Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Data mapping collection · Preparing for incidents

Data Mapping for Breach Readiness Under the DPDP Act

In the first hours of a breach, the questions are always the same: which systems, what data, which people, which vendors, who to call. This guide shows how to have those answers ready. It includes a free Excel worksheet.

By the DPDPActIndia editorial team · Last updated 4 October 2026 · About 16 minute read · Checked against the Act text and the DPDP Rules, 2025 · Editorial policy

In short

A breach-ready data map answers the scoping questions before the incident: which systems, what personal data, roughly how many people, how to reach them, which processors, where the logs are and who to call. The Act does not require a data map. It does require reasonable security safeguards and, from 13 May 2027, intimation of a breach.

  • What the law says: Section 8(5) requires reasonable security safeguards. Section 8(6) and Rule 7 require intimation of a breach. Both commence on 13 May 2027.
  • What the map does not do: decide whether an event is a breach, or what to send and when. The breach reporting guide covers that.
  • The method: incident, systems, data, people, processors, notices. The map supplies the middle four.
Phase 1
Prepare
Put the breach facts in the map before anything goes wrong.
Phase 3
Improve
Update the map with what the incident exposed.
In this article
  1. The basics
  2. What is breach-ready data mapping?
  3. What the Act and Rules ask
  4. The incident-to-notice model
  5. Use the map
  6. The first-hour scoping questions
  7. From the map to the notices
  8. Worked example: an exposed export
  9. Processors, logs and recovery
  10. Where scoping stalls
  11. Build and use it
  12. The free worksheet
  13. Step-by-step implementation
  14. 7 common mistakes
  15. FAQ
  16. Related resources
  17. Primary sources

The basics

What is data mapping for breach readiness? A plain definition

It means keeping your inventory, flow map and processor register in a form that a response team can use in the first hours of an incident. The question it answers is: if this system were compromised today, what would we need to know?

The personal data inventory says what data each system holds. The flow and processor map says where copies went and who holds them. The request-ready lookup already records contacts that help here too. Readiness adds a few fields: how many people, how to reach them, where the logs are, how to contain and recover, and who to call out of hours.

What this page does not do

It is not a reporting guide. For who notifies whom, what the notices say and when they are due, follow the guide to reporting a DPDP Act data breach. See also Section 8 and the glossary entries on personal data breach and breach notification.

The law

What the DPDP Act and Rules ask after a personal data breach, and what the map must supply

The Act asks you to prevent breaches and, if one happens, to intimate the Board and each affected Data Principal. The map has to be able to supply the facts both tasks need. The table paraphrases the provisions. Penalties are covered in the reporting guide.

The provisions behind breach readiness and what the map must supply
ProvisionIn plain wordsWhat the map must supply
Section 2
Personal data breach
Unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability.Which systems and data could be involved.
Section 8(1)
Responsibility
The Data Fiduciary remains responsible for compliance, including for processing by a Data Processor on its behalf.A processor register with real contacts.
Section 8(5) and Rule 6(1)
Safeguards
Reasonable security safeguards to prevent a breach, including for processing by a processor. Rule 6(1) refers to encryption or masking, access control, logs with monitoring and review, backups for continued processing, keeping logs and personal data for one year unless a law requires otherwise, and security terms in processor contracts.Where each control sits, per system.
Section 8(6) and Rule 7(1)
Data Principals
Intimation to each affected Data Principal, in a concise, clear and plain manner, through her user account or a mode of communication she registered with you, with prescribed content.Who is affected and how to reach them.
Rule 7(2)
Board
Intimation to the Board without delay, then detailed information within seventy-two hours of becoming aware, or a longer period the Board allows.The facts for both submissions.
Three cautions

Commencement. Section 8 and Rules 6 and 7 commence on 13 May 2027. Time. “Without delay” is not a fixed number of hours, and “becoming aware” is not defined. The map. We found no provision that requires a data map for breach response. This is practice, not a legal duty.

The method

The incident-to-notice model: six links from first alert to evidence

Every incident follows six links: incident, systems, data, people, processors and notices. The map supplies links two to five. A missing link is a gap, and gaps are what slow the first hours.

1IncidentWhat happened, and when you became aware.From the response team
2SystemsWhich systems are involved.From the Systems sheet
3DataWhat those systems hold.Categories, children’s data
4PeopleWho is affected and how to reach them.Count and route
5ProcessorsWho else holds the data.Contact and logs
6NoticesWhat you send and keep.See the reporting guide

Use the map

The first-hour scoping questions a breach-ready data map answers

Ten questions come up in almost every incident. If the map answers them, the team spends its first hours acting, not asking.

First-hour scoping questions, where the answer sits and what a blank costs
QuestionWhere the answer sitsWhat a blank costs you
1. Which systems are involved?Systems sheet: system and ownerTime spent asking around.
2. What personal data do they hold?Personal data held, joined to the inventoryYou cannot judge the likely consequences.
3. Is children’s data involved?Children’s data flagYou may miss a group that Section 9 treats separately.
4. Roughly how many people?Data Principals estimateYou cannot size the response or the notices.
5. How do we reach them?How to reach themRule 7(1) refers to the user account or a registered mode of communication. No route, no notice.
6. Who else holds a copy?Processor IDs, copies and exportsA copy at a vendor or in a shared drive is missed.
7. Where are the logs?Where the logs areYou cannot establish the timing or the extent.
8. How do we stop it?How to containContainment waits while someone looks for the lever.
9. How do we recover?How to recoverNobody knows who can restore.
10. Who do we call?Owner, out-of-hours contact, processor contactNobody answers when it matters.

Use the map

From the map to the Rule 7 notices: which map fields feed which content

Rule 7 asks for facts the map already holds: how far the breach reached, what you did, and how to reach the people affected. The map does not write the notice. It supplies the raw material.

Rule 7 content and the map fields that feed it
What the Rules ask forWhere the facts come from
Rule 7(1): a description of the breach, including its nature, extent and timingExtent: systems, data held and people. Timing: the logs.
Rule 7(1): the consequences likely to arise for the personData held and the children’s data flag.
Rule 7(1): the measures taken to mitigate the riskHow to contain and how to recover.
Rule 7(1): safety measures the person can takeThe data exposed decides the advice. Exposed log-ins call for different steps than exposed addresses.
Rule 7(1): contact details of a person who can respond, and delivery through the user account or a registered mode of communicationThe system owner, the named response contact and how to reach the people.
Rule 7(2): the Board intimation and the detailed informationSystems, data and people for the first. Logs, causes, mitigation, remedial steps and a report on the notices sent for the second.

This table shows where the facts sit and does not replace the Rule. For the full content, order and timing, follow the breach reporting guide.

Use the map

Worked example: a customer export shared by public link at a fictional online store

In a rehearsal, a staff member shares a customer export folder by public link. The map answers most scoping questions and the team finds three gaps. Scoping took 40 minutes (drill D-002 in the worksheet).

The team opens the Systems sheet and finds S-005, the shared drive, which holds exports of the order database (S-002) and the email platform (S-003). The store and every vendor here are fictional.

Scoping the exposed export from the map (illustrative)
QuestionWhat the map saidGap
Which system?S-005, shared drive. Exports of S-002 and S-003.No owner recorded.
What data?Name, email, phone and order counts. No card numbers.None.
How many people?S-002 holds about 21,000 customers and S-003 about 9,500 subscribers. The export’s own count was not recorded.No population estimate for S-005.
Children?No, for both source systems.None.
How to reach them?Registered email, as recorded for S-002 and S-003.No route recorded for S-005 itself.
Who else holds it?P-004, the file storage vendor. It can supply the sharing log.The contract has no incident terms.
Logs and containment?Sharing log in the drive. Remove the shared link and change folder permissions.Log retention not recorded.
  • What the map made quick: the system, data, vendor and containment step were all recorded.
  • What it exposed: no owner, no head count and no recorded log retention for the shared drive. The team assigned the fixes.
  • What the map did not decide: whether the exposure was a personal data breach and what to send. That assessment and the notices follow the reporting guide.

The numbers are invented. They are not a conclusion about any real business.

Use the map

Processors, logs and recovery: what to line up before an incident

Three things decide how fast you can scope a breach that touches a vendor: a person to call, access to the logs and a way to restore.

  • Processors. Section 8(1) keeps you responsible for processing done on your behalf. Record a named escalation contact and an out-of-hours route, and check whether the contract covers incidents and evidence. Rule 6(1) refers to security terms in the contract, but we found no fixed list of clauses.
  • Sub-processors. We found no express provision on sub-processors in Rules 6 or 7. Record them anyway, because your data may sit with a vendor’s vendor.
  • Logs. Rule 6(1) refers to logs, monitoring and review, and to keeping logs and personal data for one year unless another law requires otherwise. Record where logs sit, who can pull them and whether a processor will supply them.
  • Recovery. Rule 6(1) refers to measures for continued processing, such as backups. Record where they are and who can restore. Backups hold personal data, so include them in your retention and erasure plan.
  • An offline copy of the map. If the map lives only on the system that is down, it cannot help. Keep a restricted offline copy for the response team.

Use the map

Where breach scoping stalls: the map gaps that cost the most time

Most delay in the first hours comes from a handful of gaps in the map, not from the incident itself.

Map gaps that slow breach scoping, and the fix
GapWhat happensFix
A system is missing from the mapThe scope is understated and a later discovery reopens the incident.Reconcile the map with IT and finance software lists each quarter.
No count of peopleYou cannot size the notices.Record a rough count or range per system.
No way to reach peopleNotices cannot be sent through the account or a registered mode of communication.Record the route for each system and note records that lack one.
Logs not foundTiming and extent are guesswork.Record where the logs are, who pulls them and how long they last.
No known way to containAccess stays open while someone looks for the lever.Record the step and who can take it.
No out-of-hours contact, or a vendor with only a support queueNobody picks up on a Sunday night.Name a person, a backup and a vendor escalation route.
Stale rowsThe map describes last year’s systems and vendors.Record a verified date and recheck when a vendor, tool or team changes.

Build and use it

The free Breach Readiness Worksheet: Excel file, sheets and gap flags

The worksheet has a Systems sheet for the scoping facts, a Processors sheet for vendor contacts and a Drills sheet for rehearsals, with examples, a summary and lists. Enter your details on the download page to get the link.

DPDP Act Breach Readiness Worksheet 2026

Excel (.xlsx), about 27 KB. Sheets: Start here, Systems, Processors, Drills, three example sheets, Summary and Lists. Gap flags are formulas. The examples are fictional.

The Systems sheet records the data held, a rough head count, how to reach people, where the logs are, how to contain and recover, the owner and an out-of-hours contact. The Processors sheet records the contact, whether the contract covers incidents, whether logs are available and whether sub-processors are known. The Drills sheet logs each rehearsal.

How the gap flags work

A flag shows the first gap in a row. It is a prompt to check, not a finding of non-compliance. Minutes to scope is your own measure, not a legal time. The file holds out-of-hours contact details, so limit who can open it.

Build and use it

Step-by-step implementation: make your data map breach-ready in 6 steps

Add the breach fields, record how to reach people, line up processors, logs and recovery, name owners, rehearse, then close the gaps.

1Add the breach fields to the Systems lookup

What to do
For each system, record the data categories, whether children’s data is held and a rough count of people. Take systems and activity IDs from your inventory.
Output
One Systems row per system, with data and head count filled in.

2Record how to reach the people

What to do
For each system, note the route you hold for contacting a person: the user account or a registered email or phone. Note records that have none.
Output
A reach route on every row, or a noted exception.

3Line up processors, logs and recovery

What to do
Add a named escalation contact for each processor and check the contract for incident terms. Record where logs sit, how to contain and how to restore.
Output
A contact, a log location, a containment step and a recovery route for each system.

4Name owners and an out-of-hours route

What to do
Name an owner for each system and a person to call out of hours, with a backup. Roles and the workflow are in the reporting guide.
Output
An owner and an out-of-hours contact on every row.

5Rehearse with a made-up incident

What to do
Pick a short scenario, such as a shared link set to public. Using only the worksheet, list the systems, data, people and processors involved, and time it.
Output
A Drills row with minutes to scope and the gaps found.

6Close the gaps and recheck on change

What to do
Give every gap an owner and a date, then update the sheets. Recheck rows when a vendor, tool or team changes, and after any real incident.
Output
A verified date on every row and no open drill gaps.

Build and use it

7 common mistakes when using a data map for breach readiness

Most failures come from mapping too little, storing the map in the wrong place or never testing it.

Common mistakes and fixes
MistakeWhy it hurtsFix
1. Treating the map as the response planA map holds facts, not roles or decisions.Keep the map and the workflow separate, and link them.
2. Mapping only production systemsExports, shared drives, mailboxes and laptops hold personal data too.Record copies and exports against each system.
3. Leaving out how to reach peopleA count without a route cannot become a notice.Record the route for every system that holds people’s data.
4. Listing a team mailbox as the contactNobody answers at night or on holidays.Name a person, a backup and an out-of-hours number.
5. Assuming a processor will tell youSection 8(1) keeps you responsible, and a vendor may not volunteer what it knows.Get incident terms in the contract and a named contact.
6. Keeping the only copy on the affected systemIf the system is down or locked, so is the map.Keep a restricted offline copy for the response team.
7. Never testing itGaps appear for the first time during a real incident.Rehearse, log the drill and fix what it finds.

Questions

Frequently asked questions: data mapping and breach readiness under the DPDP Act

Does the DPDP Act require a data map for breach response?

No. We found no provision that requires a data map for breach response. The Act does require reasonable security safeguards (Section 8(5)) and, from 13 May 2027, intimation of a breach (Section 8(6) and Rule 7). A map is the practical way to prepare for both.

What is a personal data breach under the DPDP Act?

Section 2 defines it as unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. Whether an event meets that definition is an assessment step in the breach reporting guide.

How does a data map help with breach notification?

It supplies the facts the notices rest on: which systems and data, roughly how many people, how to reach them, which processors and where the logs are. It does not decide what to send or when. The reporting guide covers that.

What should we know in the first hour of an incident?

Which systems, what personal data, whether children’s data is involved, roughly how many people, how to reach them, which processors, where the logs are, how to contain and recover, and who to call. Each is a column on the worksheet.

How do we find the affected Data Principals?

Start from the affected systems, then use the head count and reach route recorded for each. Rule 7(1) refers to the user account or a mode of communication the person registered with you. We found no express rule for people with no registered route, so record those cases in advance and take advice.

Is a Data Processor responsible for notifying the Board?

Section 8(1) keeps the Data Fiduciary responsible for compliance, including for processing by a Data Processor on its behalf. We found no general duty in Rule 7 for a processor to notify the Board. The contract sets its role, so record a named contact and incident terms.

How long must we keep logs?

Rule 6(1) refers to keeping logs and personal data for one year unless another law requires otherwise. Confirm the scope of that wording for your systems with a legal adviser, and record where each system’s logs sit and who can pull them.

Where do backups fit?

Rule 6(1) refers to measures for continued processing, such as data backups. Record where backups are and who can restore. Backups also hold personal data, so include them in your retention and erasure plan.

How often should we rehearse?

We found no provision that sets a frequency. A sensible practice is yearly, after a major system or vendor change and after any real incident.

Is a data map the same as an incident response plan?

No. The plan sets roles, decisions and steps. The map holds the facts the plan needs. Keep both and link them. The reporting guide covers the workflow.

Related

Continue the data mapping collection

Go to the full method, the legal text and the practical tools. When you are ready to move from records to working controls, see the DPDP implementation framework.

Sources

Primary sources and regulatory references

  1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India, 11 August 2023. Sections 2, 8 and 9 are cited here.
  2. The Digital Personal Data Protection Rules, 2025, notified 13 November 2025 (G.S.R. 846(E)). Rules 6 and 7 are cited here.
  3. Our breach reporting guide, complete data mapping guide and section-by-section Act pages.
About this article. Prepared by the DPDPActIndia editorial team under our editorial policy. It explains the Act and Rules in general terms and is not legal advice (disclaimer).