Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Data mapping collection · Understand

Is Data Mapping Mandatory Under the DPDP Act? What the Law Requires and What It Needs in Practice

A clear, section-by-section answer for compliance leads, founders and counsel: what the Act and Rules do and do not say about data maps, inventories and records of processing, and how much mapping you actually need.

By the DPDPActIndia editorial team · Last updated 4 October 2026 · About 14 minute read · Checked against the Act text · Editorial policy

In short

No. Data mapping is not an express obligation under the DPDP Act. The Act does not use the words data map, data inventory or record of processing, and it has no general equivalent of GDPR Article 30. But several duties, including the right to a summary of your processing and sharing under Section 11(1), are hard to meet and harder to prove without one. Treat a data map as practical compliance infrastructure, not as a legal requirement.

  • Safe wording: “Not expressly required, but practically necessary to meet several duties.”
  • Closest hook: Section 11(1)(a) and (b), a summary of data and processing, and the identities of those it was shared with.
  • No separate penalty attaches to not having a data map. Penalties attach to failing specific duties, such as reasonable security safeguards.
Express legal duty
None found
No provision names a data map, inventory or RoPA.
In practice
Strongly advised
Needed to run consent, vendors, erasure, rights and breach duties.
In this article
  1. The answer
  2. The verdict in three layers
  3. What the Act says and leaves out
  4. Which duties depend on a data map
  5. The comparisons
  6. DPDP vs GDPR Article 30
  7. The DPDP Rules 2025
  8. Significant Data Fiduciaries
  9. Penalties and enforcement
  10. What to do
  11. The five-question self-test
  12. How much mapping you need
  13. The minimum viable data map
  14. Claims to avoid and what to say instead
  15. Go further
  16. FAQ
  17. Related resources
  18. Primary sources

The answer

Is data mapping mandatory under the DPDP Act? The verdict on data inventory, RoPA and records of processing

The honest answer has three layers, and mixing them up is where most online advice goes wrong. The law does not require a map by name. The law does require outcomes that you cannot reliably deliver without the information a map holds. And if you are ever challenged, a map is the quickest way to show what you did.

1Express dutyNo section of the Act names data mapping, a data inventory or a register of processing.Answer: not mandatory by name
2Duties that need the informationErasure, processor control, rights requests, breach intimation and security all depend on knowing what you hold and where.Answer: practically necessary
3EvidenceIf a question arises, you must be able to prove notice and consent, and show what safeguards you took.Answer: strongly advisable

This page deals only with the question “is it mandatory?” For the method, the fields and the roadmap, use the complete DPDP data mapping guide.

The answer

What the DPDP Act says about data mapping, and what it leaves out

The Act is outcome-based. It tells a Data Fiduciary what it must achieve, such as erasing data or protecting it, and leaves the method to the organisation. We found no provision that prescribes a record, register or map as the method.

What the Act does not contain

  • The terms “data map”, “data inventory” or “record of processing”.
  • A general duty to keep a register of processing activities.
  • A prescribed list of fields to record for each activity.
  • A duty to show such a record to the Board on request, in the way GDPR Article 30(4) works.

What it does contain

  • Responsibility for processing done by processors on your behalf (Section 8(1)).
  • Erasure by you and by your processors (Section 8(7)).
  • A duty to prove notice and consent in a proceeding (Section 6(10)).
  • A right to a summary of data and a list of recipients (Section 11(1)).
What the Act says

Section 11(1) lets a Data Principal obtain from a Data Fiduciary to whom she has given consent: (a) a summary of the personal data being processed and the processing activities undertaken with respect to it; and (b) the identities of all other Data Fiduciaries and Data Processors with whom the data has been shared, with a description of the data shared. The Act does not say how you must keep that information. The practical answer is a maintained inventory.

Section 8(4) adds that a Data Fiduciary must implement “appropriate technical and organisational measures” to ensure effective observance of the Act. Section 8(4) does not mention mapping. It is, however, the general accountability duty under which many organisations place their inventory, because a documented view of processing is a common organisational measure. That is our reading of how it is used, not a statement that the section requires it.

The answer

Which DPDP Act duties depend on a data map? A strength-of-link table

Not every link is equally strong. The table grades how closely each duty depends on the information in a data map, so you can separate what the Act says from what we advise.

DPDP provisions graded by how much they depend on data mapping (the Act sets the duty, not the map)
ProvisionWhat the Act requiresWhy a map mattersLink
11(1)(a), (b)On request, give a summary of data and processing activities, and the identities of those the data was shared with.This is the information a map holds. Without it you rebuild the answer from scratch each time.Direct
8(7)Erase data when consent is withdrawn or the purpose is no longer served, and cause processors to erase it.You cannot erase from systems and processors you have not listed.Strong
6(6)On withdrawal, cease processing and cause processors to cease.Shows every system and processor that must stop.Strong
8(1), 8(2)You stay responsible for processors and may engage them only under a valid contract.A processor list with contract status is the control that proves this.Strong
8(6)Intimate the Board and each affected Data Principal of a personal data breach, in the prescribed form and manner.Tells you who is affected and what data was involved.Strong
8(5)Protect personal data with reasonable security safeguards, including data processed by processors.Safeguards need to be placed where the data actually is.Supporting
6(10), 5Give notice, and prove notice and consent if a question arises in a proceeding.Links each activity to a notice version and consent record.Supporting
12, 8(3)Correct, complete, update and erase on request. Keep data complete, accurate and consistent where it drives decisions or is disclosed.Shows where each copy of the data lives.Supporting
8(4)Implement appropriate technical and organisational measures to ensure effective observance.A documented view of processing is one common such measure.Supporting
9Verifiable parental consent for children; no tracking or targeted advertising directed at children.Flags where minors’ data is held and used.Supporting
How to read this table

Direct means the duty is, in substance, to produce what a data map contains. Strong means the duty is very hard to perform reliably without that information. Supporting means a map helps but other controls also matter. The grading is our editorial judgment, not a statement in the Act.

The comparisons

DPDP Act vs GDPR Article 30: why a record of processing activities (RoPA) is not a DPDP Act requirement

GDPR Article 30 expressly requires records of processing. DPDP has no general equivalent. Teams with GDPR experience often assume the two match. They do not, and repeating the GDPR rule as a DPDP rule is the most common error in this topic.

Records of processing: GDPR compared with the DPDP Act
QuestionGDPRDPDP Act
Is there an express records duty?Yes. Article 30 requires controllers and processors to keep records of processing, with a limited exemption for some smaller organisations.No general equivalent was found in the Act.
Are the fields prescribed?Yes. Article 30(1) lists what a controller’s record must contain.No. You choose what to record.
Must the record be shown to the regulator?Yes, on request, under Article 30(4).No equivalent obligation was found.
What is the basis for processing?Six lawful bases, including legitimate interests.Consent, or the specific “certain legitimate uses” in Section 7. There is no general legitimate-interest basis.
Practical effectA register is a compliance deliverable in itself.A register is a tool for meeting other duties.
Watch out: do not import GDPR vocabulary

Say “a data inventory in RoPA format”, not “the DPDP RoPA”. Use “applicable basis” (consent or a Section 7 use), not “lawful basis” or “legitimate interest”. See the plain-language comparison of data map, data inventory and RoPA.

The comparisons

Do the DPDP Rules 2025 require data mapping or a data inventory?

We have not relied on any rule as imposing a data mapping or RoPA duty. The Rules were notified on 13 November 2025 and supply the detail the Act leaves to rules: the content of notices, breach intimation, retention and erasure details, Consent Manager registration and Significant Data Fiduciary measures.

Those topics matter because each one is a place where a map earns its keep. A notice must describe the data and purpose. A breach intimation must describe what happened. Erasure and retention rules need to be applied to specific systems. None of this turns a map into a legal requirement, but it raises the cost of operating without one.

Confirm before you rely on it

Rule numbers and exact wording should be checked against the Gazette text (G.S.R. 846(E)) before you cite them in a policy, contract or client advice. See our DPDP Rules 2025 explainer. Core Data Fiduciary duties apply from 13 May 2027, and Consent Manager registration opens on 13 November 2026.

The comparisons

Do Significant Data Fiduciaries (SDFs) have to maintain a data map?

Not by name, but this is where mapping is hardest to avoid. Section 10(2) requires a notified Significant Data Fiduciary to appoint a Data Protection Officer based in India and an independent data auditor, and to undertake periodic Data Protection Impact Assessments and periodic audits.

  • A Data Protection Impact Assessment, as Section 10(2)(c)(i) describes it, covers the rights of Data Principals, the purpose of processing and the assessment and management of risk. Each of these is easier to assess against a current inventory.
  • An independent auditor evaluating compliance will ask where data is, who handles it and how long it is kept. A map answers these consistently.
  • Section 10(1) lets the Central Government notify a class of Significant Data Fiduciaries based on factors such as the volume and sensitivity of data processed. We are not aware of a notified class at the time of writing. If you handle large volumes or sensitive data, plan as though you might be assessed. Check the current position before relying on this.

For the governance model, see Significant Data Fiduciary under the DPDP Act.

The comparisons

Can you be penalised for not having a data map?

Not for the absence of a map as such. The Schedule to the Act attaches monetary penalties to breaches of specific provisions, and the Board decides after an inquiry (Section 33).

Maximum penalties for selected duties that a data map helps you meet (Schedule to the Act)
DutyMaximum penaltyWhere a map helps
Reasonable security safeguards to prevent a breach (Section 8(5))Up to Rs 250 croreLocating systems, processors and data that need safeguards.
Intimation of a personal data breach (Section 8(6))Up to Rs 200 croreIdentifying affected people and data fast.
Children’s data obligations (Section 9)Up to Rs 200 croreFlagging where minors’ data is collected and used.

Other provisions carry other maximums, listed in the Schedule. These are ceilings, not fixed fines. Section 33 requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of data and the steps taken to mitigate. A documented, working inventory is one way to show the steps you took. The practical risk of having no map is therefore indirect: you are more likely to fail a duty that carries a penalty, and less able to show your efforts.

What to do

The five-question self-test: do you already have a working data map?

If you can answer all five without asking around, you effectively have one. If not, the gaps tell you where to start.

  1. Question 1What personal data do we hold, and about whom? Customers, employees, applicants, vendors, children.
  2. Question 2Why do we use it, and on what basis? The specified purpose, and consent or a named Section 7 use.
  3. Question 3Which systems and which vendors touch it? Including SaaS tools, backups and any processor outside India.
  4. Question 4When does it get deleted, and where? Including at processors and in backups.
  5. Question 5If a person asked for a summary, or a breach happened today, what would we send and to whom? This is Sections 11(1) and 8(6) in one question.
How many of the five can you answer today?Answer from documents, not from memory
All fiveYou have a working map. Assign an owner, set a review date, and keep it current when systems or vendors change.
Two to fourBuild a lightweight inventory this month. Start with the questions you could not answer, usually vendors and deletion.
None or oneRun a full mapping exercise. Begin with processors and erasure, then work back to purposes and notices.

What to do

How much data mapping do you need? Depth by organisation type

The Act does not set a standard, so match depth to risk. The table is our practical guidance and should be tested against your own facts.

Practical depth of data mapping by organisation profile (editorial guidance, not a legal threshold)
ProfileReasonable depthStart with
Small business, one or two systems, few vendorsA one-page register in a spreadsheet, reviewed twice a year.Purposes, systems, vendors, retention.
Growing company with a SaaS stack and several processorsA full inventory with owners, processor list and a simple flow diagram.The processor list and erasure paths.
Regulated or data-heavy business: fintech, health, education, children’s dataA full inventory plus flow maps, cross-border flags and a children’s data flag, reviewed on change.High-risk activities and breach impact.
Likely Significant Data Fiduciary or large enterpriseA governed programme: ownership, change control, audit evidence, DPIA linkage.Governance and evidence.

What to do

The minimum viable data map: four steps to a personal data inventory and data flow map

If you do nothing else, capture these four things for every processing activity. This is enough to answer most of the self-test.

1List activitiesBy business process, not by IT system.See the 7-step method
2Name purpose and basisConsent, or a Section 7 use.Mapping the basis
3Name systems and processorsWhere it sits and who handles it.Flows and processors
4Set retention and erasureWhen it goes, and how.Retention mapping

The full set of fields is in the minimum inventory fields table. A free Data Inventory Workbook is planned for this collection.

What to do

Data mapping claims to avoid, and what to say instead

Precise wording protects you in policies, proposals and board papers. These are the claims we see most often, with a safer version.

Common claims about DPDP data mapping and accurate replacements
Claim you may seeWhy it is riskySay instead
“DPDP mandates a RoPA.”Imports GDPR Article 30. No general equivalent was found.“DPDP does not require a RoPA, but a RoPA-style inventory helps meet several duties.”
“Data mapping is required for compliance.”Overstates. It is not named as a duty.“Data mapping is practically necessary to implement and demonstrate several duties.”
“You will be fined for not having a data map.”Penalties attach to specific duties, not to the absence of a map.“Without a map you are more likely to fail duties that carry penalties.”
“Only Significant Data Fiduciaries need one.”Section 10 does not name mapping, and other fiduciaries have the same underlying duties.“SDF duties make mapping harder to avoid, and the same duties apply in lighter form to everyone.”
“A consent banner is enough.”Consent is one control. Erasure, processors and breach response need to know where data sits.“Consent captures permission. A map shows what that permission covers.”

Not sure how mapped you are?

Score your readiness against the Act and Rules, then get matched with an implementation partner who can own the mapping work. Prefer to talk scope first? See data mapping services.

FAQ

Frequently asked questions: is data mapping mandatory under the DPDP Act?

Is data mapping mandatory under the DPDP Act?

No. The Act does not name data mapping, a data inventory or a register of processing as an obligation. However, duties such as the Section 11(1) summary of data and sharing, erasure under Section 8(7), processor control under Section 8(1) and breach intimation under Section 8(6) are hard to meet reliably without the information a data map holds.

Does the DPDP Act require a Record of Processing Activities (RoPA)?

No. We found no general records-of-processing requirement for ordinary Data Fiduciaries. GDPR Article 30 has one; the DPDP Act does not. A RoPA-style inventory is a useful format, but it should not be described as a DPDP legal requirement.

Which DPDP Act sections make data mapping necessary in practice?

Section 11(1) is the closest, because it gives a Data Principal a right to a summary of data and processing and a list of those it was shared with. Sections 8(1), 8(2), 8(5), 8(6), 8(7), 6(6), 6(10) and 12 are also much easier to meet and demonstrate with a maintained inventory.

Can a Data Fiduciary be penalised for not having a data map?

Not for the absence of a map as such. The Schedule attaches penalties to breaches of specific provisions, for example up to Rs 250 crore for failing to take reasonable security safeguards. Having no map makes it more likely you fail such a duty and harder to show the steps you took.

Do small businesses and startups need data mapping under the DPDP Act?

The Act does not exempt small businesses from the underlying duties, and it does not prescribe how much mapping they need. A simple one-page register of purposes, systems, vendors and retention is a proportionate starting point.

Do Significant Data Fiduciaries (SDFs) have to maintain a data map?

Not by name. Section 10(2) requires a notified Significant Data Fiduciary to appoint a Data Protection Officer and an independent data auditor and to undertake periodic Data Protection Impact Assessments and audits. Those tasks are much easier with a current inventory.

Do the DPDP Rules 2025 require data mapping or a data inventory?

We have not relied on any rule as imposing a data mapping or RoPA duty. The Rules cover notices, breach intimation, retention and erasure details, Consent Managers and Significant Data Fiduciary measures. Confirm exact rule wording against the Gazette text before citing it.

Is a spreadsheet enough for a DPDP Act data map?

For many organisations, yes. What matters is that it names an owner for each activity, is verified against real systems and vendors, and is reviewed when something changes. Move to a tool when the volume of systems or change makes a spreadsheet unreliable.

How should I describe data mapping in a policy or board paper?

Use wording such as: “Data mapping is not an express obligation under the DPDP Act, but it is a practical control that supports consent, processor oversight, retention and erasure, rights handling and breach response.” Have counsel confirm it for your own context.

Related

Continue the data mapping collection

Go to the full method, the legal text and the practical tools. When you are ready to move from records to working controls, see the DPDP implementation framework.

Sources

Primary sources and regulatory references

  1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India, 11 August 2023. Sections 5, 6, 8, 9, 10, 11, 12 and 33 and the Schedule are cited here.
  2. The Digital Personal Data Protection Rules, 2025, notified 13 November 2025 (G.S.R. 846(E)), Gazette of India. See our DPDP Rules 2025 explainer.
  3. Regulation (EU) 2016/679 (GDPR), Article 30, for the comparison only.
  4. Our complete data mapping guide and section-by-section Act pages.
About this article. Prepared by the DPDPActIndia editorial team under our editorial policy. It explains the Act and Rules in general terms and is not legal advice (disclaimer). The strength-of-link grading and depth guidance are editorial judgment. Rule references and commencement dates should be confirmed against the Gazette text before you rely on them. Spotted an error? Tell us.