Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Data mapping collection · Understand

Data Mapping vs Data Inventory vs RoPA Under the DPDP Act: What Each Term Means and Which One You Need

Data map, personal data inventory, data flow map, record of processing activities, data catalogue: teams use these words interchangeably, and auditors do not. Here is what each one is, what the DPDP Act does and does not say, and how GDPR Article 30 compares.

By the DPDPActIndia editorial team · Last updated 4 October 2026 · About 13 minute read · Checked against the Act text and GDPR Article 30 · Editorial policy

In short

A data inventory is the list, a data flow map is the picture, a data map is the umbrella term for both, and a RoPA is a GDPR Article 30 style record of processing activities. The DPDP Act names none of them as a duty. For an Indian Data Fiduciary, the practical choice is a personal data inventory as the master record plus a data flow map for vendors and breaches, exported into a RoPA layout only when GDPR or a customer requires it.

  • Under the DPDP Act: no term here is a named obligation. Calling a RoPA “required by DPDP” is inaccurate.
  • Under GDPR: Article 30 expressly requires records of processing from controllers and processors, with a limited exemption for smaller organisations.
  • Best practice: keep one master inventory and generate the other views from it.
Data inventory
The list
One row per processing activity: data, purpose, systems, owners, processors, retention.
RoPA
The GDPR format
A record of processing activities with fields set by GDPR Article 30.
In this article
  1. The terms
  2. The terms side by side
  3. How the pieces fit together
  4. One activity, three views
  5. RoPA and the law
  6. What a GDPR RoPA contains
  7. Article 30 fields mapped to the DPDP Act
  8. Scope: digital personal data
  9. Which one you need
  10. Which record to build
  11. Naming mistakes to avoid
  12. Go further
  13. FAQ
  14. Related resources
  15. Primary sources

The terms

Data mapping vs data inventory vs RoPA: the terms side by side

Each term answers a different question. The inventory answers “what do we hold and why?” The flow map answers “where does it go?” A RoPA answers “can we show the regulator the Article 30 record?”

Data mapping terms compared, with their status under the DPDP Act
TermQuestion it answersUsual formStatus under the DPDP Act
Data mapHow does personal data move through the organisation?Umbrella term covering the inventory and the flow diagram.Not named as a duty.
Personal data inventoryWhat personal data do we process, for what purpose, where, with whom and for how long?A spreadsheet or tool, one row per processing activity.Not named as a duty. Helps meet Sections 8 and 11.
Data flow mapWhere does data come from, where does it go, and who touches it on the way?A diagram, often one per business process.Not named as a duty. Helps with processors (Section 8(1)) and breach response (Section 8(6)).
RoPA (record of processing activities)What does GDPR Article 30 require us to record?A register with the fields listed in Article 30.No general equivalent in the Act.
IT asset inventory or CMDBWhat systems, servers and applications do we own?A technical register of assets.Not a DPDP term. A useful input, but it does not say what personal data sits in each system.
Data catalogue or lineage toolWhat datasets exist, and how do they transform?Software that scans or documents data stores.Not a DPDP term. A tool that can feed the inventory.
Consent recordCan we prove notice and consent?Logs or receipts, linked to a notice version.Section 6(10) places the burden of proof on the Data Fiduciary.
Data Protection Impact Assessment (DPIA)What are the risks to people from this processing?A periodic assessment document.Named for Significant Data Fiduciaries only, in Section 10(2)(c)(i).
Plain-English rule

If someone asks for “the data map”, ask what decision it is for. A board explanation needs the flow picture. A rights request needs the inventory. A GDPR customer questionnaire may need the RoPA format.

The terms

How a data map, personal data inventory and data flow map fit together

Think of the data map as a folder and the inventory and flow map as the two documents inside it. A RoPA is not a third document. It is a particular layout of the inventory.

Data mapThe umbrella for how personal data is held and moves
Personal data inventoryThe list. One row per processing activity: data elements, specified purpose, applicable basis, systems, owner, processors, retention, erasure path.
Data flow mapThe picture. Sources, systems, processors, recipients and cross-border hops, drawn per process.
Linked recordsNotice versions, consent records, processor contracts and retention schedules that the inventory points to.
Where RoPA sits

A RoPA is the inventory presented in the field layout that GDPR Article 30 prescribes. If your inventory already holds purposes, categories of data, recipients, transfers, retention and security measures, you can export it as a RoPA without keeping a second list. Keeping two lists by hand is how they drift apart.

1Master inventoryOne maintained source of truth with an owner and a review date.You maintain this
2Flow maps and DPDP Act viewsVendor reviews, breach impact, erasure and rights playbooks drawn from the inventory.You use this daily
3RoPA exportThe same data in Article 30 layout for a GDPR customer, auditor or regulator.Produced on demand

The terms

One processing activity, three views: inventory row, flow map and RoPA entry

The facts are the same; the presentation changes. The example below is illustrative and uses a newsletter sign-up. Adapt it to your own systems.

The same activity (newsletter sign-up) shown as an inventory row, a flow map description and a RoPA-style entry (illustrative)
ViewWhat it shows
Personal data inventory rowActivity: newsletter subscription. Data Principals: website visitors who subscribe. Data: name, email address. Specified purpose: send the newsletter. Applicable basis: consent (Section 6). Notice version: v3. System: email platform. Processor: email service provider. Retention: until consent is withdrawn or the purpose is no longer served. Erasure path: unsubscribe triggers deletion in the email platform. Owner: marketing lead.
Data flow mapWebsite sign-up form → form handler → email platform (processor) → subscriber inbox. Unsubscribe link → email platform → deletion. Mark where data crosses to a processor and whether the processor is outside India.
RoPA-style entry (GDPR layout)Controller and contact details. Purpose: newsletter. Categories of data subjects: subscribers. Categories of personal data: contact data. Categories of recipients: email service provider. Third-country transfers and safeguards, if any. Envisaged erasure time limit. General description of security measures.

Notice that the inventory row is the richest. It carries the applicable basis, notice version and erasure path that the DPDP Act cares about, and which Article 30 does not ask for in the same way. That is why we recommend building the inventory first and the RoPA layout second.

RoPA and the law

What a GDPR RoPA contains: Article 30 records of processing activities

GDPR Article 30 requires controllers to keep a written record with seven kinds of information, and processors to keep a shorter record. Both must be made available to the supervisory authority on request.

Controller record, Article 30(1)

  • Name and contact details of the controller and, where applicable, the DPO.
  • The purposes of the processing.
  • Categories of data subjects and of personal data.
  • Categories of recipients, including in third countries.
  • Transfers to third countries and the documented safeguards, where applicable.
  • Where possible, envisaged time limits for erasure.
  • Where possible, a general description of security measures.

Processor record, Article 30(2)

  • Name and contact details of the processor and of each controller on whose behalf it acts.
  • The categories of processing carried out for each controller.
  • Transfers to third countries and safeguards, where applicable.
  • Where possible, a general description of security measures.

Under Article 30(3) the records must be in writing, including electronic form, and under Article 30(4) they must be made available to the supervisory authority on request. Article 30(5) exempts organisations with fewer than 250 employees, but not where the processing is likely to risk people’s rights and freedoms, is not occasional, or includes special categories of data. In practice this exemption is narrow.

Do not carry this across to India

None of the above is a DPDP Act requirement. The Act has no controller record, no processor record, no 250-employee test and no standing duty to keep a register for inspection in the way Article 30(4) works. The Board and the Central Government do have powers to call for information, so you should still be able to explain your processing on request. Where the Act expects a Data Fiduciary to know and show something, it says so in the specific provision, for example Section 11(1) on the summary of data and sharing.

RoPA and the law

GDPR Article 30 fields mapped to the DPDP Act: what to record for each

Most Article 30 fields have a DPDP Act counterpart, but the Act’s own vocabulary differs. Use the Act’s words in your inventory so that every field points to a duty.

GDPR Article 30(1) fields and the closest DPDP Act concept (a mapping aid, not a legal equivalence)
Article 30(1) fieldDPDP Act concept to recordWhy it matters under the Act
Controller and DPO contact detailsData Fiduciary and the business contact of a Data Protection Officer, if applicable, or a person who can answer Data Principals’ questions (Section 8(9)).Publication of contact information.
Purposes of the processingThe specified purpose in the notice (Section 5) and the applicable basis: consent or a Section 7 certain legitimate use.Lawful purpose and consent limited to what is necessary.
Categories of data subjects and of personal dataCategories of Data Principal and the data elements processed.Notice content and the summary under Section 11(1)(a).
Categories of recipientsOther Data Fiduciaries and Data Processors with whom data is shared, and what is shared.Section 11(1)(b) and Section 8(1), 8(2).
Transfers to third countries and safeguardsCross-border flags. Section 16 lets the Central Government restrict transfers to notified countries or territories.A flag lets you react if a restriction is notified. Section 16(2) also keeps in force any other Indian law that gives higher protection or restricts transfers.
Envisaged time limits for erasureRetention trigger, period and erasure path, including at processors.Section 8(7) and 8(8).
General description of security measuresReasonable security safeguards in place for the activity.Section 8(5).

Fields the DPDP Act cares about that Article 30 does not list as such: the notice version and consent record location (Section 6(10)), the children’s data flag (Section 9), the erasure path at each processor (Section 8(7)(b)) and the rights request search locations (Sections 11 and 12). These are the reason an inventory built for the DPDP Act is richer than a bare RoPA. See the full minimum inventory field list.

RoPA and the law

Scope check: the DPDP Act covers digital personal data

The Act applies to digital personal data, including personal data collected in non-digital form and then digitised. Your inventory should therefore focus on digital systems and digitised records.

  • Section 2 defines “processing” as wholly or partly automated operations on digital personal data, covering collection, storage, use, sharing, erasure and similar operations.
  • Section 3 applies the Act to digital personal data processed in India, and to processing outside India connected with offering goods or services to Data Principals in India.
  • Section 3 does not apply to personal data processed by an individual for a personal or domestic purpose, or to certain personal data made publicly available.

If you hold paper forms, record the point at which they are scanned or keyed in, because that is where they enter scope. GDPR’s scope is framed differently, so a GDPR RoPA may list some non-automated records that a DPDP inventory does not need. Confirm the edge cases with counsel.

Which one you need

Which record should you build? Data inventory, flow map or RoPA by situation

Start with the inventory in every case. Add the flow map when you have processors, and the RoPA layout only when an outside requirement asks for it.

What to build in each situation (editorial guidance)
SituationBuildWhy
Indian business, DPDP Act only, few systemsA personal data inventory in a spreadsheet.Covers consent proof, erasure, processors and rights requests without extra paperwork.
Indian business with many processors or SaaS toolsInventory plus a data flow map per major process.Vendors, onward sharing and breach impact need the picture.
GDPR applies to you, for example you offer services to people in the EUInventory plus a RoPA export that meets Article 30.Article 30 is an express obligation under GDPR.
An enterprise or EU customer asks for your “RoPA” in a questionnaireA RoPA-format export of the inventory.It is a customer requirement, not a DPDP Act requirement.
Likely Significant Data FiduciaryInventory, flow maps and a link to your Data Protection Impact Assessment and audit evidence.Section 10(2) duties are easier to evidence with a current inventory.
One practical test

Ask: “Which law or contract is making me produce this?” If the answer is GDPR or a customer, call it a RoPA. If the answer is your own DPDP Act compliance programme, call it a personal data inventory.

Which one you need

Naming mistakes to avoid when you write about data mapping and RoPA

Accurate labels protect you in policies, contracts and board papers. These are the mix-ups we see most often.

Common terminology mistakes and accurate replacements
You may seeProblemSay instead
“The DPDP RoPA.”Implies the Act prescribes a RoPA.“A personal data inventory, which can be exported in RoPA format.”
“Data mapping and data inventory are the same.”Blurs the list and the picture.“The data map includes the inventory and the flow map.”
“Our asset inventory is our data map.”An IT asset list does not show what personal data sits in each system or why.“The asset inventory is an input to the data map.”
“A data discovery scan is a data map.”A scan finds data but does not record purpose, basis, owner or retention.“Scan results feed the inventory, which a person must complete and verify.”
“A DPIA is the same as a RoPA.”A DPIA assesses risk. A RoPA records processing.“A DPIA draws on the inventory. For Significant Data Fiduciaries it is required periodically under Section 10(2)(c)(i).”
“Lawful basis” or “legitimate interest” as a DPDP field.GDPR vocabulary. The Act uses consent or the specific certain legitimate uses in Section 7.“Applicable basis: consent, or a named Section 7 use.”

Which record do you have today?

Score your readiness against the Act and Rules, then get matched with an implementation partner who can build the inventory and flow maps. Prefer to talk scope first? See data mapping services or RoPA services.

FAQ

Frequently asked questions: data mapping vs data inventory vs RoPA under the DPDP Act

What is the difference between data mapping and a data inventory?

A data inventory is the structured list of processing activities, with the data, purpose, systems, owners, processors and retention for each. Data mapping is the wider exercise and its output, which also includes a data flow map showing how data moves between systems, vendors and countries. In everyday use, “data map” often covers both.

What is a RoPA?

RoPA stands for record of processing activities. It is the written record that GDPR Article 30 requires controllers and processors to keep, with prescribed fields such as purposes, categories of data and recipients, transfers, erasure time limits and security measures.

Does the DPDP Act require a RoPA or data inventory?

No. We found no provision in the DPDP Act that requires a RoPA, a data inventory or a data map. Several duties, such as Section 11(1) on the summary of data and sharing, Section 8(7) on erasure and Section 8(1) on processors, are easier to meet and demonstrate with one.

Is a RoPA the same as a data map?

No. A RoPA is a register in the format GDPR Article 30 prescribes. A data map is a broader view that includes an inventory and a flow diagram. A well-built inventory can be exported as a RoPA, but a RoPA alone usually lacks DPDP-specific fields such as notice version, consent record and erasure path at processors.

Which should an Indian company build first, a data map or a RoPA?

Build a personal data inventory first. It serves DPDP Act duties directly, and you can export it in RoPA layout later if GDPR or a customer requires it. Add a data flow map once you have several processors or cross-border transfers.

Do I need a RoPA if GDPR also applies to my business?

If GDPR applies to you, Article 30 is an express obligation for controllers and processors, subject to the limited exemption in Article 30(5). Take advice on whether GDPR applies to your processing, then keep a RoPA alongside your DPDP Act inventory.

Is a data flow diagram the same as a data inventory?

No. A data flow diagram shows movement between points. An inventory records the attributes of each processing activity, such as purpose, applicable basis, owner and retention. You need both, because the diagram shows where data goes and the inventory shows why and for how long.

Is a DPIA the same as a data inventory or RoPA?

No. A Data Protection Impact Assessment assesses risk to people. Under the DPDP Act, a periodic DPIA is required of Significant Data Fiduciaries under Section 10(2)(c)(i). A current inventory makes the assessment easier to carry out.

Can I use a spreadsheet for my personal data inventory?

Yes, for many organisations. What matters is that each row has an owner, is verified against real systems and vendors, and is reviewed on a schedule or when something changes. Move to a tool when the number of systems makes a spreadsheet unreliable.

Related

Continue the data mapping collection

Go to the full method, the legal text and the practical tools. When you are ready to move from records to working controls, see the DPDP implementation framework.

Sources

Primary sources and regulatory references

  1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India, 11 August 2023. Sections 2, 3, 5, 6, 7, 8, 9, 10, 11, 12 and 16 are cited here.
  2. Regulation (EU) 2016/679 (GDPR), Article 30, Records of processing activities, for the comparison only.
  3. The Digital Personal Data Protection Rules, 2025, notified 13 November 2025 (G.S.R. 846(E)). See our DPDP Rules 2025 explainer.
  4. Our complete data mapping guide and section-by-section Act pages.
About this article. Prepared by the DPDPActIndia editorial team under our editorial policy. It explains the Act and GDPR in general terms and is not legal advice (disclaimer). The mapping of Article 30 fields to DPDP Act concepts is an aid, not a legal equivalence, and the situation guidance is editorial judgment. Whether GDPR applies to you is a legal question for your counsel. Spotted an error? Tell us.