Data format
The JSON file carries everything the organization holds. The ZIP archive carries the same content split into spreadsheet files, with the partner logos as image files.
The fields each entity carries, in the terms the forms use, are listed in the "What a … holds" section of its page under Components: Organizations, Organizational Units, Processing Activities, Partners, Contacts, Contracts.
JSON file format
One structured file, holding:
| Organization | Names, address, contacts, colour, logo, notes |
| Languages | The configured languages and which one is the default |
| Partners | Every partner, with its contacts |
| Contracts | Every contract, with the partners and activities it links |
| Units and activities | Every organizational unit's name and every processing activity, once per language, with all their fields and their active/inactive status |
| Unit colours and contacts | Every organizational unit's colour and contacts — once, since they are the same in every language |
| Templates | Your custom templates |
Members and their roles are not part of it: they belong to your account, not to the register. In outline, the file looks like this:
{
"exportVersion": 1,
"exportedAt": "2026-05-18T00:00:00.000Z",
"organization": {
"licenseStart": 0,
"licenseEnd": 0,
"licenseCost": 0,
"shortName": "demo",
"isBlocked": false,
"isPublic": true,
"isDemo": true,
"highestOuId": 4,
"highestActivityId": 7,
"highestPartnerId": 7,
"highestContractId": 11,
"schemaVersion": 15,
"defaultActivityAttributes": {
"activityId": 0,
"activityName": "",
"role": "Controller",
"purposeShort": "",
"purposeLong": "",
"legalbasis": ["Consent"],
"legalbasisLong": "",
"legalbasisSpecial": ["ExplicitConsent"],
"dataCategories": ["Characteristics", "Identification"],
"datasubjectCategories": "",
"activityCategories": ["DataCollection", "DataStorage"],
"dataOrigin": "",
"timeLimit": "",
"profiling": false,
"communications": "",
"communicationsLong": "",
"controllers": [0],
"processors": [],
"transfers": false,
"transfersLong": "",
"securityLevel": "low",
"securityMeasuresLong": "",
"active": false,
"createdAt": 0,
"updatedAt": 0
},
"partners": [
{
"organizationId": 0,
"organizationName": "TEST",
"organizationNameLong": "Demo Organization",
"organizationColor": "#2563EB",
"organizationWebsite": "",
"organizationPostalAddress": {
"addressLine1": "Test Avenue",
"addressLine2": "Test Org Main Office",
"city": "Testville",
"stateProvince": "",
"postalCode": "00000",
"country": "LX"
},
"organizationLogo": null,
"organizationLogoVersion": null,
"organizationVatNumber": "",
"organizationNotes": "Self organization. This is the organization owning this ROPA.",
"organizationContacts": [
{
"contactId": 1,
"contactFirstname": "John",
"contactLastname": "Smith",
"contactRole": "DPO",
"contactEmails": [
{
"email": "dpo@test-organization.com",
"description": "DPO Office",
"isPrimary": true
}
],
"contactPhoneNumbers": [
{
"countryCode": "+1",
"phoneNumber": "5551234567",
"description": "Office",
"isPrimary": true
}
],
"contactNotes": "Data Protection Officer. Primary contact for GDPR compliance matters.",
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
}
],
"contractOrder": [],
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
},
{
"organizationId": 1,
"organizationName": "CloudStore",
"organizationNameLong": "CloudStore Solutions Inc.",
"organizationColor": "#0891B2",
"organizationWebsite": "https://www.cloudstore-demo.com",
"organizationPostalAddress": {
"addressLine1": "123 Tech Boulevard",
"addressLine2": "Suite 400",
"city": "San Francisco",
"stateProvince": "California",
"postalCode": "94105",
"country": "US"
},
"organizationLogo": null,
"organizationLogoVersion": null,
"organizationVatNumber": "",
"organizationNotes": "Cloud storage provider for document archiving and backup services. Primary data processor for file storage.",
"organizationContacts": [
{
"contactId": 1,
"contactFirstname": "Sarah",
"contactLastname": "Mitchell",
"contactRole": "DPO",
"contactEmails": [
{
"email": "sarah.mitchell@cloudstore-demo.com",
"description": "Work",
"isPrimary": true
},
{
"email": "dpo@cloudstore-demo.com",
"description": "DPO Office",
"isPrimary": false
}
],
"contactPhoneNumbers": [
{
"countryCode": "+1",
"phoneNumber": "4155551234",
"description": "Office",
"isPrimary": true
},
{
"countryCode": "+1",
"phoneNumber": "4155559876",
"description": "Mobile",
"isPrimary": false
}
],
"contactNotes": "Available Mon-Fri 9am-5pm PST. Preferred contact for data protection matters.",
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
},
{
"contactId": 2,
"contactFirstname": "James",
"contactLastname": "Rodriguez",
"contactRole": "Technical",
"contactEmails": [
{
"email": "james.rodriguez@cloudstore-demo.com",
"description": "Work",
"isPrimary": true
}
],
"contactPhoneNumbers": [
{
"countryCode": "+1",
"phoneNumber": "4155552345",
"description": "Office",
"isPrimary": true
}
],
"contactNotes": "Technical lead for API integration and data migration projects.",
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
},
{
"contactId": 3,
"contactFirstname": "Emily",
"contactLastname": "Chen",
"contactRole": "Support",
"contactEmails": [
{
"email": "emily.chen@cloudstore-demo.com",
"description": "Work",
"isPrimary": true
},
{
"email": "support@cloudstore-demo.com",
"description": "Support Team",
"isPrimary": false
}
],
"contactPhoneNumbers": [
{
"countryCode": "+1",
"phoneNumber": "4155553456",
"description": "Support Line",
"isPrimary": true
}
],
"contactNotes": "Customer support manager. Contact for service issues and incidents.",
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
}
],
"contractOrder": [1, 9],
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
}
],
"ropas": [
{
"locale": "en",
"isDefault": true
},
{
"locale": "de",
"isDefault": false
}
],
"contracts": [
{
"contractId": 1,
"contractName": "HR-SYS-2024",
"contractUrl": "https://example.com/contracts/hr-sys-2024",
"contractExpirationDate": "2025-12-31",
"contractDescription": "HR management system service agreement including payroll processing and training management",
"activityIds": [1],
"partnerIds": [1],
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
},
{
"contractId": 2,
"contractName": "DPA-BENEFITS-2024",
"contractUrl": "https://example.com/contracts/dpa-benefits",
"contractExpirationDate": "2026-06-30",
"contractDescription": "Data processing agreement for employee benefits administration and healthcare coordination",
"activityIds": [1],
"partnerIds": [5],
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
},
{
"contractId": 3,
"contractName": "OSH-2024",
"contractUrl": "https://example.com/contracts/osh-2024",
"contractExpirationDate": "2025-08-31",
"contractDescription": "Occupational safety and health surveillance service agreement with medical assessment provider",
"activityIds": [3],
"partnerIds": [2],
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
}
],
"ous": [
{
"ouId": 1,
"ouColor": "#C084FC",
"ouContacts": [
{
"contactId": 1,
"contactFirstname": "Laura",
"contactLastname": "Novak",
"contactRole": "HR Manager",
"contactEmails": [
{
"email": "hr@test-organization.com",
"description": "HR Office",
"isPrimary": true
}
],
"contactPhoneNumbers": [
{
"countryCode": "+1",
"phoneNumber": "5551230001",
"description": "Office",
"isPrimary": true
}
],
"contactNotes": "Owns the staff records and answers employees' data access requests.",
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
},
{
"contactId": 2,
"contactFirstname": "Peter",
"contactLastname": "Hall",
"contactRole": "Payroll Lead",
"contactEmails": [
{
"email": "payroll@test-organization.com",
"description": "Work",
"isPrimary": true
}
],
"contactPhoneNumbers": [],
"contactNotes": "",
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
}
]
},
{
"ouId": 2,
"ouColor": "#1c7958",
"ouContacts": []
}
],
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
},
"ropas": [
{
"orgId": "",
"orgShortName": "demo",
"locale": "en",
"ous": [
{
"ouName": "Human Resources",
"ouId": 1,
"activities": [
{
"activityId": 1,
"activityName": "Staff Management",
"purposeShort": "Staff management",
"purposeLong": "Management of training, payroll, promotion, and other aspects related to work life",
"legalbasis": ["Contract", "LegalObligation"],
"legalbasisLong": "",
"legalbasisSpecial": ["Employment", "Healthcare"],
"dataCategories": ["Identification"],
"datasubjectCategories": "Students; Other individuals related to the University; Former students",
"activityCategories": [
"DataCollection",
"DataGeneration",
"DataAccess"
],
"dataOrigin": "From the data subject or their legal representative; Reuse of data already held by the controller in other processing operations",
"timeLimit": "As long as necessary to fulfill the purpose for which they were collected and to determine possible responsibilities arising from the processing. Until consent is revoked.",
"profiling": false,
"communications": "-",
"communicationsLong": "-",
"controllers": [0],
"processors": [1, 5],
"transfers": true,
"transfersLong": "International transfers (outside the EEA) of personal data may be made to companies providing information society services, subject to the signing of contracts, and to other institutions with which data transfer agreements have been signed, in both cases respecting legality",
"securityLevel": "low",
"securityMeasuresLong": "Not required.",
"activityExpirationDate": "2099-12-31",
"forcedInactive": false,
"active": false,
"createdAt": 0,
"updatedAt": 0
}
]
},
{
"ouName": "Sales",
"ouId": 2,
"activities": [
{
"activityId": 4,
"activityName": "Customer Management",
"purposeShort": "Customer management",
"purposeLong": "Order management, logistics, billing, and collections management",
"legalbasis": ["Contract"],
"legalbasisLong": "",
"legalbasisSpecial": [],
"dataCategories": ["Identification"],
"datasubjectCategories": "Customers",
"activityCategories": [
"DataCollection",
"DataGeneration",
"DataAccess"
],
"dataOrigin": "From other public administrations or private entities; From the data subject or their legal representative",
"timeLimit": "As long as necessary to fulfill the purpose for which they were collected and to determine possible responsibilities arising from the processing.",
"profiling": true,
"communications": "",
"communicationsLong": "",
"controllers": [0],
"processors": [4],
"transfers": false,
"transfersLong": "Not made",
"securityLevel": "medium",
"securityMeasuresLong": "Not required.",
"activityExpirationDate": "2099-12-31",
"forcedInactive": false,
"active": true,
"createdAt": 0,
"updatedAt": 0
}
]
}
],
"createdAt": "2026-05-18T00:00:00.000Z",
"updatedAt": "2026-05-18T00:00:00.000Z"
}
],
"templates": []
}
ZIP data file format
The same content, split into CSV files: one per kind of record — the organization, its languages, partners, contacts, contracts and organizational units — and one per language for the activities. Every record is one row of one file, and the partner logos are image files in a logos folder. Meant to be opened and edited in a spreadsheet, not to be read by a script or an AI assistant.
For an organization whose short name is demo, the archive contains:
| File | Contents |
|---|---|
demo-organization.csv | The organization itself — a single row |
demo-locales.csv | One row per configured language |
demo-partners.csv | One row per partner |
demo-contacts.csv | One row per contact, whether of a partner or of an organizational unit |
demo-contracts.csv | One row per contract |
demo-ous.csv | One row per organizational unit, with or without activities — its colour and its name in each language |
demo-ropa-en.csv, demo-ropa-de.csv, … | One row per processing activity, one file per language |
logos/partner-0.png, … | Each partner's logo, as an image file — only for partners that have one |
demo-templates.json | Your custom templates — only present if you have any |
Download a sample: demo-export.zip, a complete export of the demo organization.
Every file follows the same conventions:
- UTF-8, comma-separated, with the column names in the first row. A cell holding a comma, a quote or a line break is wrapped in double quotes, with inner quotes doubled — spreadsheets do this for you.
- Yes/no fields hold
trueorfalse. - Multi-valued fields hold their values separated by
|, e.g.Contract|LegalObligation. - Every cell holds one value. A contact's emails and phone numbers take numbered columns —
email1…email5,phoneNumber1…phoneNumber5— since a contact holds at most five of each; unused ones stay empty. The one exception is the organization's default attributes (defaultActivityAttributes), stored as JSON text in a single cell. - Files refer to each other by number:
controllers,processorsandpartnerIdshold partnerorganizationIds,activityIdsholdsactivityIds,ouIdlinks an activity to its organizational unit, andparentTypewithparentIdlink a contact to its partner (partner, anorganizationId) or unit (ou, anouId). formatVersion, the first column of the organization file, says which layout the archive has. Archives exported before this layout existed still import.
demo-organization.csv
The organization's own settings: the archive's formatVersion, the organization's short name, the counters used to number new units, activities, partners and contracts, and the default values for a new activity (defaultActivityAttributes, as JSON). You will rarely need to edit this file.
formatVersion,shortName,licenseStart,licenseEnd,licenseCost,isBlocked,isPublic,isDemo,highestOuId,highestActivityId,highestPartnerId,highestContractId,schemaVersion,defaultActivityAttributes
2,demo,0,0,0,false,true,true,4,7,7,11,15,"{""activityId"":0,""activityName"":"""",""role"":""Controller"",""purposeShort"":"""",""purposeLong"":"""",""legalbasis"":[""Consent""],""legalbasisLong"":"""",""legalbasisSpecial"":[""ExplicitConsent""],""dataCategories"":[""Characteristics"",""Identification""],""datasubjectCategories"":"""",""activityCategories"":[""DataCollection"",""DataStorage""],""dataOrigin"":"""",""timeLimit"":"""",""profiling"":false,""communications"":"""",""communicationsLong"":"""",""controllers"":[0],""processors"":[],""transfers"":false,""transfersLong"":"""",""securityLevel"":""low"",""securityMeasuresLong"":"""",""active"":false,""createdAt"":0,""updatedAt"":0}"
demo-locales.csv
The configured languages and which one is the default. Each language listed here has a matching demo-ropa-<locale>.csv.
locale,isDefault
en,true
de,false
demo-partners.csv
One row per partner; the organization itself is partner 0. The postal address is spread over its own columns, organizationLogo names the partner's logo file in the logos folder, and contractOrder is the display order of the partner's contracts. The contacts are in demo-contacts.csv.
organizationId,organizationName,organizationNameLong,organizationColor,organizationWebsite,organizationVatNumber,addressLine1,addressLine2,city,stateProvince,postalCode,country,organizationLogo,organizationNotes,contractOrder
0,TEST,Demo Organization,#2563EB,,,Test Avenue,Test Org Main Office,Testville,,00000,LX,,Self organization. This is the organization owning this ROPA.,
1,CloudStore,CloudStore Solutions Inc.,#0891B2,https://www.cloudstore-demo.com,,123 Tech Boulevard,Suite 400,San Francisco,California,94105,US,,Cloud storage provider for document archiving and backup services. Primary data processor for file storage.,1|9
demo-contacts.csv
One row per contact. parentType and parentId say whose contact it is — partner and an organizationId, or ou and an ouId — and the rows keep each list's order, so a partner's or unit's first contact comes first. An email takes three columns (email, emailDescription, emailIsPrimary) and a phone number four (countryCode, phoneNumber, phoneDescription, phoneIsPrimary), each numbered 1 to 5.
parentType,parentId,contactId,contactFirstname,contactLastname,contactRole,contactNotes,email1,emailDescription1,emailIsPrimary1,email2,emailDescription2,emailIsPrimary2,email3,emailDescription3,emailIsPrimary3,email4,emailDescription4,emailIsPrimary4,email5,emailDescription5,emailIsPrimary5,countryCode1,phoneNumber1,phoneDescription1,phoneIsPrimary1,countryCode2,phoneNumber2,phoneDescription2,phoneIsPrimary2,countryCode3,phoneNumber3,phoneDescription3,phoneIsPrimary3,countryCode4,phoneNumber4,phoneDescription4,phoneIsPrimary4,countryCode5,phoneNumber5,phoneDescription5,phoneIsPrimary5
partner,0,1,John,Smith,DPO,Data Protection Officer. Primary contact for GDPR compliance matters.,dpo@test-organization.com,DPO Office,true,,,,,,,,,,,,,+1,5551234567,Office,true,,,,,,,,,,,,,,,,
partner,1,1,Sarah,Mitchell,DPO,Available Mon-Fri 9am-5pm PST. Preferred contact for data protection matters.,sarah.mitchell@cloudstore-demo.com,Work,true,dpo@cloudstore-demo.com,DPO Office,false,,,,,,,,,,+1,4155551234,Office,true,+1,4155559876,Mobile,false,,,,,,,,,,,,
partner,1,2,James,Rodriguez,Technical,Technical lead for API integration and data migration projects.,james.rodriguez@cloudstore-demo.com,Work,true,,,,,,,,,,,,,+1,4155552345,Office,true,,,,,,,,,,,,,,,,
partner,1,3,Emily,Chen,Support,Customer support manager. Contact for service issues and incidents.,emily.chen@cloudstore-demo.com,Work,true,support@cloudstore-demo.com,Support Team,false,,,,,,,,,,+1,4155553456,Support Line,true,,,,,,,,,,,,,,,,
ou,1,1,Laura,Novak,HR Manager,Owns the staff records and answers employees' data access requests.,hr@test-organization.com,HR Office,true,,,,,,,,,,,,,+1,5551230001,Office,true,,,,,,,,,,,,,,,,
ou,1,2,Peter,Hall,Payroll Lead,,payroll@test-organization.com,Work,true,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
demo-contracts.csv
One row per contract, linking activities and partners by their ids.
contractId,contractName,contractUrl,contractExpirationDate,contractDescription,activityIds,partnerIds
1,HR-SYS-2024,https://example.com/contracts/hr-sys-2024,2025-12-31,HR management system service agreement including payroll processing and training management,1,1
2,DPA-BENEFITS-2024,https://example.com/contracts/dpa-benefits,2026-06-30,Data processing agreement for employee benefits administration and healthcare coordination,1,5
3,OSH-2024,https://example.com/contracts/osh-2024,2025-08-31,Occupational safety and health surveillance service agreement with medical assessment provider,3,2
demo-ous.csv
One row per organizational unit, including units that have no activities yet: ouId, the unit's colour, and one name_<locale> column per language, side by side. This is the only file holding a unit's name; its contacts are in demo-contacts.csv.
ouId,ouColor,name_en,name_de
1,#C084FC,Human Resources,Personalwesen
2,#1c7958,Sales,Vertrieb
demo-ropa-en.csv
One row per activity. The first two columns are the language and ouId, the number of the activity's organizational unit (named in demo-ous.csv); the rest are the activity's fields as they appear in the form. The multi-valued ones are legalbasis, legalbasisSpecial, dataCategories, activityCategories, controllers and processors.
locale,ouId,activityId,activityName,purposeShort,purposeLong,legalbasis,legalbasisLong,legalbasisSpecial,dataCategories,datasubjectCategories,activityCategories,dataOrigin,timeLimit,profiling,communications,communicationsLong,controllers,processors,transfers,transfersLong,securityLevel,securityMeasuresLong,active,activityExpirationDate,forcedInactive,createdAt,updatedAt
en,1,1,Staff Management,Staff management,"Management of training, payroll, promotion, and other aspects related to work life",Contract|LegalObligation,,Employment|Healthcare,Identification,Students; Other individuals related to the University; Former students,DataCollection|DataGeneration|DataAccess,From the data subject or their legal representative; Reuse of data already held by the controller in other processing operations,As long as necessary to fulfill the purpose for which they were collected and to determine possible responsibilities arising from the processing. Until consent is revoked.,false,-,-,0,1|5,true,"International transfers (outside the EEA) of personal data may be made to companies providing information society services, subject to the signing of contracts, and to other institutions with which data transfer agreements have been signed, in both cases respecting legality",low,Not required.,false,2099-12-31,false,0,0
en,2,4,Customer Management,Customer management,"Order management, logistics, billing, and collections management",Contract,,,Identification,Customers,DataCollection|DataGeneration|DataAccess,From other public administrations or private entities; From the data subject or their legal representative,As long as necessary to fulfill the purpose for which they were collected and to determine possible responsibilities arising from the processing.,true,,,0,4,false,Not made,medium,Not required.,true,2099-12-31,false,0,0
The examples come from the demo organization, trimmed to two partners, three contracts, two languages and two activities.