Data mapping collection · Understand
Data map, personal data inventory, data flow map, record of processing activities, data catalogue: teams use these words interchangeably, and auditors do not. Here is what each one is, what the DPDP Act does and does not say, and how GDPR Article 30 compares.
In short
A data inventory is the list, a data flow map is the picture, a data map is the umbrella term for both, and a RoPA is a GDPR Article 30 style record of processing activities. The DPDP Act names none of them as a duty. For an Indian Data Fiduciary, the practical choice is a personal data inventory as the master record plus a data flow map for vendors and breaches, exported into a RoPA layout only when GDPR or a customer requires it.
The terms
Each term answers a different question. The inventory answers “what do we hold and why?” The flow map answers “where does it go?” A RoPA answers “can we show the regulator the Article 30 record?”
| Term | Question it answers | Usual form | Status under the DPDP Act |
|---|---|---|---|
| Data map | How does personal data move through the organisation? | Umbrella term covering the inventory and the flow diagram. | Not named as a duty. |
| Personal data inventory | What personal data do we process, for what purpose, where, with whom and for how long? | A spreadsheet or tool, one row per processing activity. | Not named as a duty. Helps meet Sections 8 and 11. |
| Data flow map | Where does data come from, where does it go, and who touches it on the way? | A diagram, often one per business process. | Not named as a duty. Helps with processors (Section 8(1)) and breach response (Section 8(6)). |
| RoPA (record of processing activities) | What does GDPR Article 30 require us to record? | A register with the fields listed in Article 30. | No general equivalent in the Act. |
| IT asset inventory or CMDB | What systems, servers and applications do we own? | A technical register of assets. | Not a DPDP term. A useful input, but it does not say what personal data sits in each system. |
| Data catalogue or lineage tool | What datasets exist, and how do they transform? | Software that scans or documents data stores. | Not a DPDP term. A tool that can feed the inventory. |
| Consent record | Can we prove notice and consent? | Logs or receipts, linked to a notice version. | Section 6(10) places the burden of proof on the Data Fiduciary. |
| Data Protection Impact Assessment (DPIA) | What are the risks to people from this processing? | A periodic assessment document. | Named for Significant Data Fiduciaries only, in Section 10(2)(c)(i). |
If someone asks for “the data map”, ask what decision it is for. A board explanation needs the flow picture. A rights request needs the inventory. A GDPR customer questionnaire may need the RoPA format.
The terms
Think of the data map as a folder and the inventory and flow map as the two documents inside it. A RoPA is not a third document. It is a particular layout of the inventory.
A RoPA is the inventory presented in the field layout that GDPR Article 30 prescribes. If your inventory already holds purposes, categories of data, recipients, transfers, retention and security measures, you can export it as a RoPA without keeping a second list. Keeping two lists by hand is how they drift apart.
The terms
The facts are the same; the presentation changes. The example below is illustrative and uses a newsletter sign-up. Adapt it to your own systems.
| View | What it shows |
|---|---|
| Personal data inventory row | Activity: newsletter subscription. Data Principals: website visitors who subscribe. Data: name, email address. Specified purpose: send the newsletter. Applicable basis: consent (Section 6). Notice version: v3. System: email platform. Processor: email service provider. Retention: until consent is withdrawn or the purpose is no longer served. Erasure path: unsubscribe triggers deletion in the email platform. Owner: marketing lead. |
| Data flow map | Website sign-up form → form handler → email platform (processor) → subscriber inbox. Unsubscribe link → email platform → deletion. Mark where data crosses to a processor and whether the processor is outside India. |
| RoPA-style entry (GDPR layout) | Controller and contact details. Purpose: newsletter. Categories of data subjects: subscribers. Categories of personal data: contact data. Categories of recipients: email service provider. Third-country transfers and safeguards, if any. Envisaged erasure time limit. General description of security measures. |
Notice that the inventory row is the richest. It carries the applicable basis, notice version and erasure path that the DPDP Act cares about, and which Article 30 does not ask for in the same way. That is why we recommend building the inventory first and the RoPA layout second.
RoPA and the law
GDPR Article 30 requires controllers to keep a written record with seven kinds of information, and processors to keep a shorter record. Both must be made available to the supervisory authority on request.
Under Article 30(3) the records must be in writing, including electronic form, and under Article 30(4) they must be made available to the supervisory authority on request. Article 30(5) exempts organisations with fewer than 250 employees, but not where the processing is likely to risk people’s rights and freedoms, is not occasional, or includes special categories of data. In practice this exemption is narrow.
None of the above is a DPDP Act requirement. The Act has no controller record, no processor record, no 250-employee test and no standing duty to keep a register for inspection in the way Article 30(4) works. The Board and the Central Government do have powers to call for information, so you should still be able to explain your processing on request. Where the Act expects a Data Fiduciary to know and show something, it says so in the specific provision, for example Section 11(1) on the summary of data and sharing.
RoPA and the law
Most Article 30 fields have a DPDP Act counterpart, but the Act’s own vocabulary differs. Use the Act’s words in your inventory so that every field points to a duty.
| Article 30(1) field | DPDP Act concept to record | Why it matters under the Act |
|---|---|---|
| Controller and DPO contact details | Data Fiduciary and the business contact of a Data Protection Officer, if applicable, or a person who can answer Data Principals’ questions (Section 8(9)). | Publication of contact information. |
| Purposes of the processing | The specified purpose in the notice (Section 5) and the applicable basis: consent or a Section 7 certain legitimate use. | Lawful purpose and consent limited to what is necessary. |
| Categories of data subjects and of personal data | Categories of Data Principal and the data elements processed. | Notice content and the summary under Section 11(1)(a). |
| Categories of recipients | Other Data Fiduciaries and Data Processors with whom data is shared, and what is shared. | Section 11(1)(b) and Section 8(1), 8(2). |
| Transfers to third countries and safeguards | Cross-border flags. Section 16 lets the Central Government restrict transfers to notified countries or territories. | A flag lets you react if a restriction is notified. Section 16(2) also keeps in force any other Indian law that gives higher protection or restricts transfers. |
| Envisaged time limits for erasure | Retention trigger, period and erasure path, including at processors. | Section 8(7) and 8(8). |
| General description of security measures | Reasonable security safeguards in place for the activity. | Section 8(5). |
Fields the DPDP Act cares about that Article 30 does not list as such: the notice version and consent record location (Section 6(10)), the children’s data flag (Section 9), the erasure path at each processor (Section 8(7)(b)) and the rights request search locations (Sections 11 and 12). These are the reason an inventory built for the DPDP Act is richer than a bare RoPA. See the full minimum inventory field list.
RoPA and the law
The Act applies to digital personal data, including personal data collected in non-digital form and then digitised. Your inventory should therefore focus on digital systems and digitised records.
If you hold paper forms, record the point at which they are scanned or keyed in, because that is where they enter scope. GDPR’s scope is framed differently, so a GDPR RoPA may list some non-automated records that a DPDP inventory does not need. Confirm the edge cases with counsel.
Which one you need
Start with the inventory in every case. Add the flow map when you have processors, and the RoPA layout only when an outside requirement asks for it.
| Situation | Build | Why |
|---|---|---|
| Indian business, DPDP Act only, few systems | A personal data inventory in a spreadsheet. | Covers consent proof, erasure, processors and rights requests without extra paperwork. |
| Indian business with many processors or SaaS tools | Inventory plus a data flow map per major process. | Vendors, onward sharing and breach impact need the picture. |
| GDPR applies to you, for example you offer services to people in the EU | Inventory plus a RoPA export that meets Article 30. | Article 30 is an express obligation under GDPR. |
| An enterprise or EU customer asks for your “RoPA” in a questionnaire | A RoPA-format export of the inventory. | It is a customer requirement, not a DPDP Act requirement. |
| Likely Significant Data Fiduciary | Inventory, flow maps and a link to your Data Protection Impact Assessment and audit evidence. | Section 10(2) duties are easier to evidence with a current inventory. |
Ask: “Which law or contract is making me produce this?” If the answer is GDPR or a customer, call it a RoPA. If the answer is your own DPDP Act compliance programme, call it a personal data inventory.
Which one you need
Accurate labels protect you in policies, contracts and board papers. These are the mix-ups we see most often.
| You may see | Problem | Say instead |
|---|---|---|
| “The DPDP RoPA.” | Implies the Act prescribes a RoPA. | “A personal data inventory, which can be exported in RoPA format.” |
| “Data mapping and data inventory are the same.” | Blurs the list and the picture. | “The data map includes the inventory and the flow map.” |
| “Our asset inventory is our data map.” | An IT asset list does not show what personal data sits in each system or why. | “The asset inventory is an input to the data map.” |
| “A data discovery scan is a data map.” | A scan finds data but does not record purpose, basis, owner or retention. | “Scan results feed the inventory, which a person must complete and verify.” |
| “A DPIA is the same as a RoPA.” | A DPIA assesses risk. A RoPA records processing. | “A DPIA draws on the inventory. For Significant Data Fiduciaries it is required periodically under Section 10(2)(c)(i).” |
| “Lawful basis” or “legitimate interest” as a DPDP field. | GDPR vocabulary. The Act uses consent or the specific certain legitimate uses in Section 7. | “Applicable basis: consent, or a named Section 7 use.” |
Score your readiness against the Act and Rules, then get matched with an implementation partner who can build the inventory and flow maps. Prefer to talk scope first? See data mapping services or RoPA services.
FAQ
A data inventory is the structured list of processing activities, with the data, purpose, systems, owners, processors and retention for each. Data mapping is the wider exercise and its output, which also includes a data flow map showing how data moves between systems, vendors and countries. In everyday use, “data map” often covers both.
RoPA stands for record of processing activities. It is the written record that GDPR Article 30 requires controllers and processors to keep, with prescribed fields such as purposes, categories of data and recipients, transfers, erasure time limits and security measures.
No. We found no provision in the DPDP Act that requires a RoPA, a data inventory or a data map. Several duties, such as Section 11(1) on the summary of data and sharing, Section 8(7) on erasure and Section 8(1) on processors, are easier to meet and demonstrate with one.
No. A RoPA is a register in the format GDPR Article 30 prescribes. A data map is a broader view that includes an inventory and a flow diagram. A well-built inventory can be exported as a RoPA, but a RoPA alone usually lacks DPDP-specific fields such as notice version, consent record and erasure path at processors.
Build a personal data inventory first. It serves DPDP Act duties directly, and you can export it in RoPA layout later if GDPR or a customer requires it. Add a data flow map once you have several processors or cross-border transfers.
If GDPR applies to you, Article 30 is an express obligation for controllers and processors, subject to the limited exemption in Article 30(5). Take advice on whether GDPR applies to your processing, then keep a RoPA alongside your DPDP Act inventory.
No. A data flow diagram shows movement between points. An inventory records the attributes of each processing activity, such as purpose, applicable basis, owner and retention. You need both, because the diagram shows where data goes and the inventory shows why and for how long.
No. A Data Protection Impact Assessment assesses risk to people. Under the DPDP Act, a periodic DPIA is required of Significant Data Fiduciaries under Section 10(2)(c)(i). A current inventory makes the assessment easier to carry out.
Yes, for many organisations. What matters is that each row has an owner, is verified against real systems and vendors, and is reviewed on a schedule or when something changes. Move to a tool when the number of systems makes a spreadsheet unreliable.
Related
Go to the full method, the legal text and the practical tools. When you are ready to move from records to working controls, see the DPDP implementation framework.
Sources
Consultant-led and partner-backed.