Skip to content

DPMS step by step

This page answers where to start and in which order the building blocks stack up. The subject-matter detail lives on the linked pages.


1. Create partners
2. Store agreements with the partner
3. Create the register (RoPA)
4. Record processing activities
5. Assign legal basis, agreements and TOMs
6. Handle data breaches (ongoing operation)

Steps 1 and 2 are not a mandatory beginning: technically you can start with the register directly. In practice the detour pays off: as soon as you want to assign an agreement to a processing activity, it has to exist already.


DPMS → Partners → Create partner

Every company that processes data for you or for which you process data. Besides name and location, the contact details of their data protection officer belong here.

Watch the country. It co-determines whether a third country transfer needs documenting later.

→ Partners, agreements and responsibilities

Partner → Agreements tab → Create agreement

A partner without an agreement has no effect. Pick the right agreement type (General, Joint controllership agreement or Data processing agreement) and upload the document.

The agreement type cannot be changed afterwards.

DPMS → RoPA → Create RoPA

One register per area of responsibility, not per system. Typically one each for finance, marketing, HR.

Record name, short description, status, the organizational unit and the responsible data protection officer. Under controller information you add the details of your own company.

→ Scoping RoPAs and processing activities

RoPA → Processing activities tab → Create

This is the step where most things go wrong. A processing activity describes what is done with data, not which data exists. “Payroll” is an activity, “employee bank account details” is not.

Per activity you record:

  • Basic data: name, description, status, start date, retention period, department, responsible person
  • Additional data: purposes of processing, categories of data subjects, data recipients, data source
  • Data transfers: destination country, country code and justification, if data leaves the EU
  • Data types: which personal data is concretely affected

Note: after creation the tabs next to Details only load once the attributes in the Details tab have fully loaded. Wait briefly, then the rest works.

Section titled “5. Assign legal basis, agreements and TOMs”

Now the activity becomes complete:

  • Legal basis: Legal basis tab → Assign. Pick the applicable Article 6 (a) to (f) GDPR and describe how you concretely fulfil that basis. As long as nothing is assigned, the notice about the documentation duty stays in the tab permanently.
  • Agreements: Agreements tab. Assign the agreement that covers this specific processing.
  • TOMs: TOMs tab. Either Assign from the library or Create your own measure directly. The shipped TOMs from GDPR and the Standard Data Protection Model are read-only; your own extend them in the same library.

From here it is ongoing operation. You do not create a data breach yourself: it originates from an incident in the incident management system that was classified as a data breach in the incident assessment.

The data protection officer picks it up under DPMS → Data breaches via Assign incident, links it to a processing activity, assesses the risk and documents the notification of the supervisory authority. The 72-hour deadline from Detected on is calculated automatically.

→ From security incident to data breach


Partner ──► Agreement ──┐
├──► Processing activity ──► Legal basis (Art. 6)
RoPA ───────────────────┘ │ └─► TOMs
│
Incident ──► Data breach ─────────────┘

The register only bundles the processing activities. The actual work (legal basis, agreements, measures, breaches) happens throughout at the level of the processing activity.


So the planning holds up: some steps are not covered by the module today.

  • Art. 30 export of the register: no DPMS report available
  • Data protection impact assessment: no guided process in the module
  • Notification of the supervisory authority: documented, not sent
  • Notification of data subjects: documented, not sent

A full overview is under Current limits of the module on Data Protection Management.