Legal obligation
Two of the obligations the GDPR places on every organization that processes personal data are:
- Tell people how their data is used. Customers, employees, subscribers, patients — anyone whose data you collect has the right to know who you are, why you need their data, on what legal basis, how long you keep it and how to exercise their rights. That is the Art. 13 information clause.
- Keep a record of your processing. You must keep an up-to-date register of your processing activities and hand it to the supervisory authority whenever it asks for it. That is the Art. 30 register.
rat.gd takes care of both: you describe each activity once, and it writes and keeps up to date every document these obligations require.
Once activities are active, every one of them produces two documents, in every language of the register:
- Art. 30 declaration — the formal record of that activity for the supervisory authority. Open it from the activity's details, and download it as PDF or RTF.
- Art. 13 information clause — the notice you owe to the people whose data you process. Each activity has a direct link to it, and an embed snippet, so you can point to it from a privacy policy, a consent form, an email footer or a web page and it always shows the current text. It can also be downloaded as PDF or RTF.
Both documents can be shared as a link, a printable QR code card, or embedded in your own website — see Publishing the documents. The declaration can be read by outsiders only if your organization is public.
The complete register — every active activity, grouped by unit, with a front page and a summary — is available as a single PDF from the dashboard.
Your data is never locked in. Organization settings → Organization data exports the whole organization as JSON or as a ZIP of spreadsheets, and the same page restores it; see Import / Export.