A department begins using an AI tool that processes customer personal data. Under GDPR Article 30, which governance record must be updated to reflect this?
- A.The shareholder register
- B.The Record of Processing Activities (RoPA)
- C.The fixed-asset depreciation schedule
- D.The business continuity call tree
Why B is correct
GDPR Article 30 requires controllers to maintain a Record of Processing Activities documenting each processing operation's purposes, data categories, recipients, transfers, and retention; introducing an AI tool that processes customer personal data is a new or changed processing activity that must be reflected there. The shareholder register, depreciation schedule, and continuity call tree are corporate, finance, and resilience records with no Article 30 role.
Know someone studying for AI Security Fundamentals? Send them this one.