Data InventoryReports

Reports

Monitor discovery on the Dashboard, build versioned RoPA reports for your processing activities, and export the DPDPA Purpose Registry.

Data Inventory turns what your systems and processing activities hold into records you can hand to a regulator or an auditor. This page covers the Dashboard, RoPA Reports under Article 30 of the GDPR, and the DPDPA Purpose Registry under Section 5 of the DPDPA 2023.

Dashboard

Open Data Inventory > Dashboard to see the state of discovery across your tenant.

CardMeaning
Total Systems ScannedThe number of systems that have been scanned.
Systems Need AttentionSystems that are disconnected or otherwise flagged for review, shown against the total number of systems in your inventory.
Systems with Sensitive DataSystems where scanning found sensitive data, shown against the total number of systems in your inventory.

Global Footprint of Data Systems

Below the cards, a world map and a Regional Distribution list show where your systems are located. Each region in the list shows its country, a share of the total as a percentage, and a bar reflecting that share. The percentages across all regions add up to 100%.

A system counted under Systems Need Attention may need a reconnection, a re-scan, or a manual review, depending on why it was flagged. Open Inventory to see and resolve individual systems; see Inventory.

RoPA Reports

A Record of Processing Activities (RoPA) is the register that GDPR Article 30 requires a controller or processor to keep: for each activity, what is processed, why, who it is shared with, how long it is kept, and how it is protected. Neostra builds this record for you from the processing activities and systems already in your inventory, and keeps a version history so you can show what your RoPA said at any point in time.

Creating a report

Open Data Inventory > Reports > RoPA Reports. The list shows every RoPA report you have created, with its Name, linked Processing Activity, Latest Version, Created By, and Created At.

Name the report

Click New RoPA. Give the report a descriptive name, for example "Article 30 Controller RoPA 2025". This name identifies the report in the list and in its version history; it does not change the data collected.

Select a processing activity

Search and select the processing activity the report covers, then confirm.

Data completeness and validation warnings

Opening a RoPA report shows its Report Configuration panel with a Data Completeness score: a percentage and a count of complete fields out of the total fields the report needs. A Ready chip means every required field is present; an Incomplete chip means some are missing or partial.

When fields are missing or partial, an issues count appears with a View Details action listing each one, the RoPA column it affects, whether it is missing or only partially filled, and how to fix it, for example by adding an attribute to the processing activity, linking a vendor, or linking a data point.

Generating a version

Click Generate Report to produce a new version. Neostra builds an Excel and a CSV file from the current state of the processing activity and its linked records. If nothing has changed since the last version, no new version is created; if the content is different, a new version number is saved and both files are stored against it.

Version history and downloads

Each report keeps its full version history, listed with the version number, who generated it, and when. From the history, download any version as Excel or CSV.

Per-activity quick export

You can also generate an Excel or CSV RoPA report directly for a single processing activity without creating a named report first, useful for a one-off export or a quick check before setting up version tracking.

What goes into a RoPA report

Each RoPA report is built around the GDPR Article 30 record and covers:

  • Business function and purpose of processing
  • Joint controller name and contact, where applicable
  • Categories of individuals and categories of personal data involved
  • Categories of recipients, including recipient vendors and links to their processor contracts
  • Retention schedule and security measures
  • The Article 6 lawful basis, the Article 9 condition for special category data, legitimate interests, and a link to the legitimate interests assessment (LIA) where relevant
  • The rights available to individuals for that activity, and whether automated decision making is used
  • The source and location of the personal data

These columns are populated from the processing activity itself, the attributes recorded against it, and the vendors, data subjects, and data points linked to it. A field stays blank, or shows as missing or partial in the validation check, when the corresponding attribute or link has not been set on the processing activity, a linked vendor, or a linked data point. Filling in those attributes and links in Inventory is what completes the report; see Inventory.

DPDPA Purpose Registry

Open Data Inventory > Reports > DPDPA Purpose Registry to see the notice fields required under Section 5 of the DPDPA 2023, one row per processing activity.

ColumnMeaning
Processing ActivityThe activity the row covers.
PurposeThe purpose of processing to be notified to data principals.
Consent TypeThe type of consent obtained.
Harm LikelihoodThe assessed likelihood of harm from the processing.
RetentionThe retention period for the data collected.
Transfer MechanismHow personal data is transferred, where applicable.
Significant Data FiduciaryWhether the activity is treated as belonging to a significant data fiduciary: Yes, No, or blank if not set.

Rows are generated from your active processing activities and the DPDPA attributes recorded against each one. A blank cell means that attribute has not been set on the processing activity; edit the activity's attributes to fill it in.

Click Export Excel or Export CSV to download the registry.

Keeping reports accurate

RoPA reports and the Purpose Registry are only as complete as the inventory behind them. Keep processing activities, their attributes, and their linked systems, vendors, and data points current in Inventory, then regenerate a RoPA version or re-export the Purpose Registry whenever something changes; see Inventory.

Data Inventory reporting is not legal advice. Confirm your RoPA and DPDPA notice obligations with your DPO or counsel.