Universal ROPA™
Overview
Relyance automatically generates customizable and continuously updated records of processing activities (ROPAs) that materially conform to the published requirements of data protection authorities in various jurisdictions.
The contents of the automated ROPAs are based on information discovered by Relyance’s four key integrations: infrastructure, source code, contract, and vendor integrations.
ROPAs are required of certain businesses to maintain comprehensive documentation of the overall processing activities involving data subjects’ personal information. However, because ROPAs also provide visibility into data management capabilities and practices, organizations can benefit by keeping records of processing activities, not only to demonstrate compliance, but also to identify privacy risks and data insights.
Data on the Universal ROPA tab represents both your 'contractual reality' and 'operational reality'.

Universal ROPA™
This section of the Universal ROPA™ combines information found in both the Contract Analysis tab (if available) and the Data Flow Analysis tab.
The majority of the ROPA content can be manually edited by a user to ensure an accurate and complete ROPA. To manually edit information as required, edit buttons can be found in the top right corner of the “Universal ROPA” sub-tab. The ROPA page includes a comprehensive audit log, located at the bottom of the page, that tracks and summarizes all changes. See this article on Editing your ROPA.

| Relyance provides ROPAs for your Vendors, Partners, and Services. Depending on the entity type, different fields will be presented. Please refer to the legend for purposes of this documentation: Vendors Partners Services | |
|---|---|
| Vendors | |
| Partners | |
| Services |




Personal Data Types
Relyance scans your contracts for personal data types using a Relyance-built list of keywords relating to all personal data types under GDPR.

Special Categories of Personal Data
Relyance scans your contracts for personal data types using a Relyance-built list of keywords relating to all personal data types that fall into special categories of data under GDPR.

Other Data Types
Other Data Types are custom data types added to the Data Classification settings. Please see the Data Classification article for more info.

User Generated Content
This field provides a prediction if this third party entity processes User Generated Content.

Nature and Purpose of Processing from DPA
Relyance scans your contracts as part of the contract integration, and extracts the nature and purpose of processing from the documents ingested.

Basis of Data Transfers
Data transfer is an intentional sending of personal data to another party or making the data accessible by it, where neither sender nor recipient is a data subject. Under GDPR and other data protection regimes, cross-border data transfer to third countries is permissible only if such transfer relies on a limited number of mechanisms that ensure that the transfer to third countries does not lessen the level of personal data protection.
Relyance scans your contracts as part of the contract integration and extracts what transfer mechanism the contract relies on: Privacy Shield, Standard Contractual Clauses (and if so, which version), and/or Binding Corporate Rules. In the event that the basis of transfer mechanism is out of date or invalid (e.g. Privacy Shield or old versions of Standard Contractual Clauses), Relyance will proactively surface an Intelligent Insight as an alert.

Data Retention Period
Relyance scans your vendor contracts as part of the contract integration, and extracts the Data Retention Period.

Location of Data Processing
Relyance scans your contracts as part of the contract integration, and extracts the Location of Data processing.

Security Measures
Relyance scans your contracts as part of the contract integration, and extracts any Security Measures outlining how a data controller’s personal data is protected. Please see the Security Measures article for a list of security measures and their descriptions.

Processing Activities
Provides a list of all identified Processing Activities.

Processing Names and Descriptions can be found in this help center article.
Processing Activity Descriptions
This item provides the descriptions for each of the identified processing activities.

Processing Activities
This section expands on the processing description, offering a deeper understanding of the activity's purpose, foundation, recipients, and associated data subjects.

| Purpose of Processing | The purpose signifies the intent or objective behind an activity, process, or object. |
|---|---|
| Basis of Processing | The basis of processing refers to the legitimate and legally justifiable reason for collecting, using, storing, or sharing personal data in accordance with data protection regulations. |
| Condition for Process Special Categories | The condition for processing special categories of personal data involves obtaining explicit consent from the data subject or meeting specific legal requirements that allow for processing such sensitive information. |
| Data Recipient Categories | Data recipient categories refer to the distinct groups of individuals or organizations that may receive or access personal data during the course of processing activities. |
| Data Subject Categories | Data subject categories pertain to the classifications of individuals whose personal data is being collected, processed, or stored, based on their roles or relationships with the data controller. |
Subprocessors
This section of the Universal ROPA™ tab shows any identified Subproccessors.

Contract with Data Processor(s) / Controller(s)
This section includes relevant documents found in your Contract repository and/or any uploaded documents for this vendor. Found only in the Vendor Universal ROPA™.

Audit Log
The audit log serves as a comprehensive record, documenting every modification made to a third-party entity or service, manually or automatically, including all user adjustments to the Universal ROPA.

Contract Excerpts
Relyance enhances the user experience by automatically extracting important contract details and presenting them clearly in the Universal ROPA using tooltips.

This allows users to easily verify the source of the information taken from the ingested documents. This feature embodies our "trust but verify" principle, providing users with both confidence and transparency.