Styr
Data Governance for AI

The record of processing: derived, not maintained

Article 30 registers die of staleness — a spreadsheet written for the last audit, wrong by the next one. Fronterio takes a different bet: for AI processing, the fortegnelse is DERIVED at read time from registers you keep for other reasons. It cannot go stale, because it is never stored.

Derived live

AI entries assemble at read time — never a stored copy to rot

Art 30(1)

Purpose, subjects, categories, recipients, transfers, retention, measures

Zero double-entry

You document only what the platform cannot know

One register to maintain, one record to export

Every governed AI agent is a processing activity: its purpose is on the agent record, its recipients are the vendor chain in the AI Vendor Register, its third-country transfers and safeguards are the register's transfer mechanisms, and its technical measures are the guardrails and routing rules already governing it.

The ROPA assembler joins those sources into Article 30(1) entries at request time. Nothing is copied; nothing can drift. When you sign a DPA in the vendor register or add a routing rule, the record reflects it on the next read — and the PDF you export tomorrow is built from tomorrow's registers.

What a platform cannot know — retention periods, categories of data subjects — you document once via per-entry overrides. Non-AI activities (payroll, CRM) join as manual entries so the export is your complete fortegnelse, not just the AI half.

The record is honest by construction: a vendor without a signed DPA, a transfer without a Chapter V mechanism or an undocumented purpose renders as an explicit gap line. Your DPO sees what's missing before the supervisory authority asks.

Spreadsheet ROPA vs. derived ROPA

Without derivation

  • The register is a spreadsheet updated the week before an audit — and wrong the week after
  • Every AI system change means remembering to update a second document
  • Transfers and processors are copied by hand and drift from the contracts
  • Gaps hide: an empty cell looks the same as a documented 'none'

With derivation

  • AI entries assemble live from the governance registry, vendor register, routing policy and DPIAs
  • Change the source register once — the record follows automatically
  • Recipients and transfer mechanisms come from the same register your DPO already reviews
  • Every gap is an explicit line: missing DPA, undocumented transfer, unknown retention

What the derived record gives your privacy team

Entries per AI activity

One Article 30(1) entry per governed agent — purpose, data categories, recipients, transfers, retention and measures, assembled from the estate.

Per-entry overrides

Document retention periods and data-subject categories once; the override merges into the derived entry and survives every re-derivation.

Manual entries

Payroll, CRM, HR — non-AI activities join the same record so the export is the complete fortegnelse.

Explicit gap lines

Missing DPAs, undocumented Chapter V mechanisms and underived fields render as named gaps — the record never over-claims.

DPIA cross-links

Entries link their Article 35 DPIA automatically, preferring the completed assessment over drafts.

The one-click export

A controller identity block plus every entry and its gaps, as a branded PDF — rebuilt from the live registers at the moment you click.

How the record comes together

1

Govern your agents

Each agent in the governance registry becomes a processing activity with its purpose and department.

2

Keep the vendor register

Linked models bring their vendor chains, residency, DPA status and transfer mechanisms into each entry.

3

Fill the true gaps

Add retention periods and data subjects via overrides; add non-AI activities as manual entries.

4

Export on demand

The Article 30 PDF is derived from the live registers every time — hand it to your DPO or the authority.

Our old ROPA was a spreadsheet nobody trusted. Now the AI half maintains itself — we only write down the two things the platform genuinely can't know.

Available from Pro

The Article 30 record of processing is included in every paid plan.

ProBusinessEnterprise

Stop maintaining a second register

Document your AI estate once — and let the fortegnelse derive itself from it.

GDPR Art 30 record of processing — derived from your AI estate | Fronterio | Fronterio