Data mapping collection · Complete guide
Know what personal data you hold, why you use it, where it sits, who handles it and when it must go. A practical method for Indian businesses preparing for the DPDP Act, with the 2026 to 2027 timeline.
In short
Data mapping is the practice of recording what personal data an organisation processes, for what purpose, in which systems, shared with whom, and for how long. The DPDP Act does not name it as a duty and has no GDPR-style RoPA requirement. A reliable data map still makes many DPDP duties substantially easier to implement, maintain and demonstrate in practice.
Understand
Data mapping is a living record of your personal data estate: which personal data you process, about whom, for which purpose, in which systems, shared with which processors or recipients, and for how long.
The DPDP Act defines personal data as any data about an individual who is identifiable by or in relation to it, and defines processing broadly: collection, recording, storage, use, sharing, restriction, erasure and more (Section 2). A data map applies that wide definition to your real business. It shows where processing actually happens, not where your policy says it happens.
Two scoping points matter before you start. First, the Act applies to digital personal data, including data collected offline and digitised later (Section 3). A paper form that is never digitised is outside the Act, but the moment it is scanned or typed into a system it is inside your map. Second, the Act applies to processing outside India when it relates to offering goods or services to people in India, so offshore systems belong on the map too.
Map by business process (customer onboarding, payroll, support, marketing), not by system. Systems change every year; processes explain why data is collected in the first place.
Understand
No. The DPDP Act does not use the term “data mapping” and does not require a data map, a register or a RoPA from an ordinary Data Fiduciary. Data mapping is a practical way to meet duties the Act does impose.
Section 11(1) gives a Data Principal the right to obtain a summary of the personal data being processed and the processing activities undertaken, and the identities of all other Data Fiduciaries and Data Processors with whom the data has been shared, with a description of the data shared. The Act does not say how you must keep that information. A data map is the practical way to produce it consistently.
GDPR Article 30 expressly requires records of processing. Do not tell readers, clients or your board that DPDP does the same. Say instead: “Not expressly required, but practically necessary to meet several duties.” A lawyer should confirm this wording for your own context. For the full section-by-section answer, read Is data mapping mandatory under the DPDP Act?
Understand
Consent is one control. A data map is what makes the other controls workable. Every duty below is imposed by the Act or Rules. The map does not create the duty; it helps you implement and demonstrate it.
| Section | What the Act requires | How a data map helps |
|---|---|---|
| 4, 6(1) | Process for a lawful purpose, on consent or a certain legitimate use. Consent must be limited to data necessary for the specified purpose. | Records the purpose, the applicable basis and the data actually needed for each activity. |
| 5, 6(10) | Notice before or with the consent request. The fiduciary must prove notice and consent. | Links each activity to a notice version and consent record. |
| 7 | Specified legitimate uses, such as data voluntarily provided for a purpose, legal obligations and employment. | Marks which activities rely on which Section 7 clause. |
| 6(4), 6(6) | Withdrawal must be as easy as giving consent. Stop processing and cause processors to stop. | Shows every system and processor that holds the person’s data. |
| 8(1), 8(2) | The fiduciary is responsible for processing by processors, and may engage one only under a valid contract. | Lists processors, what they receive and contract status. |
| 8(3) | Ensure completeness, accuracy and consistency where data drives a decision or is disclosed to another fiduciary. | Flags which data feeds decisions and external disclosures. |
| 8(4), 8(5) | Appropriate technical and organisational measures, and reasonable security safeguards, including at processors. | Shows where data sits so controls can be prioritised. |
| 8(6) | Intimate the Board and each affected Data Principal of a personal data breach. | Tells you what data, which people and which systems a breach touched. |
| 8(7), 8(8) | Erase when consent is withdrawn or the purpose is no longer served, unless law requires retention. Cause processors to erase. | Documents retention triggers and erasure paths, including backups. |
| 8(9), 8(10) | Publish a contact for questions, and run a grievance mechanism. | Names owners who can answer questions about each activity. |
| 9 | Verifiable parental consent, no detrimental processing, no tracking or targeted advertising directed at children. | Flags activities that process children’s data. |
| 11 to 13 | Rights to a summary and sharing list, to correction, completion, updating and erasure, and to grievance redressal. | Lets you find the data and produce the sharing list. |
| 10 | Additional duties for notified Significant Data Fiduciaries: DPO, independent auditor, periodic DPIA and audit. | Additional SDF governance duties that may benefit from a stronger inventory and map. Section 10 does not mandate mapping. |
| 16 | The Government may restrict transfers to notified countries outside India. | Shows where data goes abroad, so you can react if a restriction is notified. |
The cost of getting the underlying duties wrong is high. Under Section 33 and the Schedule, penalties after a Board inquiry can reach up to Rs 250 crore for failure to take reasonable security safeguards and up to Rs 200 crore for failure to notify a breach or for breaches of the children’s data duties. These are maximums, not fixed amounts.
Understand
Use “personal data inventory” for the master record and “data flow map” for the picture. Use “RoPA” only when a GDPR-aligned client or auditor asks for that format.
| Term | What it usually means | Use it for |
|---|---|---|
| Data map | The overall view of how personal data moves through your organisation, covering inventory and flows. | The umbrella term for the whole exercise. |
| Personal data inventory | A structured list of data elements, purposes, systems, owners, processors and retention, one row per processing activity. | The working record you maintain and audit. |
| Data flow map | A diagram showing movement between collection points, systems, processors, recipients and countries. | Vendor reviews, breach impact and board explanations. |
| RoPA or processing register | A GDPR Article 30 style record of processing activities. Not a named DPDP requirement. | A “RoPA-style” layout is fine as a format, if you do not call it a legal requirement. |
For the full breakdown, with a worked example and a GDPR Article 30 comparison, read Data Mapping vs Data Inventory vs RoPA Under the DPDP Act. See the glossary entries for Data Fiduciary, Data Processor and Data Principal so your inventory uses the Act’s own words, and the comparison of Data Fiduciary vs Data Processor.
Build
A useful data map answers eight questions, in this order: what data, why, where, who, where it goes, how long, how it leaves, and what happens when a person asks or something goes wrong.
Build
Scope it, list activities, capture fields, trace flows, attach the basis, set retention, then sign off and refresh. The time it takes depends mainly on how many systems and vendors you have.
Want this done for you? See DPDP data mapping services or DPDP RoPA services.
Build
Record 17 fields per processing activity. If you only have time for a few, start with purpose, applicable basis, systems, processors and retention.
| Field | What to record | Why it matters under DPDP |
|---|---|---|
| Business activity | The process, such as customer onboarding or payroll. | Ties data to a real purpose. |
| Business owner | A named person, not a team. | Accountability under Section 8(1). |
| Data Principal category | Customer, prospect, employee, applicant, vendor contact, child. | Drives notice, basis and children’s checks. |
| Personal data elements | Name, contact, ID, transaction, device, behavioural, support data. | Consent must be limited to data necessary (Section 6(1)). |
| Source and collection point | Web form, app, API, call centre, partner, import, digitised paper. | Shows where notice must appear. |
| Purpose | The specified purpose, in the same words as the notice. | Purpose limitation and notice alignment (Section 5). |
| Applicable basis | Consent, or the Section 7 clause relied on. | Section 4(1) allows only these two routes. |
| Notice and consent record | Notice version, timestamp, where the proof is stored. | Burden of proof sits with you (Section 6(10)). |
| Systems and storage | Databases, SaaS tools, spreadsheets, email, backups, logs. | Needed for security, rights and erasure. |
| Internal access | Teams and roles with access. | Supports safeguards (Section 8(5)). |
| Processors and recipients | Name, role, contract status, data shared. | Section 8(1), 8(2) and the Section 11(1) sharing list. |
| Onward sharing and transfers | Other fiduciaries, countries, purposes. | Section 16 and Section 11(1)(b). |
| Retention trigger and period | What ends the purpose, how long you keep data, any law requiring retention. | Section 8(7) and 8(8). |
| Erasure and withdrawal path | Who acts, which systems, which processors. | Sections 6(6) and 8(7). |
| Security controls | Encryption, access control, logging, monitoring. | Section 8(5) and the Rules. |
| Children’s data flag | Yes or no, age assurance, parental consent method. | Section 9. |
| Risk rating and review date | High, medium or low, and the next review. | Keeps the record current. |
Section 4(1) recognises two routes: consent, or certain legitimate uses listed in Section 7. DPDP has no general “legitimate interest” basis like GDPR. Label the column Purpose and applicable basis and record either “Consent (Section 6)” or the exact Section 7 clause.
| Field | Example entry |
|---|---|
| Activity and owner | Newsletter subscription. Owner: Head of Marketing. |
| Data Principal and data | Prospect. Name and email address. |
| Source | Website signup form. |
| Purpose and basis | Send product updates. Consent (Section 6), tick box not pre-ticked. |
| Notice and consent record | Notice version 3 and timestamp stored in the CRM. |
| Systems and processors | Website database, email platform (processor, contract signed), CRM. |
| Retention and erasure | Until withdrawal, or after a company-set inactivity period. Unsubscribe deletes the record in the email platform and the CRM. |
| Children and review | No (not directed at children). Review every six months. |
Retention periods in your own inventory are decisions you document, informed by the Act, the Rules and any sector law. They are not set by this example.
Build
Map all six lifecycle stages and look in the places data hides. Most gaps are not in the main database. They are in backups, exports, shared drives and old vendor accounts.
Developers can use the DPDP guide for engineering teams to see how these stages translate into data stores and APIs.
Map in depth
Map every party that receives, stores or can see personal data. Under Section 8(1) you remain responsible for processing done on your behalf by a Data Processor, so your processor list is part of your own compliance record.
| Field | Question to answer |
|---|---|
| Name and role | Who is it, and what does it do for you? |
| Data shared | Which data elements and which Data Principal groups does it receive? |
| Purpose | Does its use stay within the specified purpose in your notice? |
| Contract | Is there a valid contract (Section 8(2)), and does it set security obligations? |
| Sub-processors | Does it pass data to others, and where? |
| Location | In which countries is the data stored or accessed? |
| Erasure on request or exit | Can it erase data when you instruct it, as Section 8(7)(b) expects? |
| Breach duty | How fast must it tell you about an incident? |
| Internal owner | Who manages the relationship? |
Compare three lists: finance’s vendor payment list, the single sign-on application list and the cloud account list. Tools that appear in one but not the others are usually shadow processors.
Read the glossary entry for Data Processor and the guide to consent propagation to processors. Section 8(2) applies to processors engaged for activities related to offering goods or services to Data Principals.
For the full method, a worked example and a free Excel worksheet, read data flow and processor mapping under the DPDP Act.
Map in depth
For each activity, record one primary basis: consent under Section 6, or a named Section 7 certain legitimate use. If neither fits, stop or redesign the activity.
| Activity | Typical basis | What to record in the map |
|---|---|---|
| Marketing email list | Consent (Section 6) | Notice version, tick-box evidence, unsubscribe path. |
| Sending a receipt after a purchase | Section 7(a), voluntarily provided for a purpose | The specified purpose and that the person has not objected. |
| Payroll and employee benefits | Section 7(i), employment purposes | The employment purpose, retention and payroll processors. |
| Complying with a court order | Section 7(e) | The order reference and who holds the data. |
| Medical emergency response | Section 7(f) | The emergency use and a deletion trigger afterwards. |
Section 7(a) covers the specified purpose for which the person voluntarily gave the data. Reusing that data for an unrelated purpose, such as marketing, needs a fresh basis.
Go deeper in Consent vs Certain Legitimate Uses, Mapping Consent, Purpose and Legitimate Uses (link each activity to its purpose and ground), the side-by-side comparison, Valid Consent Under Section 6 and How to Prove Consent. Start from the full consent management guide.
Map in depth
Under Section 8(7), erase personal data when consent is withdrawn or when it is reasonable to assume the purpose is no longer served, whichever is earlier, unless law requires you to keep it. You must also cause your processors to erase data you gave them.
For the full method, with the trigger table, the backup approach and a free Excel register, read the data retention and erasure mapping guide.
Withdrawing consent stops consent-based processing (Section 6(6)). Erasure is a separate duty under Section 8(7) and Section 12(3). Read the consent withdrawal guide and the glossary entries for data retention and consent withdrawal.
Map in depth
Your map is the lookup table for two stressful moments: a person asking about their data, and a personal data breach. If the map is current, both become a search, not an investigation.
Sections 11 and 12 apply to a Data Principal who has given consent, including the Section 7(a) voluntary-provision case. Follow the step-by-step guide to reporting a DPDP breach, the explainer on breach notification timing and the glossary pages for access and correction and erasure. For the request side in depth, see Data Mapping for Data Principal Requests, which turns this lookup into a request log and a free worksheet. For incident response, Data Mapping for Breach Readiness shows how the same map helps scope a personal data breach before you follow the reporting steps.
Map in depth
Add a flag column so high-risk activities get a second look. The flags below come straight from the Act.
| Flag | What to look for | Act reference |
|---|---|---|
| Children’s data | Anyone under 18, or a person with a disability who has a lawful guardian. Verifiable consent of the parent or guardian, no tracking or behavioural monitoring, no targeted advertising directed at children, subject to exemptions. | Section 9; glossary |
| Cross-border | Countries where data is stored, accessed or sent. No country restriction had been notified when this guide was last updated, and sector rules can be stricter. | Section 16; glossary |
| Decision-making | Data used to make a decision that affects a person, or disclosed to another fiduciary. Check completeness, accuracy and consistency. | Section 8(3) |
| Volume and sensitivity | Large volumes or high-risk data. Volume and sensitivity are factors for notifying a Significant Data Fiduciary. | Section 10(1) |
| Claimed exemption | Any activity relying on a Section 17 exemption. Record the exact clause and who approved it. | Section 17 |
Run and prove
A data map is only useful while it is current. Give every row an owner, define what triggers an update and keep dated snapshots as evidence.
| Role | Responsibility |
|---|---|
| Business process owners | Own their rows and attest that they are correct at each review. |
| Privacy lead or DPO contact | Maintains the standard, reviews gaps and answers questions (Section 8(9) contact). |
| IT and security | Keeps the systems list current and links security controls. |
| Procurement | Blocks new vendors that are not added to the processor list. |
| Legal | Confirms the basis, contract terms and retention rules. |
| HR | Owns employee and applicant data rows. |
If the Central Government notifies you as a Significant Data Fiduciary, Section 10(2) adds a Data Protection Officer based in India, an independent data auditor, periodic Data Protection Impact Assessments and audits. These duties may benefit from a stronger inventory, though Section 10 does not mandate mapping. No Significant Data Fiduciary class had been notified when this guide was last updated. See who may qualify, the glossary entry and DPIA.
Roles: see the guides for DPOs, legal teams and founders.
Run and prove
If you start in October 2026, a 90-day plan finishes in early January 2027, leaving about four months before core duties apply on 13 May 2027.
Pair this plan with the DPDP 2027 compliance roadmap, the compliance timeline and the compliance checklist.
Run and prove
Most failed mapping projects fail for organisational reasons, not technical ones.
Run and prove
The method is the same in every sector; the data flows differ. Start with the sector hub, then adapt your inventory.
Browse all industries, including education, where children’s data is central.
Score your readiness against the Act and Rules, then get matched with an implementation partner who can own the mapping work. Prefer to talk through scope first? See data mapping services.
FAQ
It is a living record of the personal data you process, the purpose, the systems, the processors and recipients, and the retention period. The Act does not name it as a duty, but it helps you meet several duties.
No. The Act has no provision requiring a data map or register. Duties such as proving consent, controlling processors, erasing data and responding to rights requests are easier to meet with one.
No. The DPDP Act has no general records-of-processing requirement for ordinary Data Fiduciaries. A RoPA-style layout is a useful format, but it should not be described as a legal requirement.
A data inventory is the structured list of activities, data, systems, owners and retention. A data flow map is the diagram of movement between parties. “Data map” often covers both.
At minimum: activity, owner, Data Principal category, data elements, source, purpose, applicable basis, notice and consent record, systems, processors, transfers, retention, erasure path, security controls, children’s flag and review date.
It shows which systems hold a person’s data and which processors received it, so you can provide the Section 11 summary and sharing list, correct data under Section 12 and erase it where required.
It tells you which systems, data and people a breach touched, so you can intimate the Board and each affected Data Principal as Section 8(6) and the Rules require.
The Act covers digital personal data, including data collected offline and digitised later (Section 3). Map paper records once they are scanned or entered into a system.
Update it whenever a trigger occurs, such as a new product, vendor, country or purpose, and review it on a fixed calendar. Review high-risk rows more often than low-risk ones.
Section 17(3) lets the Central Government exempt certain classes, including startups, from some provisions, so check current notifications. Even where exempt, a simple spreadsheet map helps you answer requests and manage vendors.
A spreadsheet is enough to start for most small and mid-sized organisations. Dedicated tools become useful when systems, vendors and update frequency grow beyond what a spreadsheet can keep accurate.
Browse by topic
The specialist guides below go deeper on each part of this guide. They publish in priority order; this guide and the readiness assessment are live now.
Sources
Consultant-led and partner-backed.