The data-mapping exercise you do not have to run.

A RoPA is mostly a description of what your systems do. Your systems already know. Scrutora fills that part in from the scan and leaves you the handful of decisions only a person can make.

Filled in from your code
  • ✓Data categories held
  • ✓Where each category is stored
  • ✓Which third parties receive it
  • ✓Special-category data present
  • ✓Systems and files involved
  • ✓Cross-border egress observed in code
Yours to decide
  • ○Controller name and contact
  • ○Data Protection Officer
  • ○Lawful basis for each purpose
  • ○Purposes of processing
  • ○Categories of data subjects
  • ○Retention periods
01 · Pre-filled

Categories, recipients and special-category flags, from the scan.

scrutora
RoPA overview: data categories, recipients, special category count, and policy field completion.
20 data categories, 4 recipients, 1 special category. The counts come from the same graph that draws your data flow map, so they cannot disagree with it.
02 · What only you can answerPOLICY, NOT CODE

We do not invent a lawful basis.

No scanner can read your intent. Lawful basis, purpose and retention are decisions, and a tool that guesses at them produces a document that is worse than no document, because it looks finished.

scrutora
The RoPA policy fields: controller, DPO, lawful basis, purposes, categories of data subjects, international transfers.
Saved answers flow into the JSON and CSV export alongside everything the scan proved.
03 · The finished record

Every category, every recipient, ready to hand over.

scrutora
The completed RoPA listing data categories, third-party recipients and the frameworks each triggers.
Exportable as JSON or CSV. Because it is generated, re-running the scan tells you what changed since the last one.