Data mapping collection · Preparing for incidents
In the first hours of a breach, the questions are always the same: which systems, what data, which people, which vendors, who to call. This guide shows how to have those answers ready. It includes a free Excel worksheet.
In short
A breach-ready data map answers the scoping questions before the incident: which systems, what personal data, roughly how many people, how to reach them, which processors, where the logs are and who to call. The Act does not require a data map. It does require reasonable security safeguards and, from 13 May 2027, intimation of a breach.
The basics
It means keeping your inventory, flow map and processor register in a form that a response team can use in the first hours of an incident. The question it answers is: if this system were compromised today, what would we need to know?
The personal data inventory says what data each system holds. The flow and processor map says where copies went and who holds them. The request-ready lookup already records contacts that help here too. Readiness adds a few fields: how many people, how to reach them, where the logs are, how to contain and recover, and who to call out of hours.
It is not a reporting guide. For who notifies whom, what the notices say and when they are due, follow the guide to reporting a DPDP Act data breach. See also Section 8 and the glossary entries on personal data breach and breach notification.
The law
The Act asks you to prevent breaches and, if one happens, to intimate the Board and each affected Data Principal. The map has to be able to supply the facts both tasks need. The table paraphrases the provisions. Penalties are covered in the reporting guide.
| Provision | In plain words | What the map must supply |
|---|---|---|
| Section 2 Personal data breach | Unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. | Which systems and data could be involved. |
| Section 8(1) Responsibility | The Data Fiduciary remains responsible for compliance, including for processing by a Data Processor on its behalf. | A processor register with real contacts. |
| Section 8(5) and Rule 6(1) Safeguards | Reasonable security safeguards to prevent a breach, including for processing by a processor. Rule 6(1) refers to encryption or masking, access control, logs with monitoring and review, backups for continued processing, keeping logs and personal data for one year unless a law requires otherwise, and security terms in processor contracts. | Where each control sits, per system. |
| Section 8(6) and Rule 7(1) Data Principals | Intimation to each affected Data Principal, in a concise, clear and plain manner, through her user account or a mode of communication she registered with you, with prescribed content. | Who is affected and how to reach them. |
| Rule 7(2) Board | Intimation to the Board without delay, then detailed information within seventy-two hours of becoming aware, or a longer period the Board allows. | The facts for both submissions. |
Commencement. Section 8 and Rules 6 and 7 commence on 13 May 2027. Time. “Without delay” is not a fixed number of hours, and “becoming aware” is not defined. The map. We found no provision that requires a data map for breach response. This is practice, not a legal duty.
The method
Every incident follows six links: incident, systems, data, people, processors and notices. The map supplies links two to five. A missing link is a gap, and gaps are what slow the first hours.
Use the map
Ten questions come up in almost every incident. If the map answers them, the team spends its first hours acting, not asking.
| Question | Where the answer sits | What a blank costs you |
|---|---|---|
| 1. Which systems are involved? | Systems sheet: system and owner | Time spent asking around. |
| 2. What personal data do they hold? | Personal data held, joined to the inventory | You cannot judge the likely consequences. |
| 3. Is children’s data involved? | Children’s data flag | You may miss a group that Section 9 treats separately. |
| 4. Roughly how many people? | Data Principals estimate | You cannot size the response or the notices. |
| 5. How do we reach them? | How to reach them | Rule 7(1) refers to the user account or a registered mode of communication. No route, no notice. |
| 6. Who else holds a copy? | Processor IDs, copies and exports | A copy at a vendor or in a shared drive is missed. |
| 7. Where are the logs? | Where the logs are | You cannot establish the timing or the extent. |
| 8. How do we stop it? | How to contain | Containment waits while someone looks for the lever. |
| 9. How do we recover? | How to recover | Nobody knows who can restore. |
| 10. Who do we call? | Owner, out-of-hours contact, processor contact | Nobody answers when it matters. |
Use the map
Rule 7 asks for facts the map already holds: how far the breach reached, what you did, and how to reach the people affected. The map does not write the notice. It supplies the raw material.
| What the Rules ask for | Where the facts come from |
|---|---|
| Rule 7(1): a description of the breach, including its nature, extent and timing | Extent: systems, data held and people. Timing: the logs. |
| Rule 7(1): the consequences likely to arise for the person | Data held and the children’s data flag. |
| Rule 7(1): the measures taken to mitigate the risk | How to contain and how to recover. |
| Rule 7(1): safety measures the person can take | The data exposed decides the advice. Exposed log-ins call for different steps than exposed addresses. |
| Rule 7(1): contact details of a person who can respond, and delivery through the user account or a registered mode of communication | The system owner, the named response contact and how to reach the people. |
| Rule 7(2): the Board intimation and the detailed information | Systems, data and people for the first. Logs, causes, mitigation, remedial steps and a report on the notices sent for the second. |
This table shows where the facts sit and does not replace the Rule. For the full content, order and timing, follow the breach reporting guide.
Use the map
In a rehearsal, a staff member shares a customer export folder by public link. The map answers most scoping questions and the team finds three gaps. Scoping took 40 minutes (drill D-002 in the worksheet).
The team opens the Systems sheet and finds S-005, the shared drive, which holds exports of the order database (S-002) and the email platform (S-003). The store and every vendor here are fictional.
| Question | What the map said | Gap |
|---|---|---|
| Which system? | S-005, shared drive. Exports of S-002 and S-003. | No owner recorded. |
| What data? | Name, email, phone and order counts. No card numbers. | None. |
| How many people? | S-002 holds about 21,000 customers and S-003 about 9,500 subscribers. The export’s own count was not recorded. | No population estimate for S-005. |
| Children? | No, for both source systems. | None. |
| How to reach them? | Registered email, as recorded for S-002 and S-003. | No route recorded for S-005 itself. |
| Who else holds it? | P-004, the file storage vendor. It can supply the sharing log. | The contract has no incident terms. |
| Logs and containment? | Sharing log in the drive. Remove the shared link and change folder permissions. | Log retention not recorded. |
The numbers are invented. They are not a conclusion about any real business.
Use the map
Three things decide how fast you can scope a breach that touches a vendor: a person to call, access to the logs and a way to restore.
Use the map
Most delay in the first hours comes from a handful of gaps in the map, not from the incident itself.
| Gap | What happens | Fix |
|---|---|---|
| A system is missing from the map | The scope is understated and a later discovery reopens the incident. | Reconcile the map with IT and finance software lists each quarter. |
| No count of people | You cannot size the notices. | Record a rough count or range per system. |
| No way to reach people | Notices cannot be sent through the account or a registered mode of communication. | Record the route for each system and note records that lack one. |
| Logs not found | Timing and extent are guesswork. | Record where the logs are, who pulls them and how long they last. |
| No known way to contain | Access stays open while someone looks for the lever. | Record the step and who can take it. |
| No out-of-hours contact, or a vendor with only a support queue | Nobody picks up on a Sunday night. | Name a person, a backup and a vendor escalation route. |
| Stale rows | The map describes last year’s systems and vendors. | Record a verified date and recheck when a vendor, tool or team changes. |
Build and use it
The worksheet has a Systems sheet for the scoping facts, a Processors sheet for vendor contacts and a Drills sheet for rehearsals, with examples, a summary and lists. Enter your details on the download page to get the link.
Excel (.xlsx), about 27 KB. Sheets: Start here, Systems, Processors, Drills, three example sheets, Summary and Lists. Gap flags are formulas. The examples are fictional.
The Systems sheet records the data held, a rough head count, how to reach people, where the logs are, how to contain and recover, the owner and an out-of-hours contact. The Processors sheet records the contact, whether the contract covers incidents, whether logs are available and whether sub-processors are known. The Drills sheet logs each rehearsal.
A flag shows the first gap in a row. It is a prompt to check, not a finding of non-compliance. Minutes to scope is your own measure, not a legal time. The file holds out-of-hours contact details, so limit who can open it.
Build and use it
Add the breach fields, record how to reach people, line up processors, logs and recovery, name owners, rehearse, then close the gaps.
Build and use it
Most failures come from mapping too little, storing the map in the wrong place or never testing it.
| Mistake | Why it hurts | Fix |
|---|---|---|
| 1. Treating the map as the response plan | A map holds facts, not roles or decisions. | Keep the map and the workflow separate, and link them. |
| 2. Mapping only production systems | Exports, shared drives, mailboxes and laptops hold personal data too. | Record copies and exports against each system. |
| 3. Leaving out how to reach people | A count without a route cannot become a notice. | Record the route for every system that holds people’s data. |
| 4. Listing a team mailbox as the contact | Nobody answers at night or on holidays. | Name a person, a backup and an out-of-hours number. |
| 5. Assuming a processor will tell you | Section 8(1) keeps you responsible, and a vendor may not volunteer what it knows. | Get incident terms in the contract and a named contact. |
| 6. Keeping the only copy on the affected system | If the system is down or locked, so is the map. | Keep a restricted offline copy for the response team. |
| 7. Never testing it | Gaps appear for the first time during a real incident. | Rehearse, log the drill and fix what it finds. |
Questions
No. We found no provision that requires a data map for breach response. The Act does require reasonable security safeguards (Section 8(5)) and, from 13 May 2027, intimation of a breach (Section 8(6) and Rule 7). A map is the practical way to prepare for both.
Section 2 defines it as unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. Whether an event meets that definition is an assessment step in the breach reporting guide.
It supplies the facts the notices rest on: which systems and data, roughly how many people, how to reach them, which processors and where the logs are. It does not decide what to send or when. The reporting guide covers that.
Which systems, what personal data, whether children’s data is involved, roughly how many people, how to reach them, which processors, where the logs are, how to contain and recover, and who to call. Each is a column on the worksheet.
Start from the affected systems, then use the head count and reach route recorded for each. Rule 7(1) refers to the user account or a mode of communication the person registered with you. We found no express rule for people with no registered route, so record those cases in advance and take advice.
Section 8(1) keeps the Data Fiduciary responsible for compliance, including for processing by a Data Processor on its behalf. We found no general duty in Rule 7 for a processor to notify the Board. The contract sets its role, so record a named contact and incident terms.
Rule 6(1) refers to keeping logs and personal data for one year unless another law requires otherwise. Confirm the scope of that wording for your systems with a legal adviser, and record where each system’s logs sit and who can pull them.
Rule 6(1) refers to measures for continued processing, such as data backups. Record where backups are and who can restore. Backups also hold personal data, so include them in your retention and erasure plan.
We found no provision that sets a frequency. A sensible practice is yearly, after a major system or vendor change and after any real incident.
No. The plan sets roles, decisions and steps. The map holds the facts the plan needs. Keep both and link them. The reporting guide covers the workflow.
Related
Go to the full method, the legal text and the practical tools. When you are ready to move from records to working controls, see the DPDP implementation framework.
Sources
Consultant-led and partner-backed.