The data work is done: Regixo mapped your systems and filled in the mechanical facts.
What remains are the judgments only a person can make — a lawful basis for each activity, retention,
and the sensitive-data grounds. This page walks you through every one of them, activity by
activity, so you finish with a record you can sign. Regixo suggests a starting point for each;
here you learn how to decide whether the suggestion is right, and confirm it.
Land here from:Claim & review (you've
opened the record and signed in). Not sure the record is trustworthy yet? Is
it safe to sign? If you are not in the EU / not required to keep a RoPA, you can skip this whole
section.
Your whole job on this page, in order
It is one loop: go through your activities one at a time, and for each make and confirm its
legal calls. When no activity shows needs you any more, your record is
ready to sign. For each activity, in this order:
Open it and read what Regixo found (facts) and suggested (starting points).
Purpose — confirm or rewrite the one-sentence “why”. (how ↓)
Then move to the next activity. The rest of this page is that loop, walked in full — with a worked
example first, then the decision reference for each field, then exactly where to click.
Optional · EU compliance module
You need this only if your company must keep a GDPR Article 30 RoPA or a DORA register — it is an optional module on top of the free data catalog. If that is not you, you can skip this section.
Walk one activity all the way through (the worked example)
Before the reference, do one activity end to end so the loop is concrete. Regixo grouped your
accounts and customers tables into an activity it named Manage customer
accounts, and pre-filled its suggestions. Here is each of the seven steps for it:
Step
What Regixo suggests
How you decide, and what you do
1 · Open
Found: Name, Email, Date of birth, Financial (card/IBAN). No ⚠ badge.
Read it. These are the real columns Regixo saw. No special-category flag, so step 5 won't apply here.
2 · Purpose
“Create and run customer accounts and subscriptions so people can use your product or service.” suggested
Ask: is that actually why you hold this data? Yes → confirm it. If your wording is more precise (“operate paid subscriptions and billing”), type that instead. Purpose must be a real sentence, never just the activity's name.
3 · Lawful basis
Art. 6(1)(b) contract suggested
Ask the decision walk (§ below): do you need this data to deliver the service the person signed up for? You can't run their account without it → yes → 6(1)(b) contract is right → confirm. (If you only mailed them because they opted in, it'd be consent; if a law forced you to keep it, legal obligation.)
4 · Retention
needs you (or a suggested default)
Tie it to a reason: “while the account is open, then [your statutory minimum] after closure”. Type a concrete period — never “as long as necessary”.
5 · Art. 9
No ⚠ here.
Skip. (Had it carried health/biometric/etc. data, you'd add the Art. 9(2) ground — step covered below.)
6 · Eng. facts
Data subjects: Customers suggested. Recipients / security: from “Your part”.
Review what the engineer answered. Recipients blank? That's a gap — email the engineer, don't invent it.
7 · Confirm
—
As approver, tick Confirm as legally reviewed on each call. The activity's needs you badges clear. Move to the next activity.
Every activity in your record is that same seven-step loop. The reference below is what you use
inside step 3, 4 and 5 to make each call with confidence.
The one rule that governs this page
Regixo never sets a legal field to “confirmed” on its own. Purpose, lawful basis, retention
and transfers are legal judgments — the tool suggests and sanity-checks; a named human
confirms. A confirmation must carry the name of the person who made it
(REGIXO_SIGNER_EMAIL; without it you get SIGNER_REQUIRED), and a confirmed
answer that names nobody is refused outright — ROPA_CONFIRM_UNATTRIBUTED — even on
import. No agent may confirm on your behalf: the read-only MCP server has no tool that could, and no
agent sentence is offered for the command that does.
Who already answered — the provenance on each field
You are not filling a blank form. Every field on the claim arrives in one of a few states, and its
badge tells you which — so you always know whether a value is a measured fact, a starting point, or a
decision a person already made:
Badge
What it means
Who put it there
found · auto-filled
Measured from the scanned metadata — the data categories, the transfers read from source regions.
Regixo, from the map. Mechanical; not yours to type.
suggested
A starting point Regixo proposes from a recognised table-name pattern — a likely purpose, a likely lawful basis. Never a decision.
Regixo. You confirm or replace it.
provided
A value a person typed but has not confirmed — including the engineer’s three facts (security measures, recipients, data subjects), answered once as “Your part” on their free record and travelling with the draft.
A person — the engineer, or a preparer on your team.
confirmed
A legal call a named person has reviewed and stands behind, recorded with who confirmed it and when.
An approver on your team. Only a person reaches this state.
The engineering side may still owe you the three facts it answers — security measures,
recipients and data subjects. Usually they arrive provided;
where one is blank it reaches you as a gap whose only fix is an email back to the engineer. You review
theirs, you do not invent them. The legal calls — purpose, lawful basis, retention, transfers — are
yours alone.
Do not guess a value to clear a gap
A record is defensible because it is true, not because it is full. If you do not know a retention
period, or which systems receive a copy, find out — ask the engineer, read the contract — rather than
filling in something plausible. A confirmed field is a statement a named person stands behind in front
of a regulator; a plausible guess sealed as confirmed is worse than a flagged gap, not better.
Why two “blank” counts don’t match
You’ll see the outstanding work counted two ways, and both are right. Per field — “10 legal calls
still blank” — counts every open field across every activity; it sizes the job. Per activity —
“4 activities need you” — counts how many activities have at least one open field; it tells you where to
look. One activity with three open fields is three of the first count and one of the second.
The fields you fill
Each processing activity has these fields. The mechanical ones (data categories, role, the
transfers suggestion) are already filled from the map; three are facts the engineering side answers
(“Your part” on their free record); the rest are yours.
Field
What it is
Starts as
Purpose
Why you process this data.
needs you (a suggestion if the table name is recognisable)
Lawful basis
Your Article 6(1) ground.
needs you / a suggestion
Retention
How long you keep it.
needs you / a suggestion
Art. 9(2) ground
Extra ground for special-category data — only shown if present.
needs you
Art. 10 condition
Condition for criminal-offence data — only if present.
needs you
Transfers outside the EU
Whether data leaves the EU.
auto-suggested from the source region
Recipients · Data subjects
Who receives it; whose data it is.
usually answered by the engineer (“Your part” on their free record) — you review; needs you if left blank
Security measures
How it’s protected.
never auto-filled by Regixo — the engineer answers it (“Your part”); you review; needs you if left blank
Controller · DP contact
Your organisation and its data-protection contact (Art. 30(1)(a)).
from regixo.yml or the claim form
Step 2 · Purpose
Purpose is the one-sentence why you hold this data (Article 30(1)(b)). Regixo suggests one
from the activity's tables; you confirm it if it's true, or rewrite it. Two rules: it must be a
real sentence, never the activity's name restated ("customer accounts" is not a purpose), and
it must be specific — "operate customer accounts and billing", not "business purposes". If
Regixo left it blank, write it yourself. To decide: finish the sentence "We hold this data in
order to …" — that is your purpose.
Step 3 · Lawful basis (Article 6(1)) — the decision walk
Every activity needs exactly one Article 6(1) ground. Regixo suggests a starting point; to
decide whether it's right (or pick one where it left the field blank), ask these five questions in
order and stop at the first “yes”:
2. Do you need it to deliver what the person signed up for — could you not provide the service without it?
Art. 6(1)(b) contract
You can't run the account or fulfil the order without it. customer accounts, orders, subscriptions.
3. Are you doing it only because the person opted in, and would stop if they withdrew?
Art. 6(1)(a) consent
You must be able to show consent and let them withdraw. marketing emails, newsletters.
4. Is it a genuine business need a reasonable person would expect, that doesn't override their rights?
Art. 6(1)(f) legitimate interests
You must record a balancing test (see below). security logs, fraud prevention.
5. (rare) Someone's life is at stake / a public-interest task?
6(1)(d) vital interests · 6(1)(e) public task
Emergencies; public bodies and delegated tasks.
Two activities can share a basis; one activity has exactly one. If two questions
both feel like “yes”, pick the one that is the primary reason you hold the data. Regixo's
suggestion follows this same logic from your table names — this walk is how you confirm it.
The full six grounds, exactly as Regixo labels them
Ground
In plain English
Typically fits
Art. 6(1)(a) consent
The person agreed to it.
Marketing, newsletters, optional cookies.
Art. 6(1)(b) contract
You need it to deliver what they signed up for.
Customer accounts, orders, subscriptions.
Art. 6(1)(c) legal obligation
A law requires you to hold it.
Invoices, tax records, payroll.
Art. 6(1)(d) vital interests
Someone’s life depends on it.
Rare — emergency/medical situations.
Art. 6(1)(e) public task
You act in the public interest / official authority.
Public bodies and delegated tasks.
Art. 6(1)(f) legitimate interests
A genuine business reason that doesn’t override the person’s rights.
Guidance, not legal advice
The “typically fits” column and Regixo’s per-activity suggestions are a starting point to help you
think it through — not a decision, and not legal advice. The right basis depends on your specific
facts, and a named person on your team makes the call and signs. Where Regixo isn’t confident it marks
the field needs you rather than guess.
How Regixo suggests one
Regixo reads the activity’s table names and offers a starting suggestion when it recognises a
pattern. It’s a transparent heuristic, not a legal engine:
If the tables look like…
Suggested starting point
user, account, customer, profile, subscription
Art. 6(1)(b) contract
invoice, payment, charge, billing, order
Art. 6(1)(c) legal obligation / 6(1)(b) contract
employee, payroll, hr, staff
Art. 6(1)(c) legal obligation / 6(1)(b) contract
log, audit, event, session
Art. 6(1)(f) legitimate interests
marketing, campaign, newsletter, subscriber
Art. 6(1)(a) consent
patient, health, medical, clinical
a care-provision basis — and an Art. 9 ground (below)
Choosing (f) legitimate interests — the balancing test
Legitimate interests is flexible but comes with homework: you must be able to show you weighed
your interest against the person’s rights and freedoms (a “balancing test”), and that a
reasonable person would expect the processing. Record that reasoning alongside the field, where an
auditor will find it — regixo annotate set <activityKey> lawfulBasis "Art. 6(1)(f) legitimate interests"
--confirm --why "<your balancing test, in a line>". If the data is sensitive or the person
wouldn’t expect it, another basis is usually safer.
Step 5 · Special category — Article 9(2)
Some data is extra-sensitive: health, ethnicity, religion, political opinions, trade-union
membership, biometrics, sexual orientation. When Regixo detects it (its own Art. 9
badge), the activity needs a second ground under Article 9(2) in addition to your
Article 6 basis. The ten grounds, exactly as Regixo lists them:
9(2)(a)
explicit consent
9(2)(f)
legal claims
9(2)(b)
employment & social-security law
9(2)(g)
substantial public interest
9(2)(c)
vital interests
9(2)(h)
health or social care
9(2)(d)
not-for-profit body
9(2)(i)
public health
9(2)(e)
made public by the data subject
9(2)(j)
archiving, research or statistics
The Art. 9 ground is a separate field from the lawful basis, so your Article 6 basis
stays a clean single choice.
Criminal-offence data — Article 10
Data about criminal convictions or offences (its own Art. 10 class,
never an Art. 9 ground) may only be processed under official authority or where authorised by Union
or Member-State law. Regixo asks you to confirm that condition — it never proposes an Art. 9 ground
for it.
If you do KYC / AML — this one won’t prompt you
Sanctions, PEP and adverse-media screening pulls in criminal-offence data (Article 10). But KYC
often lands in “Uncategorised processing”, so the classifier sees nothing sensitive by column name and
shows no Art. 10 field to prompt you — you have to add it yourself. The condition to record for
AML screening: it is authorised by Union or Member-State law (your anti-money-laundering
obligations). Add it to your KYC/AML activity even though the screen didn’t ask.
Two machine claims to check before you rely on them
The Art. 9 badge and the activity grouping are the classifier’s
guesses — it reads column names and types only. Sanity-check two things against what you know before you
fill on top of them:
“0 special-category (Art. 9)” means no column name or type looked sensitive — not
that none is. A free-text notes field can carry health data behind a neutral name.
Independently verify any system you know handles sensitive data, and add the Art. 9(2) ground
yourself; the machine will not prompt you for what it could not see.
“Uncategorised processing” holds tables that matched no recognised activity pattern. Read
it — an activity the rules could not name is still one you may have to record. For a regulated firm it
is often KYC / AML checks, which rarely look like the common table names.
Step 4 · Retention
How long you keep the data, and why. Regixo suggests a common default when the activity is
recognisable — you confirm or replace it:
Billing / invoices → 7 years (statutory tax retention)
KYC / AML checks → 5 years after the business relationship ends (anti-money-laundering law; varies by member state)
Employee records → 6 years after leaving (varies by member state)
No recognisable pattern → the field is needs you. Set a
concrete period tied to a reason, not “as long as necessary”.
Step 6 · The engineer’s three facts (+ transfers)
Transfers outside the EU
Auto-suggested from each source’s region — “None identified”
when every source is in the EU, or “Yes — a source is hosted outside the EU” otherwise. Confirm or
correct it, and note the safeguard (e.g. Standard Contractual Clauses) if data does leave.
Recipients
Who the data is disclosed to (processors, authorities). Regixo suggests the
destination systems it can trace from cross-system lineage; you confirm those and add the rest. Enter
categories, comma-separated.
Data subjects
Whose data it is — customers, employees, patients. Categories, not names.
Security measures
How the data is protected. Never auto-filled — describe your controls,
or set them once in your organisation profile so they apply across activities.
Step 7 · Fill & confirm — exactly where to click
Filling and confirming happen on the claimed record. Read it signed out and every open legal call is
already visible:
the value slot holds a hint, not an answer
the badge reads needs you
a line beside it names who may act — A preparer can fill this
That last line is a label, not a button. The one way in is the Sign in to fill card in the rail;
once you are signed in, each open row carries its own + Fill this editor, opened in place.
One activity, read signed out — Recipients and Security measures are still open,
Retention was confirmed by a person, and the record names who:
what you'll see — the claimed record, signed out: the rail's “Sign in to fill” card, and one activity whose open calls read “needs you” beside “A preparer can fill this” (a static picture, not a live app)
Regixocompliance portal · EU-hostedHave edits to make? Sign in
Sign in to fill
Reviewing is free and needs no account. To fill in the legal fields or manage your team, sign in. Making the record official (sign & seal) is a separate, later step.
How your team works this record: a viewer reads · a preparer fills · an approver confirms & signs · an admin does all of that and manages the team.
GDPR · Art. 30 · Record of Processing — drafted from your own systems
Record of Processing Activities
DRAFT
1 / 4
Manage customer accounts
2 open calls
accounts · customers
⚠ Needs you: confirm the legal fields (purpose, lawful basis, retention); add who you share this data with (recipients) — none could be detected from the schema.
Purpose
Create and run customer accounts and subscriptions so people can use your product or service. suggestedA preparer can edit this
Personal data
Financial (card/IBAN), Identifier, Date of birth, Email, Name found
Data subjects
Customers suggestedA preparer can edit this
Recipients
— none detected from your schema; add who you share this withneeds youA preparer can fill this
Lawful basis
You need it to provide your product or service.Art. 6(1)(b) contractsuggestedA preparer can edit this
Retention
5 years after account closure (AML) confirmedA preparer can edit this· confirmed by dana@acme.example, 10 Jul 2026
Transfers outside the EU
None identified from source regions suggestedA preparer can edit this
Security measures
Describe them — or set once in your org profileneeds youA preparer can fill this
Here is a legal-basis row mid-fill — the inline editor open on the lawful-basis call, with the
approver's confirm checkbox:
what you'll see — the compliance portal · fill a legal field (signed in, as an approver) — a signed-in state; not reproducible from a signed-out capture
▲A person confirms legal fields — not Regixo. Purpose, lawful basis and retention are legal judgments; Regixo suggests and sanity-checks, your approver confirms and signs.
Three fields usually arrive already answered: security measures, recipients and
data subjects are facts about the systems, not legal calls, so the engineer answers them once
on their own free Record page (“Your part”) and the answers travel with the record. Review and adjust
them on the claim page like any other value. One left blank reaches you as a gap — and the only way to
close it is an email back to the engineer. The legal calls — purpose, lawful basis, retention,
transfers — remain yours alone.
Where each surface lands — and the honest limit of each:
▤ In the portal
On the claimed record, fill each call where you see it, step by step:
Open the activity and read its detail table. Auto-filled facts carry a
found badge; open legal calls carry
needs you.
On a blank row press + Fill this; a row already filled shows ✎ edit instead.
Pick or type the value. Lawful basis is a picker —
— pick an Art. 6(1) basis — lists all six, with a free-text
…or type the basis in your own words underneath; special-category data adds
— pick an Art. 9(2) ground — (all ten).
Press Save. A preparer’s value saves as
provided by you — a starting point to confirm, never a
confirmation.
An approver ticks Confirm as legally reviewed — your act as approver; Regixo
never confirms a legal field for you. to confirm it, or presses
Revert to Regixo’s suggestion. Confirming records who confirmed it and when.
The Schedule — open items on this record index lists every open field, so you always know what
is left. A tour: the compliance portal
tour.
The free local record (regixo open) lets the engineer answer
their own three fields on Your part — security measures, recipients, data subjects.
The legal calls (purpose, lawful basis, retention, transfers) are filled and confirmed on
the forwarded claim portal, or from the terminal with regixo annotate.
$ At the terminal
run
$ regixo annotate set <activityKey> lawfulBasis "Art. 6(1)(b) contract" --confirm
✋This one’s yours. Only a person can confirm a legal field.
Confirming needs a signer identity (REGIXO_SIGNER_EMAIL); without it the
command refuses with SIGNER_REQUIRED and saves nothing. Detail below.
✦ A connected assistant
A different surface. An assistant registered against the read-only
regixo mcp server reads the RoPA DRAFT (get_compliance_state) —
which legal fields are still suggested, and which need you. Neither agent surface can
confirm a legal field: no read tool exists to do it, and no sentence is offered for the command
that does.
Two ways to make the calls, depending on who you are:
In the portal (the compliance team)
Open each activity on your claimed record, choose the field’s value, and confirm. Roles apply: a
preparer fills the fields; an approver confirms and signs. A confirmed field records who
confirmed it and when.
From your project (the engineer, optional)
An engineer can pre-fill or confirm legal fields from the terminal with regixo annotate.
Confirming requires a signer identity, so the record knows who made the call:
✋This one’s yours. Only a person can confirm a legal field.
No anonymous confirmations
Without --confirm the value saves as a draft fill, not a confirmation — attributed to
engineer-cli when no signer is set. Ask for --confirm with no
REGIXO_SIGNER_EMAIL and the command refuses with SIGNER_REQUIRED and
writes nothing at all. And a confirmed legal answer
that names no one who confirmed it is refused outright (ROPA_CONFIRM_UNATTRIBUTED), even
on import. Confirmation is always a named human act.
Rebuild the draft files — regixo report
regixo report re-reads the catalog and rewrites the draft files on disk, stamped
DRAFT. You rarely need it — everything that reads the catalog live is already
current the moment you save: the portal at regixo open, and the record
regixo invite sends. Both rebuild the draft on the spot.
The files on disk do not.regixo start and regixo watch write
RoPA_DRAFT.json. The human-readable RoPA_DRAFT.html — the one you would
actually email someone — is written in one place only: here.
say
“Rebuild my Regixo draft paperwork from the current map.”
Show the commandHide the commandShow the sentenceHide the sentence
run
$ regixo report
then
It re-reads the catalog and rewrites both files, stamped DRAFT. Add
--dora (or set dora: true in regixo.yml) and it writes the
DORA register draft too.
When you actually need it: only when you are handing someone the
file. Fill a legal answer with regixo annotate, email
RoPA_DRAFT.html without re-running this, and you sent a file that does not contain
your answer — the CLI said “✓ Saved your answer”, and it had: to the catalog, not to that file.
regixo invite rebuilds the record as it sends, so the question never arises.
Show what it prints in the terminalHide the terminal outputShow what your agent reportsHide what your agent reports
example output
RoPA DRAFT → ./RoPA_DRAFT.json (4 activities, stamped DRAFT)
auto-filled 14 fields · 10 need you · 0 special-category (Art. 9) · coverage 2/4 sources
read it: open RoPA_DRAFT.html
Honest about the suggestions
The suggestion heuristic is a convenience, pending legal review — treat every suggestion as a prompt
to think, never as Regixo choosing your basis. The signed record is exactly what a human confirmed.
How you know your RoPA is finished
Run the loop until all three of these are true — then, and only then, the record is ready to sign:
No activity shows a needs you badge any more — every legal call
is filled and confirmed by a named approver.
The Schedule — open items on this record index is empty — it reads Awaiting confirmation, with nothing left blank.
You have sanity-checked the two machine claims (§ above): any system you
know handles sensitive data has an Art. 9(2) ground, and nothing important sits unread in
“Uncategorised processing”.
The record still says DRAFT — that is expected; it becomes OFFICIAL
only when a named person signs it, which is the next step. Filling everything here does not sign
anything.
Your next step
The RoPA’s legal calls are finished. If you are a regulated financial entity, one more register is
waiting: The DORA register → — the ICT-provider register, drafted from
the same map, filled the same way (its own decision walks). Not regulated? Skip ahead to
Unlock, sign & maintain to make this official.