroll or customer administration fails these conditions. In practice, almost every organization therefore needs records of processing activities.

Yes. preeco | data protection imports existing records as XLSX or DOCX. The AI maps the content to the structured fields of the Art. 30 form; alternatively, a new processing activity can be derived from a plain-language task description. Switching from Excel does not mean starting over.

The AI suggests content for individual sections – purposes, data categories, data subjects, legal bases, recipients, third-country transfers and retention periods – and optionally supports threshold analysis and protection needs assessment. You confirm or adjust. AI features are optional and disabled by default: preeco uses an OpenAI-compatible interface, you choose your provider freely or self-host the model. The software is fully functional without AI.

Yes. Processing activities carried out on behalf of controllers (Art. 30(2) GDPR) are documented separately. In combination with contract management, the "contractual relationships" section shows the data recipients and the data processing agreements covering each processing activity.

At preeco, the records of processing activities are not an add-on module but a core part of preeco | data protection – together with data subject requests, data breaches, DPIA/TIA, DPAs, TOMs, deletion concept and training, with no hidden surcharges. Cloud instances are provisioned within 48 hours (on business days), with no setup fees and no notice periods. You receive an individual quote within 24 hours.

In ISO 27001-certified data centers operated by Hetzner Online GmbH in Germany (Nuremberg, Falkenstein), running on 100% green electricity – with no third-country transfers. Daily backups with off-site storage and a guaranteed availability of 99.0% per calendar month. Private cloud with your own domain and SSO (SAML2) as well as an on-premises installation are also available.

Every approved processing activity automatically produces a PDF revision – a fixed, historical state of your documentation. Two revisions can be compared with color-coded changes, and stored SHA-256 checksums prove integrity. Status reports, procedure files and the BayLDA questionnaire are generated at the push of a button, and records export as PDF or DOCX.

See the ROPA built on your own processing activities

In 30 minutes we show you how preeco | data protection makes your records under Art. 30 GDPR complete and audit-proof.