Template · June 17, 2026
ROPA template for data processing under the PDPL
PDPL ROPA template: required fields, how SMEs use it, and a prefilled example.
Edit & copy
This is a reference template. Consult a legal advisor before using in production.
Quick answer
What is the data processing activities register template?
A data processing activities register template is an internal table used to list personal data processing activities in the business, from collection, storage, use, and sharing to deletion. Under the PDPL, this is a foundational document to demonstrate you manage data systematically, especially when there are inspections, incident handling, or compliance reviews.
What fields should the data processing activities register template include?
You should record at least the following fields so the ROPA is usable in practice, not just “for show”.
| Field to record | Content to fill in | Why it's needed | |
|---|---|---|---|
| Name of processing activity | Example: order intake, timekeeping, recruitment | Clearly define the processing scope | |
| Responsible unit/department | Sales, HR, Customer Support, IT | Know who is accountable | |
| Processing purpose | Delivery, customer care, payroll | Tie to a lawful purpose under the rules | |
| Data types | Full name, phone number, email, Citizen ID, bank account | Assess risk level | |
| Data subjects | Customers, employees, candidates | Know whose data it is | |
| Collection sources | Web form, Zalo, contract, camera | Support transparency and traceability | |
| Legal basis/consent | Consent, contract, legal obligation... | Reduce the risk of lacking a basis | |
| Recipients/data sharing | Delivery provider, cloud, accounting | Control data transfers | |
| Where stored | Google Workspace, on-prem server, CRM | Manage data locations | |
| Retention period | 12 months, 5 years, per accounting law... | Avoid keeping data too long | |
| Safeguards | Access control, MFA, encryption, logs | Demonstrate security | |
| Deletion/anonymization on expiry | Soft delete, hard delete, anonymize | Close the data lifecycle | |
| Person responsible for updates | Name, department, update date | Maintain accuracy |
How to prefill the data processing activities register template?
Below is a practical template for SMEs; you can copy it into Excel/Google Sheets or Notion.
Create one row for each processing activity:
For example, separate “recruitment”, “sales”, “timekeeping”, “customer support” rather than combining them.
State the purpose and data types clearly:
Don’t write generic phrases like “for business”; specify which data is used for what.
Identify data recipients:
If using third parties such as a CRM, email marketing, cloud, or a delivery provider, specify them.
Set retention periods:
Record according to internal policy or related legal obligations; upon expiry, delete/anonymize.
Review regularly:
Update when switching vendors, adding tracking tools, changing HR processes, or opening new sales channels.
Minimum ROPA table
| No. | Processing activity | Responsible department | Purpose | Data types | Data subjects | Collection sources | Recipients/shares | Where stored | Retention period | Protection measures | Updated by | Update date |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Recruitment | HR | Screen candidates, interview, sign employment contracts | Full name, phone number, email, CV, Citizen ID, bank account | Candidates | Recruitment form, email, LinkedIn | ATS provider, email, e-signature service | Google Workspace, ATS | 6–12 months if not hired; per personnel file if hired | HR access control, MFA, limited storage | HR Manager | 08/2025 |
| 2 | Online sales | Sales/Customer Support | Process orders, deliver, post-sale support | Full name, phone number, address, purchase history | Customers | Website, hotline, Zalo | Carrier, payment gateway, CRM | CRM, order files | According to internal policy | Encryption, access control, access logs | Ops Lead | 08/2025 |
| 3 | Timekeeping | HR/IT | Manage working hours, payroll calculation | Full name, employee ID, attendance data | Employees | Time clock device, app | Timekeeping software provider | On-prem server/SaaS | Per employment record retention period | Access control, backup, audit log | HR Admin | 08/2025 |
How should the data processing activities register be used within a business?
For SMEs, the ROPA should be a living file, not a one-off document left on the shelf. Legal/HR/IT/ops owners should update it when changes occur, such as adding analytics tools, running ads lead forms, using a chatbot, moving data to a new cloud, or engaging external vendors.
A practical example: if the company uses Google Forms to receive candidate information, then pushes it to an ATS and sends automated emails, you should note each data touchpoint. If there are cookies/SDKs tracking behavior on the website, record the collection activity, data types, and recipients as required; do not unilaterally conclude a tracker is “illegal”—you need to check the purpose, notice, and appropriate consent mechanisms.
How is the data processing activities register related to PDPL compliance?
Yes. The ROPA helps the business see the full data lifecycle, thereby addressing obligations such as transparency notices, consent management, controlling data sharing, and reacting to incidents. Under the Personal Data Protection Law (Law 91/2025/QH15), serious violations may be subject to criminal handling; specific penalty levels will be set out in the Government’s guiding decree, and the enforcement authority is the Ministry of Public Security (A05).
If a data violation occurs, the business must notify within 72 hours from discovery, so having an up-to-date ROPA will help you trace quickly: which data was affected, which systems hold it, who received the data, and who needs to be notified.
FAQ about the data processing activities register template
- Under the PDPL, businesses should have a ROPA to manage processing activities and demonstrate compliance. The level of detail varies by business model and operations; consult a lawyer if your data systems are complex.
- SMEs can start with Excel/Google Sheets if processes are still simple. When data grows, there are many systems, or several departments update it, move to software to facilitate access control, change tracking, and reporting.
- Yes. If a third party accesses or processes personal data on your behalf, list the provider name, purpose of sharing, storage location/region, and safeguards as required.
- It may leave the business unable to demonstrate compliance when inspected or when incidents occur. This is also a real risk because data changes continuously, especially when adding trackers, chatbots, a CRM, or new vendors.
If you need a ROPA template with prebuilt columns for a cookie banner, consent evidence logging, and DSAR, consent.vn can help you standardize it to your internal process.
Source: the Personal Data Protection Law (Law 91/2025/QH15) and Decree 13/2023/ND-CP on thuvienphapluat.vn; enforcement agency A05/Ministry of Public Security at bocongan.gov.vn
Access the full template library — no account needed.
Need more PDPL templates?