DPMS step by step
This page answers where to start and in which order the building blocks stack up. The subject-matter detail lives on the linked pages.
The order at a glance
Section titled “The order at a glance”1. Create partners2. Store agreements with the partner3. Create the register (RoPA)4. Record processing activities5. Assign legal basis, agreements and TOMs6. Handle data breaches (ongoing operation)Steps 1 and 2 are not a mandatory beginning: technically you can start with the register directly. In practice the detour pays off: as soon as you want to assign an agreement to a processing activity, it has to exist already.
1. Create partners
Section titled “1. Create partners”DPMS → Partners → Create partner
Every company that processes data for you or for which you process data. Besides name and location, the contact details of their data protection officer belong here.
Watch the country. It co-determines whether a third country transfer needs documenting later.
→ Partners, agreements and responsibilities
2. Store agreements
Section titled “2. Store agreements”Partner → Agreements tab → Create agreement
A partner without an agreement has no effect. Pick the right agreement type (General, Joint controllership agreement or Data processing agreement) and upload the document.
The agreement type cannot be changed afterwards.
3. Create the register
Section titled “3. Create the register”DPMS → RoPA → Create RoPA
One register per area of responsibility, not per system. Typically one each for finance, marketing, HR.
Record name, short description, status, the organizational unit and the responsible data protection officer. Under controller information you add the details of your own company.
→ Scoping RoPAs and processing activities
4. Record processing activities
Section titled “4. Record processing activities”RoPA → Processing activities tab → Create
This is the step where most things go wrong. A processing activity describes what is done with data, not which data exists. “Payroll” is an activity, “employee bank account details” is not.
Per activity you record:
- Basic data: name, description, status, start date, retention period, department, responsible person
- Additional data: purposes of processing, categories of data subjects, data recipients, data source
- Data transfers: destination country, country code and justification, if data leaves the EU
- Data types: which personal data is concretely affected
Note: after creation the tabs next to Details only load once the attributes in the Details tab have fully loaded. Wait briefly, then the rest works.
5. Assign legal basis, agreements and TOMs
Section titled “5. Assign legal basis, agreements and TOMs”Now the activity becomes complete:
- Legal basis: Legal basis tab → Assign. Pick the applicable Article 6 (a) to (f) GDPR and describe how you concretely fulfil that basis. As long as nothing is assigned, the notice about the documentation duty stays in the tab permanently.
- Agreements: Agreements tab. Assign the agreement that covers this specific processing.
- TOMs: TOMs tab. Either Assign from the library or Create your own measure directly. The shipped TOMs from GDPR and the Standard Data Protection Model are read-only; your own extend them in the same library.
6. Handle data breaches
Section titled “6. Handle data breaches”From here it is ongoing operation. You do not create a data breach yourself: it originates from an incident in the incident management system that was classified as a data breach in the incident assessment.
The data protection officer picks it up under DPMS → Data breaches via Assign incident, links it to a processing activity, assesses the risk and documents the notification of the supervisory authority. The 72-hour deadline from Detected on is calculated automatically.
→ From security incident to data breach
How the parts connect
Section titled “How the parts connect”Partner ──► Agreement ──┐ ├──► Processing activity ──► Legal basis (Art. 6)RoPA ───────────────────┘ │ └─► TOMs │Incident ──► Data breach ─────────────┘The register only bundles the processing activities. The actual work (legal basis, agreements, measures, breaches) happens throughout at the level of the processing activity.
What you handle outside the application
Section titled “What you handle outside the application”So the planning holds up: some steps are not covered by the module today.
- Art. 30 export of the register: no DPMS report available
- Data protection impact assessment: no guided process in the module
- Notification of the supervisory authority: documented, not sent
- Notification of data subjects: documented, not sent
A full overview is under Current limits of the module on Data Protection Management.