Regixo docs
For the compliance team·Step 4 of 6 — Fill the RoPA·see the whole journey ↗

Fill the RoPA — the legal calls

The data work is done: Regixo mapped your systems and filled in the mechanical facts. What remains are the judgments only a person can make — a lawful basis for each activity, retention, and the sensitive-data grounds. This page walks you through every one of them, activity by activity, so you finish with a record you can sign. Regixo suggests a starting point for each; here you learn how to decide whether the suggestion is right, and confirm it.

Land here from: Claim & review (you've opened the record and signed in). Not sure the record is trustworthy yet? Is it safe to sign? If you are not in the EU / not required to keep a RoPA, you can skip this whole section.

Optional · EU compliance module You need this only if your company must keep a GDPR Article 30 RoPA or a DORA register — it is an optional module on top of the free data catalog. If that is not you, you can skip this section.

Walk one activity all the way through (the worked example)

Before the reference, do one activity end to end so the loop is concrete. Regixo grouped your accounts and customers tables into an activity it named Manage customer accounts, and pre-filled its suggestions. Here is each of the seven steps for it:

StepWhat Regixo suggestsHow you decide, and what you do
1 · OpenFound: Name, Email, Date of birth, Financial (card/IBAN). No badge.Read it. These are the real columns Regixo saw. No special-category flag, so step 5 won't apply here.
2 · Purpose“Create and run customer accounts and subscriptions so people can use your product or service.” suggestedAsk: is that actually why you hold this data? Yes → confirm it. If your wording is more precise (“operate paid subscriptions and billing”), type that instead. Purpose must be a real sentence, never just the activity's name.
3 · Lawful basisArt. 6(1)(b) contract suggestedAsk the decision walk (§ below): do you need this data to deliver the service the person signed up for? You can't run their account without it → yes → 6(1)(b) contract is right → confirm. (If you only mailed them because they opted in, it'd be consent; if a law forced you to keep it, legal obligation.)
4 · Retentionneeds you (or a suggested default)Tie it to a reason: “while the account is open, then [your statutory minimum] after closure”. Type a concrete period — never “as long as necessary”.
5 · Art. 9No here.Skip. (Had it carried health/biometric/etc. data, you'd add the Art. 9(2) ground — step covered below.)
6 · Eng. factsData subjects: Customers suggested. Recipients / security: from “Your part”.Review what the engineer answered. Recipients blank? That's a gap — email the engineer, don't invent it.
7 · ConfirmAs approver, tick Confirm as legally reviewed on each call. The activity's needs you badges clear. Move to the next activity.

Every activity in your record is that same seven-step loop. The reference below is what you use inside step 3, 4 and 5 to make each call with confidence.

The one rule that governs this page Regixo never sets a legal field to “confirmed” on its own. Purpose, lawful basis, retention and transfers are legal judgments — the tool suggests and sanity-checks; a named human confirms. A confirmation must carry the name of the person who made it (REGIXO_SIGNER_EMAIL; without it you get SIGNER_REQUIRED), and a confirmed answer that names nobody is refused outright — ROPA_CONFIRM_UNATTRIBUTED — even on import. No agent may confirm on your behalf: the read-only MCP server has no tool that could, and no agent sentence is offered for the command that does.

Who already answered — the provenance on each field

You are not filling a blank form. Every field on the claim arrives in one of a few states, and its badge tells you which — so you always know whether a value is a measured fact, a starting point, or a decision a person already made:

BadgeWhat it meansWho put it there
found · auto-filledMeasured from the scanned metadata — the data categories, the transfers read from source regions.Regixo, from the map. Mechanical; not yours to type.
suggestedA starting point Regixo proposes from a recognised table-name pattern — a likely purpose, a likely lawful basis. Never a decision.Regixo. You confirm or replace it.
providedA value a person typed but has not confirmed — including the engineer’s three facts (security measures, recipients, data subjects), answered once as “Your part” on their free record and travelling with the draft.A person — the engineer, or a preparer on your team.
confirmedA legal call a named person has reviewed and stands behind, recorded with who confirmed it and when.An approver on your team. Only a person reaches this state.

The engineering side may still owe you the three facts it answers — security measures, recipients and data subjects. Usually they arrive provided; where one is blank it reaches you as a gap whose only fix is an email back to the engineer. You review theirs, you do not invent them. The legal calls — purpose, lawful basis, retention, transfers — are yours alone.

Do not guess a value to clear a gap A record is defensible because it is true, not because it is full. If you do not know a retention period, or which systems receive a copy, find out — ask the engineer, read the contract — rather than filling in something plausible. A confirmed field is a statement a named person stands behind in front of a regulator; a plausible guess sealed as confirmed is worse than a flagged gap, not better.
Why two “blank” counts don’t match You’ll see the outstanding work counted two ways, and both are right. Per field — “10 legal calls still blank” — counts every open field across every activity; it sizes the job. Per activity — “4 activities need you” — counts how many activities have at least one open field; it tells you where to look. One activity with three open fields is three of the first count and one of the second.

The fields you fill

Each processing activity has these fields. The mechanical ones (data categories, role, the transfers suggestion) are already filled from the map; three are facts the engineering side answers (“Your part” on their free record); the rest are yours.

FieldWhat it isStarts as
PurposeWhy you process this data.needs you (a suggestion if the table name is recognisable)
Lawful basisYour Article 6(1) ground.needs you / a suggestion
RetentionHow long you keep it.needs you / a suggestion
Art. 9(2) groundExtra ground for special-category data — only shown if present.needs you
Art. 10 conditionCondition for criminal-offence data — only if present.needs you
Transfers outside the EUWhether data leaves the EU.auto-suggested from the source region
Recipients · Data subjectsWho receives it; whose data it is.usually answered by the engineer (“Your part” on their free record) — you review; needs you if left blank
Security measuresHow it’s protected.never auto-filled by Regixo — the engineer answers it (“Your part”); you review; needs you if left blank
Controller · DP contactYour organisation and its data-protection contact (Art. 30(1)(a)).from regixo.yml or the claim form

Step 2 · Purpose

Purpose is the one-sentence why you hold this data (Article 30(1)(b)). Regixo suggests one from the activity's tables; you confirm it if it's true, or rewrite it. Two rules: it must be a real sentence, never the activity's name restated ("customer accounts" is not a purpose), and it must be specific — "operate customer accounts and billing", not "business purposes". If Regixo left it blank, write it yourself. To decide: finish the sentence "We hold this data in order to …" — that is your purpose.

Step 3 · Lawful basis (Article 6(1)) — the decision walk

Every activity needs exactly one Article 6(1) ground. Regixo suggests a starting point; to decide whether it's right (or pick one where it left the field blank), ask these five questions in order and stop at the first “yes”:

Ask, in order…If yes →Because / examples
1. Does a law require you to hold this data?Art. 6(1)(c) legal obligationTax law, anti-money-laundering (KYC), employment law. invoices, KYC/AML, payroll.
2. Do you need it to deliver what the person signed up for — could you not provide the service without it?Art. 6(1)(b) contractYou can't run the account or fulfil the order without it. customer accounts, orders, subscriptions.
3. Are you doing it only because the person opted in, and would stop if they withdrew?Art. 6(1)(a) consentYou must be able to show consent and let them withdraw. marketing emails, newsletters.
4. Is it a genuine business need a reasonable person would expect, that doesn't override their rights?Art. 6(1)(f) legitimate interestsYou must record a balancing test (see below). security logs, fraud prevention.
5. (rare) Someone's life is at stake / a public-interest task?6(1)(d) vital interests · 6(1)(e) public taskEmergencies; public bodies and delegated tasks.

Two activities can share a basis; one activity has exactly one. If two questions both feel like “yes”, pick the one that is the primary reason you hold the data. Regixo's suggestion follows this same logic from your table names — this walk is how you confirm it.

The full six grounds, exactly as Regixo labels them
GroundIn plain EnglishTypically fits
Art. 6(1)(a) consentThe person agreed to it.Marketing, newsletters, optional cookies.
Art. 6(1)(b) contractYou need it to deliver what they signed up for.Customer accounts, orders, subscriptions.
Art. 6(1)(c) legal obligationA law requires you to hold it.Invoices, tax records, payroll.
Art. 6(1)(d) vital interestsSomeone’s life depends on it.Rare — emergency/medical situations.
Art. 6(1)(e) public taskYou act in the public interest / official authority.Public bodies and delegated tasks.
Art. 6(1)(f) legitimate interestsA genuine business reason that doesn’t override the person’s rights.Fraud prevention, security logs, network operation.
Guidance, not legal advice The “typically fits” column and Regixo’s per-activity suggestions are a starting point to help you think it through — not a decision, and not legal advice. The right basis depends on your specific facts, and a named person on your team makes the call and signs. Where Regixo isn’t confident it marks the field needs you rather than guess.

How Regixo suggests one

Regixo reads the activity’s table names and offers a starting suggestion when it recognises a pattern. It’s a transparent heuristic, not a legal engine:

If the tables look like…Suggested starting point
user, account, customer, profile, subscriptionArt. 6(1)(b) contract
invoice, payment, charge, billing, orderArt. 6(1)(c) legal obligation / 6(1)(b) contract
employee, payroll, hr, staffArt. 6(1)(c) legal obligation / 6(1)(b) contract
log, audit, event, sessionArt. 6(1)(f) legitimate interests
marketing, campaign, newsletter, subscriberArt. 6(1)(a) consent
patient, health, medical, clinicala care-provision basis — and an Art. 9 ground (below)
Choosing (f) legitimate interests — the balancing test

Legitimate interests is flexible but comes with homework: you must be able to show you weighed your interest against the person’s rights and freedoms (a “balancing test”), and that a reasonable person would expect the processing. Record that reasoning alongside the field, where an auditor will find it — regixo annotate set <activityKey> lawfulBasis "Art. 6(1)(f) legitimate interests" --confirm --why "<your balancing test, in a line>". If the data is sensitive or the person wouldn’t expect it, another basis is usually safer.

Step 5 · Special category — Article 9(2)

Some data is extra-sensitive: health, ethnicity, religion, political opinions, trade-union membership, biometrics, sexual orientation. When Regixo detects it (its own Art. 9 badge), the activity needs a second ground under Article 9(2) in addition to your Article 6 basis. The ten grounds, exactly as Regixo lists them:

9(2)(a)explicit consent9(2)(f)legal claims
9(2)(b)employment & social-security law9(2)(g)substantial public interest
9(2)(c)vital interests9(2)(h)health or social care
9(2)(d)not-for-profit body9(2)(i)public health
9(2)(e)made public by the data subject9(2)(j)archiving, research or statistics

The Art. 9 ground is a separate field from the lawful basis, so your Article 6 basis stays a clean single choice.

Criminal-offence data — Article 10

Data about criminal convictions or offences (its own Art. 10 class, never an Art. 9 ground) may only be processed under official authority or where authorised by Union or Member-State law. Regixo asks you to confirm that condition — it never proposes an Art. 9 ground for it.

If you do KYC / AML — this one won’t prompt you Sanctions, PEP and adverse-media screening pulls in criminal-offence data (Article 10). But KYC often lands in “Uncategorised processing”, so the classifier sees nothing sensitive by column name and shows no Art. 10 field to prompt you — you have to add it yourself. The condition to record for AML screening: it is authorised by Union or Member-State law (your anti-money-laundering obligations). Add it to your KYC/AML activity even though the screen didn’t ask.

Two machine claims to check before you rely on them

The Art. 9 badge and the activity grouping are the classifier’s guesses — it reads column names and types only. Sanity-check two things against what you know before you fill on top of them:

Step 4 · Retention

How long you keep the data, and why. Regixo suggests a common default when the activity is recognisable — you confirm or replace it:

No recognisable pattern → the field is needs you. Set a concrete period tied to a reason, not “as long as necessary”.

Step 6 · The engineer’s three facts (+ transfers)

Transfers outside the EU
Auto-suggested from each source’s region — “None identified” when every source is in the EU, or “Yes — a source is hosted outside the EU” otherwise. Confirm or correct it, and note the safeguard (e.g. Standard Contractual Clauses) if data does leave.
Recipients
Who the data is disclosed to (processors, authorities). Regixo suggests the destination systems it can trace from cross-system lineage; you confirm those and add the rest. Enter categories, comma-separated.
Data subjects
Whose data it is — customers, employees, patients. Categories, not names.
Security measures
How the data is protected. Never auto-filled — describe your controls, or set them once in your organisation profile so they apply across activities.

Step 7 · Fill & confirm — exactly where to click

Filling and confirming happen on the claimed record. Read it signed out and every open legal call is already visible:

That last line is a label, not a button. The one way in is the Sign in to fill card in the rail; once you are signed in, each open row carries its own + Fill this editor, opened in place.

One activity, read signed out — Recipients and Security measures are still open, Retention was confirmed by a person, and the record names who:

what you'll see — the claimed record, signed out: the rail's “Sign in to fill” card, and one activity whose open calls read “needs you” beside “A preparer can fill this” (a static picture, not a live app)
Regixo compliance portal · EU-hosted Have edits to make? Sign in

GDPR · Art. 30 · Record of Processing — drafted from your own systems

Record of Processing Activities

DRAFT
1 / 4

Manage customer accounts

2 open calls

accounts · customers

⚠ Needs you: confirm the legal fields (purpose, lawful basis, retention); add who you share this data with (recipients) — none could be detected from the schema.
PurposeCreate and run customer accounts and subscriptions so people can use your product or service. suggested A preparer can edit this
Personal dataFinancial (card/IBAN), Identifier, Date of birth, Email, Name found
Data subjectsCustomers suggested A preparer can edit this
Recipients— none detected from your schema; add who you share this with needs youA preparer can fill this
Lawful basisYou need it to provide your product or service. Art. 6(1)(b) contract suggested A preparer can edit this
Retention5 years after account closure (AML) confirmed A preparer can edit this · confirmed by dana@acme.example, 10 Jul 2026
Transfers outside the EUNone identified from source regions suggested A preparer can edit this
Security measuresDescribe them — or set once in your org profile needs youA preparer can fill this

Here is a legal-basis row mid-fill — the inline editor open on the lawful-basis call, with the approver's confirm checkbox:

what you'll see — the compliance portal · fill a legal field (signed in, as an approver) — a signed-in state; not reproducible from a signed-out capture
Regixo compliance portal · EU-hosted
DK dana@acme.eu
Activity detail & gaps — Manage customer accounts
PurposeOperate and support customer accounts found
Personal dataname, email, postal address found
Data subjectsCustomers found
Lawful basis — no lawful basis recorded yet needs you
+ Fill this
Retention— none recorded needs you+ Fill this
A person confirms legal fields — not Regixo. Purpose, lawful basis and retention are legal judgments; Regixo suggests and sanity-checks, your approver confirms and signs.

Three fields usually arrive already answered: security measures, recipients and data subjects are facts about the systems, not legal calls, so the engineer answers them once on their own free Record page (“Your part”) and the answers travel with the record. Review and adjust them on the claim page like any other value. One left blank reaches you as a gap — and the only way to close it is an email back to the engineer. The legal calls — purpose, lawful basis, retention, transfers — remain yours alone.

Where each surface lands — and the honest limit of each:

▤ In the portal

On the claimed record, fill each call where you see it, step by step:

  1. Open the activity and read its detail table. Auto-filled facts carry a found badge; open legal calls carry needs you.
  2. On a blank row press + Fill this; a row already filled shows ✎ edit instead.
  3. Pick or type the value. Lawful basis is a picker — — pick an Art. 6(1) basis — lists all six, with a free-text …or type the basis in your own words underneath; special-category data adds — pick an Art. 9(2) ground — (all ten).
  4. Press Save. A preparer’s value saves as provided by you — a starting point to confirm, never a confirmation.
  5. An approver ticks Confirm as legally reviewed — your act as approver; Regixo never confirms a legal field for you. to confirm it, or presses Revert to Regixo’s suggestion. Confirming records who confirmed it and when.

The Schedule — open items on this record index lists every open field, so you always know what is left. A tour: the compliance portal tour.

The free local record (regixo open) lets the engineer answer their own three fields on Your part — security measures, recipients, data subjects. The legal calls (purpose, lawful basis, retention, transfers) are filled and confirmed on the forwarded claim portal, or from the terminal with regixo annotate.

$ At the terminal
run
$ regixo annotate set <activityKey> lawfulBasis "Art. 6(1)(b) contract" --confirm

This one’s yours. Only a person can confirm a legal field.

Confirming needs a signer identity (REGIXO_SIGNER_EMAIL); without it the command refuses with SIGNER_REQUIRED and saves nothing. Detail below.

✦ A connected assistant

A different surface. An assistant registered against the read-only regixo mcp server reads the RoPA DRAFT (get_compliance_state) — which legal fields are still suggested, and which need you. Neither agent surface can confirm a legal field: no read tool exists to do it, and no sentence is offered for the command that does.

Two ways to make the calls, depending on who you are:

In the portal (the compliance team)

Open each activity on your claimed record, choose the field’s value, and confirm. Roles apply: a preparer fills the fields; an approver confirms and signs. A confirmed field records who confirmed it and when.

From your project (the engineer, optional)

An engineer can pre-fill or confirm legal fields from the terminal with regixo annotate. Confirming requires a signer identity, so the record knows who made the call:

run
$ export REGIXO_SIGNER_EMAIL=dpo@acme.example
$ regixo annotate set <activityKey> lawfulBasis "Art. 6(1)(b) contract" --confirm

This one’s yours. Only a person can confirm a legal field.

No anonymous confirmations Without --confirm the value saves as a draft fill, not a confirmation — attributed to engineer-cli when no signer is set. Ask for --confirm with no REGIXO_SIGNER_EMAIL and the command refuses with SIGNER_REQUIRED and writes nothing at all. And a confirmed legal answer that names no one who confirmed it is refused outright (ROPA_CONFIRM_UNATTRIBUTED), even on import. Confirmation is always a named human act.

Rebuild the draft files — regixo report

regixo report re-reads the catalog and rewrites the draft files on disk, stamped DRAFT. You rarely need it — everything that reads the catalog live is already current the moment you save: the portal at regixo open, and the record regixo invite sends. Both rebuild the draft on the spot.

The files on disk do not. regixo start and regixo watch write RoPA_DRAFT.json. The human-readable RoPA_DRAFT.html — the one you would actually email someone — is written in one place only: here.

say

“Rebuild my Regixo draft paperwork from the current map.”

Show the commandHide the commandShow the sentenceHide the sentence
run
$ regixo report
then

It re-reads the catalog and rewrites both files, stamped DRAFT. Add --dora (or set dora: true in regixo.yml) and it writes the DORA register draft too.

When you actually need it: only when you are handing someone the file. Fill a legal answer with regixo annotate, email RoPA_DRAFT.html without re-running this, and you sent a file that does not contain your answer — the CLI said “✓ Saved your answer”, and it had: to the catalog, not to that file. regixo invite rebuilds the record as it sends, so the question never arises.

Show what it prints in the terminalHide the terminal outputShow what your agent reportsHide what your agent reports
example output
RoPA DRAFT → ./RoPA_DRAFT.json (4 activities, stamped DRAFT)
auto-filled 14 fields · 10 need you · 0 special-category (Art. 9) · coverage 2/4 sources
read it: open RoPA_DRAFT.html
Honest about the suggestions The suggestion heuristic is a convenience, pending legal review — treat every suggestion as a prompt to think, never as Regixo choosing your basis. The signed record is exactly what a human confirmed.

How you know your RoPA is finished

Run the loop until all three of these are true — then, and only then, the record is ready to sign:

The record still says DRAFT — that is expected; it becomes OFFICIAL only when a named person signs it, which is the next step. Filling everything here does not sign anything.

REGIXO — documentation · machines suggest, humans sign · not legal advice · Glossary