Articles
GDPR, RoPA and DPIA: How to Stop Being Intimidated by Acronyms and Build an Effective Data Protection Framework
GDPR, RoPA and DPIA: How to Stop Being Intimidated by Acronyms and Build an Effective Data Protection Framework
Personal data is one of the key resources of modern business. It is used in virtually every area — from customer acquisition and CRM management to payroll administration and interactions with contractors.
However, as the value of data increases, so does a company’s responsibility for how that data is processed.
Every time a new lead is entered into a CRM system, HR receives a candidate’s CV, accounting processes employee information, or a marketing agency launches an email campaign, the company is processing personal data.
For a long time, many businesses treated data protection as a formality: publish a Privacy Policy on the website, obtain the user’s consent, and consider the matter closed.
In practice, this is not enough.
As of 23 August 2026, Moldova applies Law No. 195/2024 on Personal Data Protection, which introduces a modern and comprehensive approach to the processing and protection of personal data and reflects the principles of the European GDPR.
For businesses, this means understanding not only which documents are required, but also how personal data actually flows through the company.
Let us look at what RoPA and DPIA are and why they are becoming important tools for managing data protection risks.
RoPA: Mapping Personal Data Flows Within the Company
RoPA (Record of Processing Activities) is a register of personal data processing activities.
At first glance, it may appear to be simply a table listing the company’s databases. In reality, a RoPA helps a company systematically identify what data it processes, for what purposes, and within which business processes.
Consider an ordinary company that simultaneously uses:
- a CRM system;
- corporate email;
- accounting software;
- cloud storage;
- an HR management system;
- email marketing services;
- external marketing or IT contractors.
Personal data may be involved in each of these processes.
A RoPA brings this information together into a single structured framework and helps answer key questions:
- whose data does the company process;
- which categories of personal data are processed;
- for what purposes the data is processed;
- what the legal basis for the processing is;
- who has access to the data;
- to whom the data is disclosed or transferred;
- where the data is stored;
- how long the data should be retained;
- what measures are used to protect it.
A RoPA is therefore not merely a formal document prepared “for an inspection.” It is a practical tool that enables a business to see its personal data processing activities as a whole.
DPIA: Assessing Risks Before Launching a New Project
DPIA (Data Protection Impact Assessment) is an assessment of the impact that personal data processing may have on the rights and freedoms of individuals.
If a RoPA shows what happens to personal data within a company, a DPIA answers a different question:
What risks does a particular processing activity create for data subjects, and are the existing safeguards sufficient?
A DPIA becomes particularly relevant when implementing new technologies or processes that may create increased risks.
For example, a company may plan to use:
- automated customer profiling;
- large-scale monitoring systems;
- artificial intelligence technologies;
- large-scale processing of personal data;
- special categories of personal data;
- new methods of analysing data or making decisions based on personal data.
In such situations, it is important to assess the potential consequences before the processing activity is launched, rather than after a problem has already occurred.
A DPIA makes it possible to identify risks, assess their likelihood and potential impact, and establish measures capable of reducing those risks.
This is why a DPIA can be viewed as a kind of legal “crash test” for a new business process.
RoPA and DPIA Are Only Part of the System
Having a processing register and a completed risk assessment does not, by itself, mean that a company fully complies with data protection requirements.
Personal data protection should cover the entire lifecycle of information — from the moment it is collected until it is deleted.
1. Legal Basis for Processing
For each processing activity, the company must determine the legal basis on which it is entitled to process personal data.
Depending on the circumstances, this may include, for example, performance of a contract, compliance with a legal obligation, or another legal basis provided for by applicable legislation.
It is important not simply to select a legal basis from a list, but to ensure that it genuinely applies to the specific processing activity.
2. Informing Data Subjects
Individuals should understand who processes their personal data, why it is processed, what data is used, and what rights they have.
Therefore, the Privacy Policy and other privacy notices should reflect the company’s actual processing activities rather than exist separately from them.
3. Retention Periods
Personal data should not be retained indefinitely simply because it might be useful at some point in the future.
Retention periods should be established for different categories of data, taking into account the purposes of processing and applicable legal requirements. The company should also establish procedures for deleting or archiving data when appropriate.
4. Working with Contractors
CRM providers, marketing agencies, accounting firms, IT contractors and other service providers may have access to personal data.
In such cases, their roles, rights and obligations should be clearly defined, and contractual arrangements should properly address personal data protection requirements.
5. Organisational and Technical Security Measures
Data protection is not limited to legal documentation.
A company should control access to information, allocate appropriate access rights among employees, ensure the security of data storage and transmission, and implement other necessary organisational and technical measures.
6. Responding to Data Breaches and Security Incidents
Even where appropriate safeguards are in place, the possibility of a security incident cannot be completely eliminated.
A company should therefore establish in advance how it will respond to personal data breaches: who is responsible for managing the incident, how it will be documented, what remedial measures should be taken, and when notification of the competent authority or affected individuals may be required.
The Biggest Mistake Is Treating Compliance as a Folder of Documents
A company may have an impressive Privacy Policy, several consent forms and dozens of pages of internal documentation — and still have no clear understanding of what actually happens to personal data in practice.
For example:
According to the policy: customer data is retained for a specified period.
In reality: the CRM system continues to store it significantly longer.
Or:
According to the documentation: personal data is used for one specific purpose.
In reality: the marketing department uses the same database for additional marketing communications.
This is why effective data protection does not begin with downloading a template from the internet. It begins with an analysis of actual business processes.
We Build a System, Not Just Documents
Legal compliance with personal data protection requirements is a comprehensive task.
We help businesses audit their existing processes and build a data protection framework that takes into account applicable legislation, including the GDPR and Law of the Republic of Moldova No. 195/2024.
Depending on the company’s needs, our legal support may include:
- auditing personal data processing activities;
- preparing and updating the RoPA;
- determining the appropriate legal bases for processing;
- reviewing and preparing Privacy Policies;
- developing internal policies and procedures;
- conducting DPIAs for processing activities that may present a high risk;
- reviewing agreements with processors and other contractors;
- assessing international transfers of personal data;
- developing procedures for handling and fulfilling data subject rights;
- preparing data breach and incident response procedures;
- providing legal support for the implementation of GDPR and Moldovan data protection requirements.
Data Protection Should Work Together with Your Business
The purpose of compliance is not to create additional obstacles for a company. It is to make personal data processing activities transparent, manageable and legally sound.
When a business understands what data it collects, why it needs that data, on what legal basis it is processed, where it is stored, to whom it is transferred, and when it should be deleted, personal data protection stops being a collection of confusing acronyms.
RoPA gives the company a map.
DPIA helps assess the risks.
And a comprehensive compliance framework turns legal requirements into a clear and manageable part of everyday business operations.
You focus on growing your business. We help ensure that the way you work with data does not create unnecessary legal risks.
Useful articles
European-Style Taxation: Moldova Changes the Rules for International Business
The Republic of Moldova has begun transposing European rules on direct taxation into its national legislation. On 22 September, the Government approved the relevant draft law. For most entrepreneurs, its provisions may still seem somewhat distant: some are due to take effect in 2027–2028, while others will apply only after the country joins the European Union. However, for companies with foreign shareholders, subsidiaries, loans or intellectual property, the changes may have very practical implications.
Legal Support for Businesses: Reliable Protection for Your Company
Businesses need legal counsel not only when a dispute has already arisen, a regulatory inspection has begun, or a business partner has breached an agreement. It is far more effective to identify and address legal risks before they become serious problems. That is why effective legal support is not about constantly dealing with consequences — it is about taking a systematic and proactive approach to risk management.
Moldova's New Data Protection Law: Fines of Up to 2 Million Lei — How Businesses Can Protect Themselves. A Step-by-Step Guide
On August 23, 2026, Law No. 195/2024 on the protection of personal data comes into force in the Republic of Moldova — the national version of the European Regulation (EU) 2016/679, better known as the GDPR.
Leave a request