Your GDPR record of processing activities now fills itself from the modules you already use, instead of starting from a blank page. DoliPlus — the enhanced cloud edition of Dolibarr — brings you five concrete tools:

  • a pre-filled register: DoliPlus reads your installation and proposes one sheet per detected activity;
  • a request desk: access, rectification, erasure and portability, with the one-month deadline tracked automatically;
  • a breach register with its 72-hour countdown;
  • an automatic purge of data kept too long, which you test before switching it on;
  • a sealed log: every erasure actually carried out leaves a trace that nobody can quietly rewrite.

In other words, your business software no longer merely stores data: it helps you prove that you handle it properly. Moreover, these tools switch on when you ask for them — simply tell us you want to use them, and we open them on your installation.

 

The GDPR record of processing activities you don’t have to write

Every company that handles personal data must keep a register of its processing activities. In practice, therefore, this concerns almost every small business: as soon as you invoice, prospect, employ staff or install a camera, you are concerned.

That is precisely where the exercise stalls. Faced with an empty spreadsheet, nobody knows where to start.

DoliPlus takes the problem from the other end. Since it knows which modules you run, it also knows which data you process. Consequently, one button walks through your active modules and creates a sheet per detected activity: customer management, prospecting, payroll, email campaigns, video meetings, support tickets, and so on.

GDPR record of processing activities pre-filled in DoliPlus

Each sheet arrives as pending validation, never as validated. This distinction matters: a register signed without being read is exactly what a supervisory authority criticises. You therefore review the sheets one after another, adjust the retention periods to your actual practice, then validate.

Finally, remember to add what happens outside your software — video surveillance, outsourced payroll, time clocks. Without them, the register would be incomplete.

 

Answer a request without spending three hours searching

Someone asks you for a copy of their data, or asks you to erase it. You then have one month to answer, and the clock starts on the day the request arrives.

DoliPlus opens a request desk. Above all, it does more than record the request: it goes and looks. It gathers what your installation actually holds about that person — third party sheet, contacts, invoices, quotes, tickets, email exchanges, documents — and hands you the file, ready to send.

However, two safeguards stand before any action. First, a human must state how they verified the requester’s identity. Second, a request filed through the public form only becomes actionable once the requester has confirmed their email address. Consequently, nobody erases anyone else’s data by simply typing their name.

 

The 72 hours that count after a data breach

A stolen laptop, a mailbox opened by the wrong person, a file sent to the wrong address: a breach is rarely spectacular. Yet the deadline is strict — 72 hours from the moment you became aware of it.

DoliPlus therefore opens a breach register with a visible countdown. It also asks the questions the authority will ask: what happened, which data, how many people, what you did about it, and whether those people must be informed.

 

See what the purge would erase, before you run it

Keeping data forever breaks the rules. Erasing blindly, on the other hand, destroys your address book. That dilemma stops most companies from ever starting.

DoliPlus settles it with a simulation. In one click, you get the exact table of what would be touched: rule by rule, the number of records concerned, separating those that would be anonymised from those that would be deleted.

The activation button only appears underneath that table. Therefore you cannot start the purge without having seen the figures. It stays switched off until you decide, and its activation is recorded with the name of the person who approved it.

Does your DoliPlus run several companies? Each one then applies its own retention periods, never those of a neighbour. From the main company, the simulation reads company by company: the detail of each, then the grand total. From a secondary company, you only see your own. Finally, activation is driven from the main company, since it commits them all.

 

Prove, six months later, that the erasure really happened

Here is the question that always comes last, and always at the worst moment: “prove to me that you really erased my data”. A dated line in a table proves very little, since whoever administers the database can rewrite it.

DoliPlus therefore writes every action actually carried out into a sealed log: an erasure, an objection to prospecting, a data file handed to someone, the activation of the purge, and the outcome of each of its runs.

Sealed action log backing the GDPR record of processing activities

Each line carries a fingerprint computed from the previous one. As a result, editing or removing a line breaks the chain, and the verification screen names the first break. The sealing key lives outside the database, so someone with database access alone cannot rewrite this log without it showing.

💡 Worth knowing: full server access could still rewrite the log — no local sealing protects against that. We say so plainly, because a promise that oversells is a promise nobody should trust.

 

Your GDPR record of processing activities: what DoliPlus covers, and what it does not

DoliPlus covers the register, data subject requests, breaches, retention periods and the proof of execution. In short, it covers what an ERP can actually do, because it holds the data.

By contrast, it does not carry out impact assessments, and it does not manage website cookie banners. These two subjects belong elsewhere, and free tools already cover them well — the French data protection authority publishes its PIA software for impact assessments, for example.

 

Further reading

 

💡 Ready to start your register? Just tell us the subject interests you: we switch these screens on in your DoliPlus, we run the analysis of your installation together, and we look at the purge simulation before any decision. You leave with an exportable GDPR record of processing activities, without having written a single line in a spreadsheet.

Related Entrées