gdpr-ropa-dpa-enlisted
Install: claude install-skill matematicsolutions/awesome-matematic-skills-en
# GDPR RoPA + DPA EN - records of processing (Art. 30) and processor contracts (Art. 28)
## Philosophy
A RoPA is a living accountability document and a processor contract is a list of mandatory clauses -
both can be checked mechanically against the article. The skill drafts/redlines; signing and filing
are human acts.
## Part 1 - Records of processing (Art. 30)
**Controller (Art. 30(1))** - mandatory fields per activity:
- name and contact details of controller / joint controller / DPO,
- purposes of the processing,
- categories of data subjects and categories of personal data,
- categories of recipients (incl. in third countries),
- transfers to third countries + safeguards (Chapter V),
- envisaged erasure time limits per category,
- general description of technical and organisational security measures (Art. 32).
**Processor (Art. 30(2))** - narrower: categories of processing per controller, transfers + safeguards,
description of measures.
The skill validates completeness (a missing field is a gap, not a guess) and flags activities needing a
DPIA => [[gdpr-dpia-en]]. The Art. 30(5) exemption (<250 persons) is narrow - rarely applies in practice.
## Part 2 - Processor contract review (Art. 28(3))
The contract MUST bind the processor to:
- **(a)** process **only on the controller's documented instructions** (incl. transfers),
- **(b)** ensure **confidentiality** of authorised persons,
- **(c)** apply **security** measures (Art. 32),
- **(d)** respect the conditions for