Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

DPDP Data Mapping · India

DPDP Data Mapping Services: Know Where Your Personal Data Lives and Where It Goes

Data mapping finds the personal data your organisation handles and records where it is stored, who can access it and which vendors receive it. It is the practical starting point for notices, consent, rights requests, retention and breach response under the DPDP Act, 2023 and the DPDP Rules, 2025.

Partner-driven, not a one-size-fits-all consultancy. We scope your data mapping first, then match you with a specialist partner suited to your systems, so you don’t buy consulting you don’t need.

Data map: personal data sources feed a central inventory that connects to vendors Website forms, CRM, HRMS, WhatsApp and email, and spreadsheets feed a central personal data inventory. It records purpose, owner, retention and transfers, and connects to payroll, email, cloud and analytics vendors. WHERE DATA COMES IN WHERE IT GOES Website formsCRMHRMSWhatsApp, emailSpreadsheets Personal datainventory PayrollEmail platformCloud storageAnalytics PurposeOwnerRetentionTransfers Recorded for every system and vendor
ForIT, security, data and compliance owners
ScopeSystems, vendors and data flows
OutputData inventory and flow maps
DeliverySpecialist partners matched to your scope
Statutory statusImplementation control, not a stand-alone legal requirement

DPDP data mapping in short

What it is
A record of where your organisation’s personal data comes from, where it is stored, who can access it, which vendors receive it and when it is deleted.
Is it required?
There is no stand-alone requirement in the DPDP Act, 2023 or the DPDP Rules, 2025. It is an implementation control that most statutory duties depend on.
What you get
A personal-data inventory, data-flow maps, a vendor and processor map and a gap list.
Who does the work
You, with specialist partners matched through DPDPActIndia where the work needs them. We scope first and you decide whether to proceed.
When
Before notices, consent, retention and rights processes are finalised, and ahead of 13 May 2027, when the main duties commence.

Last updated 3 October 2026 · Based on the DPDP Act, 2023 and the DPDP Rules, 2025 · Editorial policy

The problem

You can’t protect, delete or explain data you can’t find.

Personal data rarely sits in one place. It spreads across your CRM, HRMS, website forms, WhatsApp and email, support tools, analytics, spreadsheets and vendor systems. Under the DPDP Act, your notice has to describe what you collect and why, a withdrawn consent has to be acted on, and erasure has to reach every copy. None of that works reliably until you know what you hold, where it is and who receives it.

What breaks without a data map

  • Notices describe data you don’t collect, or miss data you do
  • Consent withdrawal reaches some systems but not others
  • Erasure misses copies in exports, backups and spreadsheets
  • Access requests from Data Principals can’t be answered fully
  • Breach impact is guesswork, because nobody knows what was in the affected system

Definition

What is DPDP data mapping?

DPDP data mapping is the process of finding the digital personal data your organisation handles and recording where it comes from, why it is collected, where it is stored, who can access it, which vendors receive it, where it travels and when it should be deleted. The result is a data inventory and a set of data-flow maps that your work under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 can be built on.

At a glance

  • Also called: data inventory, data flow mapping, personal data discovery
  • Typical owner: IT, security, data or privacy lead
  • Main output: inventory and data-flow maps
  • Legal status: implementation control
  • Feeds into: notices, consent, rights, retention and your RoPA

Why it comes first

A data map sits underneath most DPDP duties.

Each duty below depends on knowing what data you hold and where it goes.

DPDP dutyWhat the data map tells youLegal basis / status
NoticeWhat personal data you collect and for which purposes, so the notice is accurateStatutory S.5
Consent and withdrawalWhere consent is captured and which systems and vendors must act on a withdrawalStatutory S.6
Data Principal rightsWhere a person’s data sits, so access, correction and erasure requests can be answeredStatutory S.11–14
Retention and erasureWhere copies live, including backups and exports, and when each should goStatutory S.8(7) + Rules
ProcessorsWhich vendors handle personal data on your behalf and need a contractStatutory S.8(2)
Security safeguardsWhich systems hold the most sensitive data and need the strongest controlsStatutory S.8(5) + Rules
Breach responseWhich systems, vendors and people are affected when something goes wrongStatutory S.8(6) + Rules
Cross-border transfersWhether and where personal data leaves IndiaStatutory S.16

Coverage

What does a data mapping project cover?

Scope is agreed up front. Most projects start with the highest-risk systems and widen from there.

  • Core business systems: CRM, HRMS, finance, support and marketing tools
  • Website and mobile apps: forms, analytics, cookies and third-party SDKs
  • Collection points: sign-ups, enquiries, calls, WhatsApp and email
  • Data categories and how sensitive each one is
  • The purpose for which each category is used
  • Data owners and who has access
  • Processors, sub-processors and other recipients
  • Transfers outside India
  • Retention periods and where deletion has to happen
  • Backups, spreadsheets, shared drives and unmanaged SaaS tools

How to do it

How to map personal data under the DPDP Act, step by step.

A practical sequence that works for most organisations. Start small, then widen.

1

Define the scope

Pick one business unit or process to start with, such as customer onboarding, HR or marketing, instead of the whole company at once.

2

Find collection points

List where personal data enters: website and app forms, calls, WhatsApp, email, events and partner feeds.

3

Talk to data owners

Interview the people who handle the data every day to learn where it is stored and who it is shared with.

4

Map the flow

Record how data moves through internal systems, payment gateways and vendors, and any transfers outside India, through to deletion.

5

Review and keep it current

Check the map with owners, rank the gaps and set triggers to update it when systems, vendors or purposes change.

Spreadsheets are enough for small estates with a handful of systems. Discovery tools help when there are many systems, a lot of unstructured data or frequent change.

Example and template

DPDP data mapping example and template structure.

An illustrative extract only. Your own map reflects your actual systems and vendors.

SystemData heldSourcePurposeShared withRetention
Website enquiry formName, work email, phoneWebsite visitorsRespond to enquiriesCRM vendor, email platformPer retention schedule
HRMSEmployee identity, bank and attendance dataEmployeesPayroll and HR administrationPayroll providerPer retention schedule
Marketing automationName, email, campaign activityLeads and subscribersSend updates people asked forEmail delivery providerUntil consent is withdrawn or the purpose ends

Where to look, team by team

TeamTypical personal dataTypical systemsQuestion to ask
MarketingNames, emails, phone numbers, campaign and web activityMarketing automation, website forms, analytics, ad platformsWhere did consent for each list come from, and who else receives it?
SalesContact and company details, call notesCRM, email, dialers, WhatsAppWho holds exports, and where are old leads kept?
HRIdentity, bank, attendance, leave and applicant dataHRMS, payroll, recruitment toolsHow long are unsuccessful applicant records kept?
Customer supportIdentity, order history, call recordings, chat logsHelpdesk, telephony, chat toolsHow long are recordings kept, and who can access them?
FinanceCustomer and vendor identity, bank and tax dataERP, accounting, payment gatewaysWhich gateways and advisers receive the data?
Product and engineeringAccount data, usage logs, device identifiersDatabases, logs, backups, analytics SDKsWhere do logs and test copies of production data end up?

Partner-driven delivery

We scope it. Specialist partners deliver it. You decide.

DPDPActIndia is a partner-driven platform. We don’t sell a one-size-fits-all consulting package. We define the mapping work first and then, only when you ask, match you with a specialist partner suited to your systems and sector.

STEP 1

You describe the problem

Tell us which systems, teams and vendors are involved, or start with the free assessment.

STEP 2

We scope the mapping

We turn it into a defined piece of work, not a vague enquiry.

STEP 3

We match a specialist partner

Where the work needs specialist delivery, we identify partners suited to it.

STEP 4

You decide whether to proceed

You stay in control of whether to work with any provider introduced.

Which specialist for which part

  • Discovery across systems: data engineering and governance specialist
  • Purposes, notices and contracts: privacy and legal specialist
  • Access to and exposure of sensitive stores: cybersecurity specialist
  • Ongoing ownership or a DPO appointment: appropriate DPO specialist via DPOIndia
We may work with specialist service and technology providers depending on the requirement. Organisations remain free to decide whether to proceed with any provider introduced through the platform. Looking for one now? Find your DPDP Act implementation partner.

Deliverables

Maps your teams can actually use.

Depending on scope, outputs may include:

  • Personal-data inventory
  • System and application register
  • Data-flow diagrams from collection to deletion
  • Vendor and processor map
  • Cross-border flow list
  • Data owner and access list
  • High-risk data store and gap list
  • Remediation backlog linked to notices, consent, retention and rights

Know the difference

Data mapping vs RoPA.

Closely linked, but different documents for different readers. Neither is a stand-alone requirement under the DPDP Act.

Data mappingRoPA
Main questionWhere is personal data and how does it move?Why is each activity carried out, and who is accountable?
FocusSystems, flows, vendors and locationsPurposes, data categories, recipients, retention, safeguards and owners
Typical readerIT, security, data and engineering teamsLegal, privacy, compliance and audit teams
OutputInventory and data-flow mapsA processing-activity register

The RoPA service has its own page: DPDP RoPA. A data map is the input, and the RoPA is the accountable record built from it.

Avoid these

Common data mapping mistakes.

  • Writing policies and notices before knowing what data you hold
  • Buying a consent tool before mapping, so it only covers the data you already know about
  • Mapping core systems and missing spreadsheets, shared drives and unmanaged SaaS tools
  • Leaving out vendors and sub-processors
  • Treating the map as a one-off instead of updating it when systems or vendors change

For context: in an EY India survey reported in February 2026, around 38% of respondents said they had begun categorising personal data and identifying third-party vendors. Source: Social Samosa.

Timing

Why map your data now?

13 Nov 2025

Board framework

Sections 18–26 commenced, establishing the Data Protection Board framework.

13 Nov 2026

Consent Manager milestone

Consent Manager registration: S.6(9), S.27(1)(d) and Rule 4.

13 May 2027

Substantive duties

Main Data Fiduciary duties, Data Principal rights and most Board inquiry, adjudication and penalty provisions commence.

By sector

Data mapping by sector.

The systems and vendors differ by sector. See what the DPDP Act means for yours.

Questions

Frequently asked questions about DPDP data mapping.

What is data mapping under the DPDP Act?
Data mapping is the process of finding the digital personal data your organisation handles and recording where it comes from, why it is collected, where it is stored, who can access it, which vendors receive it and when it should be deleted. The DPDP Act does not use the term, but the work supports its duties on notice, consent, rights, retention, security and breach response.
Is data mapping mandatory under the DPDP Act?
There is no stand-alone legal duty to produce a data map. It is an implementation control. In practice, duties such as accurate notices, acting on consent withdrawal, erasure and answering Data Principal requests are hard to meet without one.
What is the difference between a data inventory and a data map?
A data inventory lists what personal data you hold and where. A data map adds how that data moves: its sources, purposes, who can access it, which vendors receive it, any transfers outside India and where it is deleted. Most projects produce both.
What is the difference between data mapping and a RoPA?
A data map shows where personal data is and how it moves. A RoPA, or Record of Processing Activities, records why each processing activity happens, the data involved, recipients, retention, safeguards and the person accountable. The data map is the input to the RoPA. Neither is a stand-alone requirement under the DPDP Act.
What should a DPDP data map include?
At minimum: the systems that hold personal data, the categories of data, where it is collected from, the purpose, who can access it, which processors and other recipients receive it, any transfers outside India and the retention or deletion point. The example table on this page shows a simple structure.
How do you map personal data step by step?
Start with one business process, list where personal data is collected, interview the people who handle it, record how it moves between systems and vendors through to deletion, then review the map with owners and set triggers to update it. The step-by-step section on this page sets this out in detail.
Where should I start if I have never mapped data?
Start with one high-risk process, such as customer onboarding or HR, rather than the whole company. The free readiness assessment can also show which areas need attention first.
Do we need special software for data mapping?
Not always. A well-kept spreadsheet can work for a small organisation with a handful of systems. Larger or fast-changing environments often benefit from discovery tools. The scope of the project should decide the tooling, not the other way round.
How long does data mapping take?
It depends on the number of systems, business units and vendors, and on how well they are documented. Starting with the highest-risk areas gives usable results sooner than trying to map everything at once.
How much does data mapping cost?
It is scoped to your organisation. Cost depends on the number of entities and business units, the number of systems and vendors, the amount of unstructured data and how deep the technical discovery needs to go. The free assessment is a useful first step to see where mapping matters most.
Does data mapping cover vendors and cross-border transfers?
Yes. Processors, sub-processors and other recipients are recorded, along with any flows outside India, so that the processor duties in S.8(2) and the transfer provisions in S.16 can be assessed. Mapping records the facts; it does not decide whether a transfer is lawful.
Is there a data mapping template or example?
Yes. The example table on this page shows a workable structure: system, data held, source, purpose, shared with and retention. A template only helps if the information in it is accurate, which is why discovery comes first.
Who does the data mapping, DPDPActIndia or a partner?
DPDPActIndia is partner-driven. We help you scope the mapping work and, when you ask, introduce specialist partners suited to your systems and sector. You decide whether to proceed with any of them.

Start where you actually are.

Ten minutes now shows which areas need attention first, including where a data map would help most.