Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Data mapping collection · Trace the data

Data Flow and Processor Mapping Under the DPDP Act: How to Map Where Personal Data Goes

Your personal data inventory says what you hold. This guide shows the next step: following that data from the moment you collect it, through your systems and people, to every Data Processor and other recipient, and on to storage, retention and erasure. It includes a worked example and a free Excel worksheet, sent after a short form.

By the DPDPActIndia editorial team · Last updated 4 October 2026 · About 28 minute read · Checked against the Act text and the DPDP Rules, 2025 · Editorial policy

In short

A data flow map shows how personal data moves for one processing activity, from collection to erasure. A processor register is the separate list of third parties that handle personal data on your behalf. Build both from your personal data inventory. The inventory says what exists, the flow map says how it moves, and the register says who handles it for you. Record each move as one row, and join the three documents with an activity ID.

  • What the Act says: we found no provision in the DPDP Act or the DPDP Rules, 2025 that requires a data flow map or a processor register. They help you meet duties the Act does contain, such as contracts with processors, security, breach response and erasure.
  • The method: eight stages, from collection point to erasure, one row per hop, with every third party classified.
  • Free tool: an Excel worksheet with a flow map, a processor register, a filled example and gap flags.
Phase 1
Trace
Pick the activities. Follow the data from each entry point.
Phase 3
Check and use
Trace a real record, fix the gaps, then use the map for breach, rights and erasure work.
In this article
  1. The basics
  2. Inventory vs flow map vs processor register
  3. Does the DPDP Act require them?
  4. The method
  5. The 8-stage data flow model
  6. Worked example: an online store order
  7. Data Processor or other recipient?
  8. How to map flows and processors in 6 steps
  9. The tools
  10. Free Data Flow and Processor Worksheet
  11. What to check in a processor contract
  12. Hops that leave India
  13. Use it and keep it
  14. Put the map to work
  15. Keep it current
  16. 10 mistakes and fixes
  17. FAQ
  18. Related resources
  19. Primary sources

The basics

Data inventory vs data flow map vs processor register: three documents people mix up

The inventory lists what personal data you hold. The flow map shows how it moves. The processor register lists who handles it for you. Keep them as three linked views of the same facts, joined by an activity ID such as PA-001.

The three documents compared
DocumentQuestion it answersOne row isUsual ownerExample row
Personal data inventoryWhat personal data do we hold, why, and on what basis?One processing activityPrivacy or compliance lead, with business ownersPA-001 Order fulfilment
Data flow mapWhere does the data of this activity travel, from collection to erasure?One hop between two pointsProcess owner, with ITF-004 Operations dashboard to the email platform
Processor registerWhich third parties process personal data on our behalf, and under what contract?One third partyProcurement or the vendor owner, with complianceP-002 Email and SMS platform
How they fit together

Start from the inventory, because it gives you the activities and the purposes. The flow map then follows one activity at a time. Every hop that leaves your organisation adds or updates a row in the processor register. The personal data inventory guide shows the first document in detail.

People also ask where the Record of Processing Activities (RoPA) fits. RoPA is a GDPR term from Article 30. The DPDP Act has no equivalent duty. If you want a RoPA-style document, build it as a view of the inventory. Our guide on data mapping vs data inventory vs RoPA explains the terms.

Which guide in this collection answers which question
Your questionRead
Is data mapping required by the DPDP Act?Is data mapping mandatory under the DPDP Act?
What is the difference between the terms?Data mapping vs data inventory vs RoPA
How do we run the whole exercise across teams?How to conduct a data mapping exercise
What do we record for each activity?Personal data inventory under the DPDP Act
How does the data move, and who handles it?This guide

The basics

Does the DPDP Act require a data flow map or a processor register? What the law says

No provision of the DPDP Act or the DPDP Rules, 2025 that we found requires a Data Fiduciary to keep a data flow map or a processor register. But the Act makes you responsible for what your Data Processors do, and several duties are hard to meet without knowing where the data goes.

Legal position

Treat both documents as practical compliance infrastructure, not statutory forms. The right-hand column below is guidance on how each document helps, not a legal requirement. See is data mapping mandatory under the DPDP Act? for the full analysis.

Provisions of the Act and Rules that depend on knowing where data goes
ProvisionWhat it says, in shortHow the map or register helps
Section 2, “Data Processor”Any person who processes personal data on behalf of a Data Fiduciary.Decides who belongs in the processor register.
Section 2, “processing”Includes operations such as collection, storage, use, sharing, disclosure by transmission, restriction and erasure.Each hop on the map is an act of processing.
Section 8(1)The Data Fiduciary is responsible for complying with the Act for processing it undertakes or that a Data Processor undertakes on its behalf.The register shows whom you answer for.
Section 8(2)A Data Processor may be engaged to process personal data for any activity related to offering goods or services to Data Principals only under a valid contract.The “Contract in place” column.
Section 8(5) and Rule 6(1)Reasonable security safeguards. Rule 6(1) lists measures such as access control, logging and monitoring, backups, keeping logs and personal data for one year, and appropriate provisions in the contract with a Data Processor (clause (f)).The “Safeguards noted” and “Security terms in contract” columns.
Section 8(6) and Rule 7On a personal data breach, intimate the Board and each affected Data Principal. Rule 7(2) requires detailed information to the Board within 72 hours, or a longer period the Board allows.Shows which systems and processors to check first.
Section 8(7)Erase personal data when consent is withdrawn or the purpose is no longer served, unless law requires retention, and cause the Data Processor to erase data made available to it.The erasure leg and the processor erasure terms.
Section 11(1)A Data Principal can ask for a summary of the personal data being processed and the processing activities, and the identities of the other Data Fiduciaries and Data Processors it has been shared with.The recipient and processor lists answer this.
Section 16(1) and Rule 15The Central Government may restrict transfers to countries it notifies. Rule 15 says a Data Fiduciary must meet any requirements the Government specifies by order about making personal data available to a foreign State or its agencies.The “Location” column.

The method

The 8-stage data flow model: from collection point to erasure

Follow personal data through eight stages: collection point, system, internal use, Data Processor, other recipient, storage, retention and erasure. Record each move between two points as one row. The stages are a checklist of questions, not a straight line: data can be stored at every stage and can pass through several processors.

1Collection pointWhere data enters.Form, app, call, paper
2System or applicationWhere it lands first.CRM, store, HRMS
3Internal useWho and what uses it.Teams, jobs, reports
4Data ProcessorWho handles it for you.Hosting, email, support
5Other recipientWho gets it for their own purposes.Banks, partners, authorities
6StorageWhere copies rest.Databases, backups, files
7RetentionHow long, and what starts the clock.Period or trigger
8ErasureHow it is deleted, and who confirms.Including processors
What to record and ask at each stage
StageWhat to recordQuestions to askWhere the answer usually sits
1 Collection pointThe channel, who the data is about, the data collected and the notice shown.Where does data enter? What notice or consent screen appears? Do we collect anything the form does not need?Web and app forms, call scripts, onboarding paper, partner feeds.
2 System or applicationSystem name, owner, fields held, hosting.Which system stores it first? Does it copy data to other systems?IT asset list, single sign-on app list, database design.
3 Internal useTeams, roles, jobs, reports and exports.Who can see it? Do people copy it into spreadsheets, email or chat?Access lists, role matrices, interviews.
4 Data ProcessorVendor, service, data reached, contract status, location.Who handles data on our behalf? Who do they use in turn?Accounts payable list, API keys, procurement files.
5 Other recipientWho receives data for their own purposes, and why.Do they decide why and how to use it? Is the sharing described in the notice?Partner agreements, regulatory filings, integration list.
6 StorageEvery place a copy rests, including backups and logs.Where are the copies, the backups and the exports?Architecture notes, backup policy, interviews about spreadsheets and laptops.
7 RetentionThe period or the trigger that starts the clock.Is there one period per activity? Do backups follow it?Retention schedule, legal advice, system settings. See the retention fields.
8 ErasureHow data is deleted or anonymised, and who confirms it.Is it automatic or manual? How do we make processors erase (Section 8(7))?Deletion jobs, processor confirmations, tickets.

The method

Worked example: an online store order, mapped from checkout to erasure

Here is one activity, order fulfilment at a fictional online store, mapped as nine hops. Reading the map takes a minute. In the worksheet, three hops and three of the four third parties get a gap flag: an unknown hosting location, a courier and a payment gateway whose roles are not yet classified, and vendors whose security terms are not confirmed.

Illustrative only

The store, vendors and retention wording are fictional. Retention periods are placeholders, not recommendations. Real periods depend on your legal requirements.

  1. F-001 · 1 Collection pointCustomer to Checkout form on the website. Data: Name, address, phone, email, items ordered. Method: Web form. Receiver: Internal. Location: India. Retention: Not stored at this point. Erasure: Not applicable.
  2. F-002 · 2 System or applicationCheckout form to Order database on a cloud server. Data: Name, address, phone, email, items ordered. Method: API. Receiver: Data Processor (P-001). Location: India. Retention: Set in F-008. Erasure: Monthly deletion job (see F-009).
  3. F-003 · 3 Internal useOrder database to Operations team dashboard. Data: Name, address, phone, items ordered. Method: Database sync. Receiver: Internal. Location: India. Retention: Not copied out of the dashboard. Erasure: Not applicable.
  4. F-004 · 4 Data processorOperations dashboard to Email and SMS platform. Data: Name, email, phone, order status. Method: API. Receiver: Data Processor (P-002). Location: Unknown. Retention: Unknown. Erasure: Unknown. Gap flag: Location unknown.
  5. F-005 · 5 Other recipientOperations dashboard to Courier partner. Data: Name, address, phone. Method: File transfer. Receiver: To confirm. Location: India. Retention: Courier decides. Erasure: Courier decides. Gap flag: Role to confirm.
  6. F-006 · 5 Other recipientCheckout form to Payment gateway. Data: Name, email, order amount. Method: API. Receiver: To confirm. Location: India. Retention: Gateway decides. Erasure: Gateway decides. Gap flag: Role to confirm.
  7. F-007 · 6 StorageOrder database to Nightly backup in cloud storage. Data: All order data. Method: Database sync. Receiver: Data Processor (P-001). Location: India. Retention: Backups kept for 35 days (placeholder). Erasure: Backups expire automatically.
  8. F-008 · 7 RetentionOrder database to Order record kept after delivery. Data: Invoice and order data. Method: Database sync. Receiver: Internal. Location: India. Retention: Period to be set by Finance after checking legal requirements (placeholder). Erasure: See F-009.
  9. F-009 · 8 ErasureOrder database to Erased or anonymised. Data: Order data past its retention period. Method: Database sync. Receiver: Data Processor (P-001). Location: India. Retention: Not applicable. Erasure: Monthly deletion job; ask the host to delete backups and confirm.
What the map shows at a glance

Three hops are flagged: the email platform (role known, location unknown), and the courier and the payment gateway (roles to confirm). The erasure hop depends on the cloud host deleting backups, so the store needs that written into its contract and a confirmation on file.

The method

Is it a Data Processor or another recipient? A five-question test

A Data Processor handles personal data on your behalf. A recipient that decides its own purposes is not your processor under the Section 2 definitions, and may be a Data Fiduciary in its own right. Classify every third party before you decide which contract and checks apply.

  1. Who decides why the data is used? If the third party only does what you ask, it points to a processor. If it decides its own purposes, it points to a Data Fiduciary.
  2. Who decides the means? Tools, storage, how long to keep it, who else sees it.
  3. Does it use the data for its own products, analytics or marketing? If yes, it is not acting only for you.
  4. Does a law give it its own duties over the data? A regulated bank or an authority acting under a legal power is an example.
  5. What does the contract say? The contract does not decide the role on its own, but it is strong evidence of what each side agreed.
Typical cases (our reading, not legal advice)
Third partyUsual classificationWhy
Cloud hosting and backupData ProcessorStores and protects data as you instruct.
Email or SMS sending platformData ProcessorSends your messages to your list. Check its own use of the data.
CRM, helpdesk or HR software you configureData ProcessorYou decide what goes in and how it is used.
Payroll outsourcing partnerData ProcessorRuns payroll for you under your instructions.
Courier or logistics partnerTo confirmMay follow your instructions only, or may keep and use delivery data for its own purposes. Read the agreement.
Payment gateway, bank or card networkTo confirmOften act under financial regulation with their own duties. Classify case by case.
Advertising and analytics platformsTo confirmDepends on the settings and terms. If the platform uses the data for its own purposes, it is not acting only for you.
Authority receiving data under a legal requirementNot your processorIt receives data under a legal power. Record it as a recipient.
Joint decisions

The Act defines a Data Fiduciary as a person who, alone or in conjunction with other persons, determines the purpose and means of processing. The Act has no separate “joint controller” term. If you and a partner decide purposes together, take legal advice on how your duties divide, and record the arrangement in the map.

The method

How to map data flows and processors in 6 steps

Pick the activities, trace the entry points, follow the data, name every processor and recipient, record storage, retention and erasure, then verify against a real record. Each step names who is involved and what you should have at the end. For the wider cross-team method, see how to conduct a data mapping exercise.

1Pick the activitiesStart from the inventory.Output: priority list
2Trace entry pointsEvery channel data comes in by.Output: collection points
3Follow the dataAsk “where next?” at each hop.Output: list of hops
4Name every third partyClassify and add to the register.Output: processor register
5Record the lifecycleStorage, retention, erasure.Output: lifecycle columns
6Verify and approveTrace a real record.Output: signed-off map

1Pick the activities and set the scope

What to do
Take the activities from your personal data inventory. Start with the five that involve the most people or the most sensitive data, such as customer onboarding, payroll, marketing, support and anything involving children. Map one activity at a time.
Who to involve
The compliance lead and one business owner for each activity.
Watch for
Trying to map the whole company at once. A map nobody finishes is worth less than five finished maps.
Output
A short list of activities with their IDs.

2Trace every entry point

What to do
List every way data enters the activity: web forms, apps, calls, email, WhatsApp, paper forms, uploads, partner feeds and imports from other systems. Note the notice or consent screen shown at each one.
Who to involve
The business owner and the front-line staff who handle the data.
Watch for
Channels that nobody calls a system: shared inboxes, chat groups, call recordings and paper files.
Output
The list of collection points, with the notice shown at each.

3Follow the data through systems and people

What to do
For each entry point, ask “where does it go next?” and write one row for each hop: from, to, the data moved, and how it moves. Include exports to spreadsheets, forwards by email and copies pasted into chat.
Who to involve
The process owner and IT.
Watch for
Stopping at the edge of the main system. Many real flows happen when a person downloads a report.
Output
An ordered list of hops for the activity.

4Name every Data Processor and recipient

What to do
At each hop that leaves your organisation, name the third party and classify it with the five-question test. Add each to the processor register with its contract status and location. Cross-check the register against the accounts payable list and the single sign-on app list to find vendors you forgot.
Who to involve
Procurement, finance, IT and legal.
Watch for
Free tools on personal accounts, plug-ins, and vendors paid for by another team.
Output
A processor register and a list of other recipients.

5Record storage, retention and erasure

What to do
For each place data rests, note where the copies and backups live, what starts the retention clock, how the data is erased, and how each processor confirms erasure.
Who to involve
IT and the record owners.
Watch for
Backups, logs and data left behind with a vendor you stopped using.
Output
The storage, retention and erasure columns completed for every hop.

6Verify, close the gaps and approve

What to do
Trace one real record from collection to its last copy, and check the vendors against the register. Read the gap flags: no confirmed contract, unknown location, unclear role. Give each gap an owner and a date. Then have the activity owner sign off and date the map.
Who to involve
The compliance lead and the activity owner.
Watch for
Treating an interview as proof. Prefer a configuration screen, a contract or a traced record.
Output
A signed-off map and a dated gap list.

The tools

Free Data Flow and Processor Worksheet: columns, example and download

The worksheet is a free Excel file with a flow map sheet, a processor register sheet, a filled example, a summary and drop-down lists. Enter your details on the download page to get the link.

DPDP Act Data Flow and Processor Worksheet 2026

Excel (.xlsx), about 23 KB. Sheets: Start here, Flow map (60 rows), Processors (30 rows), Example, Summary, Lists. Gap flags are formulas. The example data is fictional.

The worksheet uses the same activity IDs as the Data Inventory Workbook, so the two fit together. You can also copy the columns below into any spreadsheet.

Flow map columns (16 fields and a gap flag)

Flow map worksheet: 16 fields
FieldWhat to enterWhy it matters
Flow IDA unique ID for the hop, such as F-001.Lets you point to one hop in a gap log or breach check.
Activity IDThe ID of the processing activity from your personal data inventory, such as PA-001.Joins the flow map to the inventory.
StagePick one of the eight stages: collection point, system, internal use, data processor, other recipient, storage, retention, erasure.Keeps every map in the same order.
FromWhere the data leaves: a person, form, system or team.Shows the start of the hop.
ToWhere the data arrives: a system, team, vendor or the end of life.Shows the end of the hop.
Personal data movedThe categories moved in this hop, for example name, phone, address, order details.Section 2 defines processing to include sharing and disclosure, so each hop is processing.
MethodHow it moves: web form, API, file transfer, email, manual upload, paper, phone or database sync.Manual methods (email, spreadsheets) are where leaks often start.
Purpose servedThe specified purpose for this hop, in the same words as the inventory.Keeps the hop tied to the purpose in the notice (Section 5).
Receiver roleInternal, Data Processor, Other recipient (own purposes), or To confirm.Decides which contract and checks apply (Sections 2 and 8).
Processor IDThe register ID, such as P-001, if the receiver is a Data Processor.Joins the hop to the processor register.
LocationIndia, Outside India or Unknown. Include where the vendor hosts the data.Section 16 and Rule 15 on transfers outside India.
Safeguards notedThe safeguards you can evidence for this hop, such as encryption in transit, access control, logging.Section 8(5) and Rule 6(1).
Retention at this pointThe retention period or trigger for the data at the destination.Sections 8(7) and 8(8); Rule 8 for named classes.
Erasure routeHow the data is erased or anonymised here and who confirms it.Section 8(7): erase, and cause the Data Processor to erase.
EvidenceHow you know: interview, architecture diagram, configuration, contract or a traced record.Separates what was seen from what was assumed.
Last verifiedThe date someone last checked this hop against the real system.Shows how fresh the map is.

Processor register columns (15 fields and a gap flag)

Processor register worksheet: 15 fields
FieldWhat to enterWhy it matters
Processor IDA unique ID such as P-001.Joins the register to the flow map.
Processor nameThe vendor or service provider.Names whom you answer for (Section 8(1)).
Service providedWhat it does for you, for example hosting, email sending, helpdesk.Helps classify the role.
Activities servedThe inventory activity IDs that use this processor.Shows how many activities depend on it.
Personal data categoriesWhat data it can reach.Scopes a breach or a rights request.
Data Principal groupsWhose data it holds: customers, employees, applicants, children.Section 9 if children are involved.
Role checkData Processor, Other Data Fiduciary, or To confirm, using the five questions.Section 2 definitions.
Contract in placeYes, No or Unknown.Section 8(2): a valid contract for activities related to offering goods or services.
Security terms in contractYes, No or Unknown. Does the contract include appropriate provisions on security safeguards?Rule 6(1)(f).
Erasure or return termsYes, No or Unknown. Will the vendor erase or return data on your instruction or at the end?Section 8(7)(b).
Breach notice duty to youYes, No or Unknown. Must the vendor tell you quickly if it has a breach?Practical: you must report breaches under Section 8(6) and Rule 7.
Sub-processors knownYes, No or Unknown. Do you know who the vendor uses?Practical: Section 8(1) keeps you responsible for processing on your behalf.
Hosting locationIndia, Outside India, Mixed or Unknown.Section 16 and Rule 15.
Internal ownerThe person who manages the vendor.Someone must act on gaps.
Last reviewedThe date of the last review.Shows how fresh the register is.

Example: the processor register for the fictional store

Processor register for the fictional store (illustrative)
IDProcessorServiceRole checkContractSecurity termsErasure termsHostingGap flag
P-001Cloud host (example)Hosting and backupsData ProcessorYesYesYesIndiaNone
P-002Email and SMS platform (example)Sends order updates and newslettersData ProcessorYesUnknownUnknownUnknownCheck contract terms
P-003Helpdesk software (example)Support tickets and chatData ProcessorUnknownUnknownNoOutside IndiaNo confirmed contract
P-004Courier partner (example)Parcel deliveryTo confirmYesUnknownUnknownIndiaRole to confirm
How the gap flags work

A gap flag is a prompt to check, not a finding of non-compliance. On the flow map, a row is flagged when a Data Processor has no Processor ID, the role is still “To confirm”, the location is unknown or blank, or the hop has not been verified. On the register, a row is flagged when the role is unconfirmed, the contract is not confirmed, the security or erasure terms are not confirmed, or the hosting location is unknown.

The tools

What to check in each Data Processor contract: the Act’s requirements and good practice

The Act says a Data Processor engaged for activities related to offering goods or services must be engaged under a valid contract (Section 8(2)), and Rule 6(1)(f) requires appropriate provisions in that contract for security safeguards. The other items below are good practice, not statutory requirements.

What the Act and Rules say

  • A valid contract with the Data Processor (Section 8(2)).
  • Appropriate security provisions in that contract (Rule 6(1)(f)).
  • You stay responsible for processing done on your behalf (Section 8(1)).
  • You must cause the processor to erase data made available to it, when erasure is due (Section 8(7)).
  • You must report a breach to the Board and each affected Data Principal (Section 8(6), Rule 7).

Good practice to ask for

  • Use of the data only on your instructions.
  • A list of the vendor’s own sub-contractors, and notice of changes.
  • A duty to tell you quickly about a breach, with a clock that lets you meet Rule 7.
  • Help with Data Principal requests.
  • Return or deletion of data at the end, confirmed in writing.
  • The locations where data is stored and accessed.
Sub-processors

We found no provision in the Act or the Rules that names sub-processors. Section 8(1) keeps you responsible for processing on your behalf, so it is sensible to ask each vendor who it uses. Record the answer in the “Sub-processors known” column.

The tools

Hops that leave India: record the location of every storage point and processor

Mark every hop and every storage point as India, Outside India or Unknown. Section 16(1) lets the Central Government restrict transfers to countries it notifies, and Rule 15 requires you to meet any requirements it specifies about making data available to a foreign State or its agencies. A map that records locations lets you check any notification quickly.

  • The Act has no blanket ban. We found no provision that bars all transfers outside India. Check the Government’s current notifications and orders before you rely on this, because they can change.
  • Other laws still apply. Section 16(2) says nothing in the section restricts any other law that gives a higher degree of protection or restricts transfers. Sector regulators may have their own rules on where certain data is stored.
  • Find the “Unknown” entries. Ask each vendor where it stores data and where its staff can access it from. Remote access by a vendor’s staff abroad may matter, so take advice on how it should be treated.

Use it and keep it

Put the map to work: breach response, rights requests, erasure and vendor reviews

A finished map answers the first questions you will be asked in a breach, a Data Principal request or a vendor review. It is the lookup table for your other compliance tasks.

Tasks the map speeds up
TaskQuestion the map answersWhere to look
Breach response (Section 8(6), Rule 7)Which systems and processors held this data? Whom do we call first? Which groups of Data Principals are affected?Storage hops, processor register, activity data categories.
Access request (Section 11)Which other Data Fiduciaries and Data Processors has this person’s data been shared with?Recipient and processor lists.
Correction or erasure (Sections 8(7), 12)Which copies must change, including those held by processors?Storage hops, erasure route.
Consent withdrawal (Section 6(6))Where must processing stop, and which processors must stop too?Flow hops, Processor IDs. See consent withdrawal under the DPDP Act.
Notice review (Section 5)Does the notice match what we collect and why?Collection hops, purpose column.
New vendor or toolDoes it add a hop, a new location or a new category of data?Update the map before signing.

Use it and keep it

Keep it current: when to redraw the map

Update the map when anything that touches personal data changes. The review rhythm below is our suggestion, not a legal requirement.

  1. On changeNew vendor, tool or feature. Add the hops and the register row before the change goes live.
  2. On changeA new field on a form, or a new data source. Update the data moved and the notice.
  3. On vendor noticeA vendor changes location or sub-contractors. Update the register and re-check the contract.
  4. On eventA breach, a near miss or a complaint. Check whether the map was right and fix what it missed.
  5. On contract renewalReview the clauses. Check security, erasure and breach terms against the register.
  6. YearlyFull re-verification. Trace one record per activity and compare the register with the accounts payable and sign-on lists. Review high-risk activities more often.

Use it and keep it

10 data flow mapping mistakes and how to fix them

Most failed maps are too big, too vague or never updated. These ten are the usual causes.

Common mistakes and fixes
MistakeWhy it hurtsFix
1. Mapping systems, not activitiesPurpose and basis are lost.Start from the activity IDs in the inventory.
2. One giant company diagramNobody can read or update it.One map per activity.
3. Writing only the vendor’s nameYou cannot tell what data it reaches.Record the service, data, contract and location.
4. Calling every third party a processorThe wrong contract and checks get applied.Use the five-question test.
5. Forgetting spreadsheets, email and chatReal flows go unrecorded.Ask where reports and exports are sent.
6. Ignoring backups and logsErasure is incomplete.Record every copy and its life.
7. Trusting that a contract existsThe clauses may be missing.Check security, erasure and breach terms.
8. No ownerGaps stay open.Name an owner for each map and each processor.
9. Never updatingThe map drifts from reality.Use the change triggers above.
10. Copying a template without checkingIt describes someone else’s business.Trace a real record before sign-off.

Want a second pair of eyes on your map?

We can review your flow maps and processor register, or connect you with an implementation partner. See our data mapping services.

FAQ

Frequently asked questions: data flow and processor mapping under the DPDP Act

What is data flow mapping?

Data flow mapping is the practice of recording how personal data moves for a processing activity: where it is collected, which systems and people use it, which third parties receive it, where it is stored, how long it is kept and how it is erased. The result is a list or diagram of hops between points.

Is data flow mapping mandatory under the DPDP Act?

We found no provision in the DPDP Act or the DPDP Rules, 2025 that requires a Data Fiduciary to keep a data flow map. It is practical compliance infrastructure that helps with processor contracts, security safeguards, breach response, erasure and Data Principal requests. See is data mapping mandatory under the DPDP Act.

What is the difference between a data inventory and a data flow map?

A data inventory lists what personal data you hold, one row per processing activity, with its purpose and basis. A data flow map follows one activity and shows how its data moves, one row per hop. The inventory is the starting point for the map. See the personal data inventory guide.

Who is a Data Processor under the DPDP Act?

Section 2 defines a Data Processor as any person who processes personal data on behalf of a Data Fiduciary. A third party that decides its own purposes for the data is not acting on your behalf and may be a Data Fiduciary itself. Use the five-question test above, and take advice on unclear cases. See the Data Processor glossary entry.

Do I need a contract with every Data Processor?

Section 8(2) says a Data Fiduciary may engage a Data Processor to process personal data on its behalf for any activity related to offering goods or services to Data Principals only under a valid contract. Rule 6(1)(f) requires appropriate security provisions in that contract. Even where an activity falls outside that wording, Section 8(1) keeps you responsible for processing on your behalf, so a written contract is the safe course.

Do I need a register of Data Processors?

We found no provision in the Act or the Rules that requires one. In practice you cannot show that each processor has a valid contract, or answer a Section 11 request about who has your data, without a list. A processor register is the simplest way to keep that list.

Is a courier or payment gateway a Data Processor?

It depends. A courier that only follows your delivery instructions may be a processor. One that keeps and uses delivery data for its own purposes may be a Data Fiduciary. Payment gateways and banks often act under financial regulation with their own duties. Mark them “To confirm”, read the agreement and take advice.

Does the DPDP Act mention sub-processors?

We found no provision in the Act or the Rules that names sub-processors. Section 8(1) makes the Data Fiduciary responsible for processing done on its behalf by a Data Processor, so ask your vendors who they use and record the answer.

How do I handle data that goes outside India?

Record the location of every storage point and processor. Section 16(1) allows the Central Government to restrict transfers to notified countries, and Rule 15 requires you to meet any requirements it specifies about making data available to a foreign State or its agencies. Check current notifications before you rely on any assumption, and note that other laws with higher protection continue to apply under Section 16(2).

How often should I update a data flow map?

Update it whenever a vendor, tool, form or data field changes, after a breach or near miss, and at contract renewal. Re-verify each map at least once a year. The rhythm is our suggestion, not a legal requirement.

What tools do I need to map data flows?

A spreadsheet is enough to start. Our free worksheet gives you a flow map sheet, a processor register and drop-down lists. Specialist discovery tools can help in large environments, but they do not replace interviews and a traced record, because they cannot tell you the purpose or the contract position.

Related

Continue the data mapping collection

Go to the full method, the legal text and the practical tools. When you are ready to move from records to working controls, see the DPDP implementation framework.

Sources

Primary sources and regulatory references

  1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India, 11 August 2023. Sections 2, 8, 11 and 16 are cited here.
  2. The Digital Personal Data Protection Rules, 2025, notified 13 November 2025 (G.S.R. 846(E)). Rules 6, 7 and 15 are cited here. See our DPDP Rules 2025 explainer.
  3. Our complete data mapping guide and section-by-section Act pages.
About this article. Prepared by the DPDPActIndia editorial team under our editorial policy. It explains the Act and Rules in general terms and is not legal advice (disclaimer). The eight-stage model, the worksheet fields, the role test, the contract good-practice list and the review rhythm are editorial guidance, not statutory requirements. Classifications in the role table are our reading and depend on the facts. Check current notifications on transfers outside India before relying on this page. Spotted an error? Tell us.