
Introduction
Our client is a public railway infrastructure manager, responsible for building, maintaining, and operating the country's rail network. As a public-sector organisation handling a broad range of personal data across multiple domains and subdomains, maintaining a compliant and well-governed Register of Processing Activities (RoPA) is both a legal obligation and an operational challenge.
Client
Transport Infrastructure Organization
Client since
2022
Services
Technologies
The problem
Our client already maintained a RoPA, but managing it consistently across domains was becoming harder to sustain. Ownership was unclear, lifecycle management was largely manual, and there was no structured way to enforce completeness or trigger periodic revalidation. The risk was a RoPA that drifted from reality, and a privacy governance model that couldn't keep pace with the organisation's scale.
The client didn't need a compliance fix, rather it needed a sustainable operating model. DTA's approach was to embed RoPA governance directly into a central Data Catalog, combining structured metadata, clear ownership, automated workflows, and quality controls in one governed environment.
How we solved it
Model the RoPA in the Data Catalog
DTA configured the Data Catalog around the Processing Activity asset, aligning the setup with the client's existing governance model and GDPR requirements. Dedicated communities and domains, a GDPR-aligned metamodel, attributes, relationships, and reference data were configured to structure information consistently. Roles were defined for Business Stewards, Data Protection Champions, and the DPO. DTA also built dedicated views and a GDPR dashboard to make the RoPA easy to navigate and maintain day to day.
Build automated workflows for the full RoPA lifecycle
DTA built workflows covering the creation, update, removal, approval, and revalidation of Processing Activities. Business rules guide users through mandatory and conditional fields. Ownership and approval tasks are assigned to the right roles automatically. Periodic revalidation can be triggered without manual coordination or removing the main source of governance drift.
Embed quality assurance from the start
Before go-live, DTA mapped existing RoPA content to the new Data Catalog model and migrated it into the new structure. That migration included a full content review, corrections and enrichments, field-level sample verification, and an automated completeness check. Business validation by Processing Activity owners was built into the process, making ongoing accuracy a shared responsibility, not a one-off exercise.
The results
Our client's RoPA governance has moved from a manual, fragmented process to a structured, catalog-driven model. Here's what that shift delivered.
One governed environment for the full RoPA
Ownership, relationships, statuses, workflows, dashboards, and an auditable change history now sit in a single place. Our client can see exactly where every Processing Activity stands, and who is responsible for it.
Automated revalidation with no manual coordination overhead
Periodic revalidation is triggered automatically, with tasks routed to the right owners. Governance no longer depends on someone remembering to follow up.
A quality-assured RoPA, maintained by the business
Completeness controls and field-level checks are built into the model. Business validation by Processing Activity owners means accuracy is maintained over time, not just at the point of implementation.
Key Learnings
A RoPA is only as good as the process that maintains it. These are the principles that made the difference on this engagement.
Ownership
A structured model only works if ownership is real. Defining roles for Business Stewards, Data Protection Champions, and the DPO wasn't a governance formality, it was the condition for everything else to function. Without named owners, workflows have nowhere to route and quality controls have no one to act on them.
Legacy
Migrate existing content, don't just configure the model. Moving legacy RoPA content into the new structure, with a full review and field-level verification, meant the client started with a clean, trustworthy foundation rather than inheriting old quality problems in a new system.
Metadata
Connecting privacy metadata to broader data governance pays dividends. Bringing Processing Activities into the Data Catalog alongside governed reference data, data domains, and data elements creates a richer picture, one that supports future governance maturity beyond the RoPA itself.
More case studies
We deliver impact where it matters most.


From fragmented controls to scalable regulatory data quality
Degroof Petercam is a Belgian investment house and private bank with deep roots in wealth management. Since 2024, it operates as part of Indosuez Wealth Management, the global wealth arm of Crédit Agricole Group. That integration created an immediate compliance pressure: the group needed a unified, scalable data quality framework across multiple entities... and fast.


Managing GDPR compliance across a complex stakeholder landscape
Mega is an internationally active energy-sector company with a complex supplier network spanning both the EU and non-EEA countries. Alongside external vendors, Mega relies on intra-group relationships with holding and sister organisations, each carrying its own data transfer risk profile.


From regulatory scrutiny to demonstrated compliance
LM Oost-Vlaanderen is a Belgian social security mutuality serving members across the province of East Flanders. As a social security organisation, it operates under strict sector-specific regulations and handles some of the most sensitive personal data categories that exist: health records, financial entitlements, and member identity.