Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsDPDP RoPA · India
A RoPA, or Record of Processing Activities, is a register of what personal data your organisation processes, why, who receives it, how long it is kept and who is accountable. The DPDP Act, 2023 does not require one by name, but it is the clearest way to show your processing is organised and defensible.
Partner-driven delivery. We scope your RoPA first, then match you with a specialist partner suited to your sector, so you get the right depth of work without paying for the wrong one.
Last updated 3 October 2026 · Based on the DPDP Act, 2023 and the DPDP Rules, 2025 · Editorial policy
Definition
A RoPA is a structured register of the ways your organisation processes personal data. For each activity, such as payroll, a newsletter or customer support, it records the purpose, the categories of personal data involved, who the data comes from, who receives it, how long it is kept, the safeguards in place and the person accountable. A RoPA is closely related to a data map, but it answers a different question: not where the data is, but why it is being processed.
The DPDP Act does not use the term “RoPA” and does not require a stand-alone record of processing activities. The concept is a GDPR Article 30 requirement. Under the DPDP Act, a RoPA is a good-practice accountability tool that supports duties on notice, consent, rights, retention and security.
Is it required?
Not by name. But several statutory duties are hard to meet or evidence without one.
| DPDP duty | How a RoPA helps | Legal basis / status |
|---|---|---|
| Notice | Lists the purposes and data categories the notice must describe | Statutory S.5 |
| Consent | Shows which activities rely on consent and which on certain legitimate uses | Statutory S.6 and S.7 |
| Accuracy and retention | Records how long each category is kept and why | Statutory S.8(3) and S.8(7) |
| Processors | Identifies who processes data on your behalf | Statutory S.8(2) |
| Security safeguards | Records the safeguards applied to each activity | Statutory S.8(5) + Rules |
| Data Principal rights | Shows where to look when a request arrives | Statutory S.11–14 |
| Accountability to the Board | Gives you an organised record if the Data Protection Board asks how you process data | Practical |
Fields
A useful RoPA has one row per processing activity, with these fields.
| Field | What to record | Why it matters |
|---|---|---|
| Activity | The processing activity, for example payroll | Gives each row a clear owner |
| Purpose | Why the data is processed | Supports notice and purpose limits |
| Basis | Consent or a certain legitimate use | Shows why processing is permitted |
| Data Principals | Whose data: customers, employees, applicants | Sets who the notice goes to |
| Data categories | The kinds of personal data involved | Links to security and retention choices |
| Source | Where the data comes from | Helps answer access requests |
| Recipients | Processors and other parties who receive it | Drives processor contracts |
| Transfers | Any transfer outside India | Supports review under S.16 |
| Retention | How long it is kept and the deletion trigger | Supports erasure and S.8(7) |
| Safeguards | Security controls applied | Evidences S.8(5) |
| Owner | The accountable person or team | Makes updates someone’s job |
| Last reviewed | Date of the last check | Shows the record is current |
How to do it
Start from your data map if you have one. If not, the first steps build it.
Identify what your teams do with personal data, such as payroll, marketing, support and recruitment.
Pull in the systems, data categories and vendors for each activity from your data map.
Write down why each activity happens and whether it relies on consent or a certain legitimate use.
Name one accountable person for each row, then confirm the details with them.
Set a review cycle and triggers for change, such as a new vendor, system or purpose.
Start with the activities that carry the most risk or the most data. A RoPA that is accurate for ten activities is more useful than one that is vague for a hundred.
Example and template
An illustrative extract only. Your own RoPA reflects your actual activities, and the basis for each should be confirmed with your legal adviser.
| Activity | Purpose | Basis | Data categories | Recipients | Retention | Owner |
|---|---|---|---|---|---|---|
| Newsletter | Send updates people asked for | Consent (S.6) | Name, email | Email delivery provider | Until consent is withdrawn | Marketing |
| Enquiry handling | Respond to website enquiries | Consent (S.6) | Name, work email, phone | CRM vendor | Per retention schedule | Sales |
| Payroll | Pay employees | To be confirmed with counsel (consent or certain legitimate use, S.7) | Identity, bank and attendance data | Payroll provider | Per retention schedule | HR |
| Function | Typical activities to record | Typical recipients |
|---|---|---|
| HR | Recruitment, onboarding, payroll, attendance, background checks | Payroll provider, HRMS vendor, verification agency |
| Marketing | Newsletters, campaigns, lead capture, analytics | Email platform, ad platforms, analytics vendor |
| Sales | Enquiry handling, quotations, account management | CRM vendor, dialer and messaging providers |
| Customer support | Ticketing, call recording, chat, complaints | Helpdesk, telephony and chat providers |
| Finance | Invoicing, collections, vendor payments | Payment gateway, banks, accountants |
| Product and IT | Account management, logging, backups, testing | Cloud, monitoring and analytics providers |
Know the difference
Useful if you already keep a RoPA for GDPR purposes.
| GDPR Article 30 | DPDP Act, 2023 | |
|---|---|---|
| Record required by law | Yes, for many controllers and processors | Not by name |
| Basis terms | Includes legitimate interests | Consent and certain legitimate uses (S.7). It has no GDPR-style “legitimate interests” |
| Regulator | Supervisory authorities | Data Protection Board of India |
| Practical use | Compulsory register | Accountability and evidence for notices, consent, rights, retention and security |
An existing GDPR RoPA is a good starting point, but the basis column and the notice, consent and Board-related fields need to be re-mapped to the DPDP Act.
Know the difference
| Data mapping | RoPA | |
|---|---|---|
| Main question | Where is personal data and how does it move? | Why is each activity carried out, and who is accountable? |
| Focus | Systems, flows, vendors and locations | Purposes, categories, recipients, retention, safeguards and owners |
| Typical reader | IT, security, data and engineering teams | Legal, privacy, compliance and audit teams |
The data mapping service has its own page: DPDP Data Mapping. A data map is the input and the RoPA is the accountable record built from it.
Partner-driven delivery
DPDPActIndia is a partner-driven platform. We don’t sell a one-size-fits-all consulting package. We define the RoPA work first and then, only when you ask, match you with a specialist partner suited to your sector and size.
STEP 1
Tell us which teams and activities are involved, or start with the free assessment.
STEP 2
We turn it into defined work, not a vague enquiry.
STEP 3
Where the work needs specialist delivery, we identify partners suited to it.
STEP 4
You stay in control of whether to work with any provider introduced.
Deliverables
Depending on scope, outputs may include:
Avoid these
Timing
Sections 18–26 commenced, establishing the Data Protection Board framework.
Consent Manager registration: S.6(9), S.27(1)(d) and Rule 4.
Main Data Fiduciary duties, Data Principal rights and most Board inquiry, adjudication and penalty provisions commence.
A RoPA needs input from several teams and sign-off from legal. Starting early leaves time to correct what it reveals before the main duties commence.
By sector
The activities and vendors differ by sector. See what the DPDP Act means for yours.
Questions
Ten minutes now shows which areas need attention first, including where a RoPA would help most.
What’s next
Consultant-led and partner-backed.