Compliance records (ROPA, DSAR, breaches)
The registers a supervisory authority asks for.
The Records area holds the three registers regulators expect. All members can add and update; only the account owner can delete.
ROPA — Records of Processing Activities (Art. 30)
The first document an authority asks for. List each activity with its purpose, lawful basis, data categories, and retention. If your sector ships starter records, use Import sector starter records to pre-fill a reviewed baseline you can edit.
DSAR — Data Subject Requests
Log access, erasure, and other requests. LexGate sets the one-month (Art. 12) deadline for you and flags anything overdue, and open requests appear in the reminder digest.
Data incidents (breach register)
Record any breach or near-miss. If notification is required, LexGate shows a 72-hour countdown (Art. 33) from discovery, and a one-click button marks when you told the authority.