Business purposes - processing activities
Document why your organization collects and uses personal data by creating processing activities and connecting them to your data sources.
Every system in your inventory exists for a reason: paying employees, running marketing campaigns, supporting customers. Processing activities let you document those business purposes and connect each one to the data sources and data it relies on. Together, they form your organization's data map, or record of processing activities (RoPA), ready to share with auditors and regulators.
One map for every jurisdiction
Whether you call it a RoPA, a data map or a data inventory, the requirement is practically the same: know what personal data you process, why, where it lives and who receives it. Processing activities in MineOS cover all of these with a single map, and you adapt the template to your jurisdictions.
| Jurisdiction | Often called | Details you might add to your template |
|---|---|---|
| US (CCPA/CPRA and other state privacy laws) | Data map or data inventory | Categories of personal information, business or commercial purpose, whether data is sold or shared, sources |
| EU and UK (GDPR) | Record of processing activities (RoPA) | Legal basis, retention periods, recipients, transfer safeguards |
| Canada (PIPEDA, Quebec Law 25) | Personal information inventory | Purposes, consent, retention, cross-border transfers |
| Brazil (LGPD) | Record of processing operations | Legal basis, purposes, retention |
If you operate in several regions, use one template with all the fields you need and use the sections to differentiate between them. See .
What is a processing activity?
A processing activity is a business purpose for collecting or using personal data, linked to the systems and data involved. For example, a "Customer support" activity might connect your helpdesk and CRM, the contact details and support history stored in them, and the customers whose data is processed.
MineOS's default processing activity template covers:
- Purpose: what the data is used for
- Data subjects: whose data is involved, such as customers, employees or job applicants
- Data sources and data types: the systems in your inventory and the data each one holds for this purpose
- Data flow: how data moves between systems and other parties, and where they're located
Build your map
1. Review Mira's suggestions in your inventory
Mira AI suggests likely processing activities for the data sources in your inventory, based on what each system does and on your For example, an HR system might come with suggestions such as "Payroll" and "Recruitment".
- Go to Data mapping › Inventory and open a data source.
- Suggestions will appear with a purple icon directly from the inventory table and within each data source.
- Accept the suggestions that match how your organization uses the system, or dismiss them.
Accepted suggestions become processing activities, linked to the data source. Work through your inventory system by system to build the map quickly. If you're not sure what a system is used for, ask its owner. See
. Complete each processing activity with autofill
Once your activities are linked to data sources, use Mira autofill to complete the rest of each activity, such as data subjects, data types, retention or legal basis, depending on your template.
- In the left navigation, under Data mapping, select Processing activities.
- Open a processing activity.
- Click Write with Mira, and review the suggestions.
- Accept or edit each suggestion, then save.
See ow suggestions and evidence work.
To create a processing activity from scratch instead, click New Activity on the Processing activities page and choose a template.
3. Map how data moves
The Data flow section of each activity shows the systems and other parties involved and where they're located, so you can spot data crossing borders. See
t your data map or RoPA
When your processing activities are complete, export them for audits, regulators or internal reviews.
- In the left navigation, under Data mapping, select Processing activities.
- Filter the table to the activities you need, for example by business unit, region or data subject. The export only includes the activities currently shown.
- Click on the export button and choose Excel or PDF.
Keep your map current
Business purposes change as teams adopt new tools and retire old ones. Review your processing activities whenever you add a data source or change how a system is used. When an activity involves higher-risk processing, link it to the relevant assessments and risks. See r map as the foundation for assessments
Your processing activities are the starting point for the rest of your compliance work. Once each business purpose is mapped to its systems, data and parties, you can see exactly where higher-risk processing happens, and which assessments you need.
| What your map shows | What it may indicate | Consider |
|---|---|---|
| Data flowing to systems or parties in other countries | International data transfers | A transfer impact assessment, and checking safeguards with each vendor |
| Sensitive data, such as health, biometric, financial or children's data | Higher-risk processing that many laws require you to assess | A data protection impact assessment or privacy impact assessment |
| Legitimate interest as the legal basis | Processing that needs a documented balancing test | A legitimate interest assessment |
| Data sold, shared or used for targeted advertising | Activities that US state privacy laws require you to assess | A data protection or risk assessment |
| AI or automated decision-making | Processing covered by AI and privacy rules on automated decisions | An AI assessment |
| A new vendor added to an activity | Third-party risk | A vendor assessment |
When you open an assessment for a processing activity, link the two, so the assessment draws on the activity's data sources, data types and data flow. Mira AI autofill then uses this mapped information to draft the assessment, so you don't enter the same details twice. Any risks the assessment identifies stay connected to the activity and its systems. See
compcurrent map means you assess where it matters, rather than assessing everything or guessing what to assess.
Related articles
- Visualize data flows: see how data moves for each processing activity
- Map international transfers with Mira: identify cross-border transfers automatically
- Building Templates: adapt the processing activity template to your jurisdictions
Updated about 2 hours ago
