Certus
← All services

RoPA & Data Mapping

A living Record of Processing Activities that reflects what your systems actually do with personal data.

What it is

The discovery and documentation of every processing activity, data flow, system and third party that touches personal data across your organisation — captured as a maintained Record of Processing Activities, not a one-time spreadsheet.

Why it matters

You cannot protect, respond to requests about, or report a breach involving data you cannot locate. Most RoPAs are built once for an audit and are wrong within six months. Without a living map, every other privacy control is built on sand.

What Certus does
  • Run structured discovery workshops with every business function that touches personal data.
  • Map systems, data flows, cross-border transfers and retention periods against PDPL requirements.
  • Classify data sensitivity and identify the systems holding your highest-risk data.
  • Build the governance process that keeps the RoPA current as systems and vendors change.
What you receive
  • A complete, PDPL-aligned Record of Processing Activities
  • A visual data flow map across systems, vendors and cross-border transfers
  • A data sensitivity classification model
  • An ownership model that keeps the RoPA accurate after we leave
Typical timeline

4–8 weeks depending on organisational complexity and number of systems.

Who this is for

DPOs, CISOs and IT leaders who need an accurate, current answer to "what personal data do we actually hold, and where."

How this differs from a generic consultancy

We build the maintenance process alongside the map itself, so it does not become shelfware the moment the project ends.