From datenschutzrecht
Provides an English-language RoPA controller template per GDPR Article 30(1) with checklist, legal framework, and column guidance for cross-border data protection compliance.
How this skill is triggered — by the user, by Claude, or both
Slash command
/datenschutzrecht:ropa-en-controller-templateThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
This skill provides a ready-to-use English-language template for the Records of Processing Activities (RoPA) of a controller pursuant to Article 30(1) GDPR. It is intended for German law firms, in-house counsel, and data protection officers who need to provide a RoPA in English to international clients, US group entities, or supervisory authorities in cross-border investigations.
This skill provides a ready-to-use English-language template for the Records of Processing Activities (RoPA) of a controller pursuant to Article 30(1) GDPR. It is intended for German law firms, in-house counsel, and data protection officers who need to provide a RoPA in English to international clients, US group entities, or supervisory authorities in cross-border investigations.
Article 30(1) GDPR requires the controller to maintain a record containing:
a) the name and contact details of the controller and, where applicable, the joint controller, the controller's representative, and the Data Protection Officer; b) the purposes of the processing; c) a description of the categories of data subjects and of the categories of personal data; d) the categories of recipients to whom the personal data have been or will be disclosed, including recipients in third countries or international organisations; e) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards; f) where possible, the envisaged time limits for erasure of the different categories of data; g) where possible, a general description of the technical and organisational measures referred to in Article 32(1) GDPR.
Article 30(3) requires written or electronic form; Article 30(4) makes the RoPA available to the supervisory authority on request; Article 30(5) provides a narrow SME exemption that rarely applies in practice.
Controller: [Company / Firm Name]
Address: [...]
Representative (Art. 27): [if applicable]
Data Protection Officer: [Name, contact]
Supervisory Authority: [competent DPA]
Created: [date]
Last amended: [date]
Version: [v1.0]
| No. | Processing activity | Purpose | Legal basis | Categories of data subjects | Categories of personal data | Categories of recipients | Third country / safeguards | Retention period | TOM reference |
|---|---|---|---|---|---|---|---|---|---|
| 1 | HR administration | Establishment, performance, and termination of employment | Art. 6(1)(b) GDPR; Sec. 26 BDSG | Employees, applicants | Master data, contract data, payroll, sick leave | Social security, tax authority, payroll provider | none | 10 years after termination (Sec. 257 HGB, Sec. 147 AO); applicants 6 months | TOM Annex 1, 3, 5 |
| 2 | Client matter administration | Engagement, performance, and billing of legal services | Art. 6(1)(b) and (f) GDPR; Sec. 50 BRAO | Clients, opposing parties, witnesses | Master data, correspondence, briefs, fee data | Courts, authorities, opposing counsel, insurers | none | 6 years after end of mandate (Sec. 50(1) BRAO); tax-relevant documents 10 years | TOM Annex 1, 2, 4, 6 |
| 3 | Website contact form | Responding to inquiries | Art. 6(1)(b) or (f) GDPR | Prospective clients | Name, email, phone, message | Hosting provider (DPA in place) | none | 6 months after closure | TOM Annex 1, 5 |
| 4 | CRM sales | Customer relationship, business development | Art. 6(1)(b) and (f) GDPR | Existing customers, prospects | Master data, contact history, revenue data | CRM SaaS provider (USA) | USA – EU-US Data Privacy Framework (active listing on file, see DPF Annex) | 3 years after last contact | TOM Annex 1, 2, 5 |
Version 1.0 – Initial draft – [date, author]
Version 1.1 – [change] – [date, author]
ropa-art-30-dsgvo-grundlagen for the German-language framework.ropa-en-processor-template for the processor counterpart.ropa-konzernumlauf-und-multi-entity for multi-entity groups.dpa-en-template-controller-processor for English DPA templates.tia-en-template-full for the English Transfer Impact Assessment template.npx claudepluginhub klotzkette/claude-fuer-deutsches-recht --plugin datenschutzrechtGenerates a GDPR Art. 30(2) processor RoPA template with cover sheet, controller table, third-country transfer safeguards, TOM references, and a deadline/risk traffic light.
Generates GDPR Article 30(1) RoPA for data controllers with all 7 mandatory fields including Python automation script. Useful for compliance, processing records, data mapping.
Generates and maintains the Brazilian LGPD ROPA (Registro de Operações de Tratamento de Dados Pessoais) by consolidating data mapping and legal basis into the ANPD template. Used for ANPD inspection readiness or vendor due diligence.