From datenschutzrecht
Generates a GDPR Art. 30(2) processor RoPA template with cover sheet, controller table, third-country transfer safeguards, TOM references, and a deadline/risk traffic light.
How this skill is triggered — by the user, by Claude, or both
Slash command
/datenschutzrecht:ropa-en-processor-templateThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
This skill provides a ready-to-use English-language template for the Records of Processing Activities of a processor pursuant to Article 30(2) GDPR. Unlike the controller record, only four mandatory contents apply. Intended for cloud providers, IT outsourcing companies, payroll bureaus, hosting providers, printing services, external DPOs, and law firms acting in a processor role.
This skill provides a ready-to-use English-language template for the Records of Processing Activities of a processor pursuant to Article 30(2) GDPR. Unlike the controller record, only four mandatory contents apply. Intended for cloud providers, IT outsourcing companies, payroll bureaus, hosting providers, printing services, external DPOs, and law firms acting in a processor role.
Article 30(2) GDPR requires each processor and, where applicable, the processor's representative, to maintain a record containing:
a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's representative, and the Data Protection Officer; b) the categories of processing carried out on behalf of each controller; c) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards; d) where possible, a general description of the technical and organisational measures referred to in Article 32(1) GDPR.
One row per controller. Multiple processing categories can be grouped where TOMs are identical.
Processor: [Company name]
Address: [...]
Representative (Art. 27): [if applicable]
Data Protection Officer: [Name, contact]
Created: [date]
Last amended: [date]
Version: [v1.0]
| No. | Controller | Categories of processing | Third country / safeguards | TOM reference |
|---|---|---|---|---|
| 1 | [Client A GmbH] | Hosting of accounting software, backups, patch management | none | TOM Annex A |
| 2 | [Client B AG] | Payroll processing, wage tax filings, social security filings | none | TOM Annex A |
| 3 | [Client C KG] | Email hosting, spam filtering | USA – sub-processor (SCCs + TIA in Annex B) | TOM Annex A |
| 4 | [Client D e.V.] | Membership administration, direct debit collection | none | TOM Annex A |
| Sub-processor | Location | Service | Transfer tool |
|---|---|---|---|
| [Hyperscaler Cloud] | USA | Infrastructure as a Service | EU-US DPF (active listing on file in Annex B) |
| [Email filter service] | Ireland | Spam filtering | EU/EEA – no transfer safeguards required |
| [Backup provider] | Germany | Offsite backup | EU/EEA – no transfer safeguards required |
Version 1.0 – Initial draft – [date, author]
Version 1.1 – [change] – [date, author]
ropa-art-30-dsgvo-grundlagen for the German framework.ropa-en-controller-template for the controller counterpart.dpa-en-template-controller-processor for English DPA template.dpa-en-tom-annex-template for the TOM annex.tia-en-template-full for the English Transfer Impact Assessment.npx claudepluginhub klotzkette/claude-fuer-deutsches-recht --plugin datenschutzrechtProvides an English-language RoPA controller template per GDPR Article 30(1) with checklist, legal framework, and column guidance for cross-border data protection compliance.
Creates GDPR Article 30(2) Records of Processing Activities for data processors, covering processor/controller details, processing categories, third-country transfers, and security measures.
Generates and maintains the Brazilian LGPD ROPA (Registro de Operações de Tratamento de Dados Pessoais) by consolidating data mapping and legal basis into the ANPD template. Used for ANPD inspection readiness or vendor due diligence.