Governance & Compliance · Data store
Records of Processing Register
Data storeGovernance & ComplianceSafety, Security & Governancearc:RecordsOfProcessingRegister
A register of processing activities recording, per purpose, the lawful basis, personal-data categories, originating and storing systems, processors, accessing roles and retention period.
Responsibility. Maintains the authoritative map of which personal data is processed where, by whom and why.
Also known as: Records of processing activities, RoPA, Data flow map, Data map
Relationships
is read by dependency
is audited by assurance
Design guidance
- MUST document a lawful basis for every processing purpose before processing begins.
- SHOULD be updated when new systems, processors, data sources or retention changes are introduced (quarterly compliance reviews).
Classification
- Patterns
- Data flow mapping
- Quality attributes
- Transparency and accountability (NIST AI RMF: accountable and transparent)
- Risks mitigated
- Undocumented data flowsIncomplete erasure across systems
- Frameworks & regulations
- GDPR Art. 30GDPR Art. 6
Sources
- Ch9.7: T. Nguyen, "GDPR and Data Protection Regulations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.7. ISBN: 9798244538229.
- Ref9.05: "Privacy and Data Protection for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/05-Privacy-Data-Protection.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note