Governance & Compliance · Data store

Records of Processing Register

Data storeGovernance & ComplianceSafety, Security & Governancearc:RecordsOfProcessingRegister

A register of processing activities recording, per purpose, the lawful basis, personal-data categories, originating and storing systems, processors, accessing roles and retention period.

Responsibility. Maintains the authoritative map of which personal data is processed where, by whom and why.

Also known as: Records of processing activities, RoPA, Data flow map, Data map

is audited byis read byis audited byCompliance Officer: is audited byCompliance OfficerErasure Orchestrator: is read byErasure OrchestratorData Protection Officer: is audited byData Protection Officer
Direct neighbourhood (hover for relationship types)

Relationships

is read by dependency

is audited by assurance

Design guidance

Classification

Patterns
Data flow mapping
Quality attributes
Transparency and accountability (NIST AI RMF: accountable and transparent)
Risks mitigated
Undocumented data flowsIncomplete erasure across systems
Frameworks & regulations
GDPR Art. 30GDPR Art. 6

Sources

  1. Ch9.7: T. Nguyen, "GDPR and Data Protection Regulations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.7. ISBN: 9798244538229.
  2. Ref9.05: "Privacy and Data Protection for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/05-Privacy-Data-Protection.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note