Free template · Updated May 2026

Record of Processing Activities (RoPA): Whistleblower Channel

A GDPR Article 30(1) record covering all six required elements, ready to paste into your master RoPA document. Pre-filled for the Confidly deployment defaults; edit the highlighted placeholders for your environment.

Identifier

Processing referenceWB-CHANNEL-01
Owner (business)Head of Compliance, [Organisation]
Owner (data protection)[DPO name]
Last reviewed[yyyy-mm-dd]
Next review[yyyy-mm-dd]

1. Controller (Art. 30(1)(a))

Controller[Organisation legal name]
Registered office[address]
Representative in the EU (if controller is non-EU)[name, address]
DPO[name, contact]

2. Purposes of processing (Art. 30(1)(b))

3. Categories of data subjects (Art. 30(1)(c))

4. Categories of personal data (Art. 30(1)(c))

Special categories (Article 9): only to the extent voluntarily included by reporters in report content or attachments. Not solicited; treated with additional safeguards.

5. Recipients (Art. 30(1)(d))

6. Third-country transfers (Art. 30(1)(e))

RecipientCountryTransfer mechanism
ClerkUSASCCs (Module Two) + EU-US Data Privacy Framework
AnthropicUSASCCs (Module Three) + Zero Data Retention contractual term

Documentation of the suitability of these transfers is held in the Transfer Impact Assessment file, dated [yyyy-mm-dd].

7. Retention periods (Art. 30(1)(f))

DataRetentionReason
Case content and attachmentsPer case type per jurisdiction; default 3 years from closure (DE), case duration + 3 years (FR), 5 years (IT, ANAC interpretation), 10 years where criminal proceedings (ES, IE recommended), per organisational retention schedule otherwiseArt. 18 Directive 2019/1937 + national transposition
Audit log entries7 yearsArt. 18 demonstrability
Authentication logs12 monthsLegitimate interest (security)
Backup copies30 days rollingDisaster recovery

8. Technical and organisational measures (Art. 30(1)(g))

9. Legal basis

Art. 6(1)(c) GDPR: compliance with the legal obligation imposed by [national transposition of Directive 2019/1937]. For special category data voluntarily disclosed, Art. 9(2)(b) GDPR (employment and social-protection law) combined with the national whistleblower act.


Maintained by [DPO name]. Reviewed annually. Made available to the supervisory authority on request per Art. 30(4) GDPR.

Use a channel whose architecture matches your RoPA

EU-hosted, role-based access, immutable audit log, documented sub-processor chain.

Multi-entity? Talk to us →