Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Data mapping collection · Complete guide

DPDP Act Data Mapping: Complete Guide to Personal Data Inventory and Data Flows

Know what personal data you hold, why you use it, where it sits, who handles it and when it must go. A practical method for Indian businesses preparing for the DPDP Act, with the 2026 to 2027 timeline.

By the DPDPActIndia editorial team · Last updated 4 October 2026 · About 22 minute read · Built from the Act text and the DPDP Rules, 2025 · Editorial policy

In short

Data mapping is the practice of recording what personal data an organisation processes, for what purpose, in which systems, shared with whom, and for how long. The DPDP Act does not name it as a duty and has no GDPR-style RoPA requirement. A reliable data map still makes many DPDP duties substantially easier to implement, maintain and demonstrate in practice.

  • Not a named legal duty. Treat it as practical compliance infrastructure, not an express DPDP obligation.
  • Closest hooks in the Act: Section 6(10) (prove notice and consent), Section 8(1) and 8(5) (responsibility for processors and security) and Section 11(1) (a summary of data and the parties it was shared with).
  • Start now: core duties apply from 13 May 2027, and mapping feeds most other tasks, so starting early protects the timeline.
Now
13 Nov 2025
DPDP Rules notified. Preparation window is open.
Deadline
13 May 2027
Core Data Fiduciary duties apply.
In this guide
  1. Understand
  2. What data mapping means under DPDP
  3. Is data mapping mandatory?
  4. DPDP duties a data map supports
  5. Data map vs inventory vs RoPA
  6. Build
  7. The 8 questions your map must answer
  8. A 7-step data mapping method
  9. The minimum inventory fields
  10. Mapping the data lifecycle
  11. Map in depth
  12. Data flow and processor mapping
  13. Purpose, consent and legitimate uses
  14. Retention and erasure mapping
  15. Rights requests and breach readiness
  16. Children, cross-border and high-risk flags
  17. Run and prove
  18. Ownership, change and audit evidence
  19. 30/60/90-day roadmap
  20. 7 common mistakes
  21. Sector snapshots
  22. Go further
  23. Check your readiness
  24. FAQ
  25. Related resources
  26. Primary sources

Understand

What is data mapping under the DPDP Act? A plain-English definition

Data mapping is a living record of your personal data estate: which personal data you process, about whom, for which purpose, in which systems, shared with which processors or recipients, and for how long.

The DPDP Act defines personal data as any data about an individual who is identifiable by or in relation to it, and defines processing broadly: collection, recording, storage, use, sharing, restriction, erasure and more (Section 2). A data map applies that wide definition to your real business. It shows where processing actually happens, not where your policy says it happens.

Two scoping points matter before you start. First, the Act applies to digital personal data, including data collected offline and digitised later (Section 3). A paper form that is never digitised is outside the Act, but the moment it is scanned or typed into a system it is inside your map. Second, the Act applies to processing outside India when it relates to offering goods or services to people in India, so offshore systems belong on the map too.

Practical tip

Map by business process (customer onboarding, payroll, support, marketing), not by system. Systems change every year; processes explain why data is collected in the first place.

Understand

Is data mapping mandatory under the DPDP Act? What the law says and does not say

No. The DPDP Act does not use the term “data mapping” and does not require a data map, a register or a RoPA from an ordinary Data Fiduciary. Data mapping is a practical way to meet duties the Act does impose.

What the Act requires

  • Process only for a lawful purpose, on consent or a certain legitimate use (Section 4).
  • Give notice, and prove notice and consent if challenged (Section 5, Section 6(10)).
  • Stay responsible for processors and use them only under a valid contract (Section 8(1), 8(2)).
  • Apply reasonable security safeguards and report breaches (Section 8(5), 8(6)).
  • Erase data when consent is withdrawn or the purpose is served, and cause processors to erase it (Section 8(7)).
  • Give a summary of data and processing, and name those it was shared with, on request (Section 11(1)).

What a data map adds

  • A single place to see every processing activity and its purpose.
  • A way to link each activity to a notice version and consent record.
  • A processor and recipient list you can show to a customer or the Board.
  • A list of systems to search, correct or erase when someone exercises a right.
  • A basis for retention rules, erasure jobs and breach impact checks.
  • Evidence of accountability, if an audit or inquiry ever asks.
What the Act says

Section 11(1) gives a Data Principal the right to obtain a summary of the personal data being processed and the processing activities undertaken, and the identities of all other Data Fiduciaries and Data Processors with whom the data has been shared, with a description of the data shared. The Act does not say how you must keep that information. A data map is the practical way to produce it consistently.

Watch out: GDPR vocabulary

GDPR Article 30 expressly requires records of processing. Do not tell readers, clients or your board that DPDP does the same. Say instead: “Not expressly required, but practically necessary to meet several duties.” A lawyer should confirm this wording for your own context. For the full section-by-section answer, read Is data mapping mandatory under the DPDP Act?

Understand

Why consent banners are not enough: the DPDP duties a data map helps you meet

Consent is one control. A data map is what makes the other controls workable. Every duty below is imposed by the Act or Rules. The map does not create the duty; it helps you implement and demonstrate it.

Notice and consentWhich activity needs which notice
Sections 5, 6
ProcessorsWho processes data on your behalf
Section 8(1), 8(2)
SecurityWhere safeguards matter most
Section 8(5)
Data Principal rightsWhere to search and correct
Sections 11 to 13
Data map
Breach responseWho and what is affected
Section 8(6)
Retention and erasureWhen and where data must go
Section 8(7), 8(8)
ChildrenWhere minors’ data sits
Section 9
GovernanceOwners, audits, SDF duties
Sections 8(4), 10
DPDP duties and how a data map helps (the Act requires the duty, not the map)
SectionWhat the Act requiresHow a data map helps
4, 6(1)Process for a lawful purpose, on consent or a certain legitimate use. Consent must be limited to data necessary for the specified purpose.Records the purpose, the applicable basis and the data actually needed for each activity.
5, 6(10)Notice before or with the consent request. The fiduciary must prove notice and consent.Links each activity to a notice version and consent record.
7Specified legitimate uses, such as data voluntarily provided for a purpose, legal obligations and employment.Marks which activities rely on which Section 7 clause.
6(4), 6(6)Withdrawal must be as easy as giving consent. Stop processing and cause processors to stop.Shows every system and processor that holds the person’s data.
8(1), 8(2)The fiduciary is responsible for processing by processors, and may engage one only under a valid contract.Lists processors, what they receive and contract status.
8(3)Ensure completeness, accuracy and consistency where data drives a decision or is disclosed to another fiduciary.Flags which data feeds decisions and external disclosures.
8(4), 8(5)Appropriate technical and organisational measures, and reasonable security safeguards, including at processors.Shows where data sits so controls can be prioritised.
8(6)Intimate the Board and each affected Data Principal of a personal data breach.Tells you what data, which people and which systems a breach touched.
8(7), 8(8)Erase when consent is withdrawn or the purpose is no longer served, unless law requires retention. Cause processors to erase.Documents retention triggers and erasure paths, including backups.
8(9), 8(10)Publish a contact for questions, and run a grievance mechanism.Names owners who can answer questions about each activity.
9Verifiable parental consent, no detrimental processing, no tracking or targeted advertising directed at children.Flags activities that process children’s data.
11 to 13Rights to a summary and sharing list, to correction, completion, updating and erasure, and to grievance redressal.Lets you find the data and produce the sharing list.
10Additional duties for notified Significant Data Fiduciaries: DPO, independent auditor, periodic DPIA and audit.Additional SDF governance duties that may benefit from a stronger inventory and map. Section 10 does not mandate mapping.
16The Government may restrict transfers to notified countries outside India.Shows where data goes abroad, so you can react if a restriction is notified.

The cost of getting the underlying duties wrong is high. Under Section 33 and the Schedule, penalties after a Board inquiry can reach up to Rs 250 crore for failure to take reasonable security safeguards and up to Rs 200 crore for failure to notify a breach or for breaches of the children’s data duties. These are maximums, not fixed amounts.

Understand

Data map vs data inventory vs RoPA: which term should Indian teams use?

Use “personal data inventory” for the master record and “data flow map” for the picture. Use “RoPA” only when a GDPR-aligned client or auditor asks for that format.

Common data mapping terms compared
TermWhat it usually meansUse it for
Data mapThe overall view of how personal data moves through your organisation, covering inventory and flows.The umbrella term for the whole exercise.
Personal data inventoryA structured list of data elements, purposes, systems, owners, processors and retention, one row per processing activity.The working record you maintain and audit.
Data flow mapA diagram showing movement between collection points, systems, processors, recipients and countries.Vendor reviews, breach impact and board explanations.
RoPA or processing registerA GDPR Article 30 style record of processing activities. Not a named DPDP requirement.A “RoPA-style” layout is fine as a format, if you do not call it a legal requirement.

For the full breakdown, with a worked example and a GDPR Article 30 comparison, read Data Mapping vs Data Inventory vs RoPA Under the DPDP Act. See the glossary entries for Data Fiduciary, Data Processor and Data Principal so your inventory uses the Act’s own words, and the comparison of Data Fiduciary vs Data Processor.

Build

The 8 questions every DPDP data map must answer

A useful data map answers eight questions, in this order: what data, why, where, who, where it goes, how long, how it leaves, and what happens when a person asks or something goes wrong.

1What data?Data elements, categories and who they are about.Records: inventory
2Why?The specified purpose and the applicable basis.Records: purpose, consent or Section 7
3Where?Systems, files, backups and locations.Records: systems and storage
4Who?Internal owners, teams, processors and vendors.Records: owners and access
5Where does it go?Recipients, onward sharing and transfers abroad.Records: flows
6How long?The retention trigger, period and any legal hold.Records: retention
7How does it leave?Erasure and withdrawal paths, including processors.Records: erasure path
8When asked or breached?Which map fields feed rights and breach playbooks.Records: playbook links

Build

How to run a data mapping exercise for DPDP compliance: a 7-step method

Scope it, list activities, capture fields, trace flows, attach the basis, set retention, then sign off and refresh. The time it takes depends mainly on how many systems and vendors you have.

  1. Step 1Set scope and name an owner. Decide which entities, business units and countries are in scope. Appoint an executive sponsor and one owner per business process. Output: a scope note and an owner list.
  2. Step 2List processing activities by business process. Start from marketing, onboarding, payments, support, HR, analytics and vendor management, not from IT systems. Output: an activity list.
  3. Step 3Capture the inventory fields for each activity. Use the minimum fields below. Interview owners, then verify against system exports. Output: a first-draft inventory.
  4. Step 4Trace systems, vendors and flows. Cross-check the vendor payment list from finance, the single sign-on app list and cloud accounts to find tools no one mentioned. Output: a data flow map and a processor list.
  5. Step 5Attach the purpose, basis and notice or consent record. For each activity, state whether it rests on consent or a Section 7 use, and where the proof lives. Output: a basis column with evidence links.
  6. Step 6Set retention triggers and erasure paths. Define when each data set ends, who erases it, and how processors and backups are covered. Output: a retention and erasure schedule.
  7. Step 7Review, sign off and schedule the refresh. Owners attest their rows, the privacy lead reviews gaps, and change triggers start the next update. Output: a signed inventory and a review calendar.

Want this done for you? See DPDP data mapping services or DPDP RoPA services.

Build

What to record in a DPDP personal data inventory: the minimum fields

Record 17 fields per processing activity. If you only have time for a few, start with purpose, applicable basis, systems, processors and retention.

Minimum fields for a DPDP personal data inventory
FieldWhat to recordWhy it matters under DPDP
Business activityThe process, such as customer onboarding or payroll.Ties data to a real purpose.
Business ownerA named person, not a team.Accountability under Section 8(1).
Data Principal categoryCustomer, prospect, employee, applicant, vendor contact, child.Drives notice, basis and children’s checks.
Personal data elementsName, contact, ID, transaction, device, behavioural, support data.Consent must be limited to data necessary (Section 6(1)).
Source and collection pointWeb form, app, API, call centre, partner, import, digitised paper.Shows where notice must appear.
PurposeThe specified purpose, in the same words as the notice.Purpose limitation and notice alignment (Section 5).
Applicable basisConsent, or the Section 7 clause relied on.Section 4(1) allows only these two routes.
Notice and consent recordNotice version, timestamp, where the proof is stored.Burden of proof sits with you (Section 6(10)).
Systems and storageDatabases, SaaS tools, spreadsheets, email, backups, logs.Needed for security, rights and erasure.
Internal accessTeams and roles with access.Supports safeguards (Section 8(5)).
Processors and recipientsName, role, contract status, data shared.Section 8(1), 8(2) and the Section 11(1) sharing list.
Onward sharing and transfersOther fiduciaries, countries, purposes.Section 16 and Section 11(1)(b).
Retention trigger and periodWhat ends the purpose, how long you keep data, any law requiring retention.Section 8(7) and 8(8).
Erasure and withdrawal pathWho acts, which systems, which processors.Sections 6(6) and 8(7).
Security controlsEncryption, access control, logging, monitoring.Section 8(5) and the Rules.
Children’s data flagYes or no, age assurance, parental consent method.Section 9.
Risk rating and review dateHigh, medium or low, and the next review.Keeps the record current.
Use DPDP vocabulary: “applicable basis”, not “legal ground”

Section 4(1) recognises two routes: consent, or certain legitimate uses listed in Section 7. DPDP has no general “legitimate interest” basis like GDPR. Label the column Purpose and applicable basis and record either “Consent (Section 6)” or the exact Section 7 clause.

Illustrative example: one inventory row

Illustrative inventory row for a newsletter signup (example only, not legal advice)
FieldExample entry
Activity and ownerNewsletter subscription. Owner: Head of Marketing.
Data Principal and dataProspect. Name and email address.
SourceWebsite signup form.
Purpose and basisSend product updates. Consent (Section 6), tick box not pre-ticked.
Notice and consent recordNotice version 3 and timestamp stored in the CRM.
Systems and processorsWebsite database, email platform (processor, contract signed), CRM.
Retention and erasureUntil withdrawal, or after a company-set inactivity period. Unsubscribe deletes the record in the email platform and the CRM.
Children and reviewNo (not directed at children). Review every six months.

Retention periods in your own inventory are decisions you document, informed by the Act, the Rules and any sector law. They are not set by this example.

Build

How to map the personal data lifecycle: collect, use, store, share, retain and delete

Map all six lifecycle stages and look in the places data hides. Most gaps are not in the main database. They are in backups, exports, shared drives and old vendor accounts.

1CollectForms, apps, calls, partners, digitised paper.Hides in: call recordings, chat widgets, scanned forms
2UseAnalytics, scoring, support, marketing, decisions.Hides in: spreadsheets, BI exports, test data
3StoreDatabases, cloud storage, laptops.Hides in: backups, logs, staging copies
4ShareProcessors, partners, regulators, affiliates.Hides in: email attachments, shared drives, messaging apps
5RetainActive use, archive, legal hold.Hides in: legacy systems, former vendors
6DeleteErase, anonymise, confirm with processors.Hides in: backup restores, vendor copies

Developers can use the DPDP guide for engineering teams to see how these stages translate into data stores and APIs.

Map in depth

Data flow and data processor mapping: who touches your personal data?

Map every party that receives, stores or can see personal data. Under Section 8(1) you remain responsible for processing done on your behalf by a Data Processor, so your processor list is part of your own compliance record.

1Data PrincipalsCustomers, employees, applicants, vendor contacts.Source of data and of rights
2Collection pointsWeb, app, API, call centre, branch, partner feeds.Notice and consent happen here
3Core systemsCRM, ERP, HRMS, warehouse, spreadsheets, backups.Your owners and your controls
4ProcessorsCloud, payments, KYC, email, support, analytics, payroll.Contract, security, erasure (8(2), 8(5), 8(7)(b))
5Recipients and countriesOther fiduciaries, regulators, group entities, overseas.Sections 11(1)(b) and 16
What to record for each Data Processor
FieldQuestion to answer
Name and roleWho is it, and what does it do for you?
Data sharedWhich data elements and which Data Principal groups does it receive?
PurposeDoes its use stay within the specified purpose in your notice?
ContractIs there a valid contract (Section 8(2)), and does it set security obligations?
Sub-processorsDoes it pass data to others, and where?
LocationIn which countries is the data stored or accessed?
Erasure on request or exitCan it erase data when you instruct it, as Section 8(7)(b) expects?
Breach dutyHow fast must it tell you about an incident?
Internal ownerWho manages the relationship?
Find the vendors nobody mentioned

Compare three lists: finance’s vendor payment list, the single sign-on application list and the cloud account list. Tools that appear in one but not the others are usually shadow processors.

Read the glossary entry for Data Processor and the guide to consent propagation to processors. Section 8(2) applies to processors engaged for activities related to offering goods or services to Data Principals.

For the full method, a worked example and a free Excel worksheet, read data flow and processor mapping under the DPDP Act.

Map in depth

Mapping purpose, consent and legitimate uses under Sections 4 to 7

For each activity, record one primary basis: consent under Section 6, or a named Section 7 certain legitimate use. If neither fits, stop or redesign the activity.

For each processing activityName the specified purpose first, then choose the basis
Consent (Sections 4(1)(a), 6)Needs a Section 5 notice, a clear affirmative action, an easy withdrawal route and a stored record. Map the notice version and proof location.
Certain legitimate use (Sections 4(1)(b), 7)Name the exact clause, for example data voluntarily provided for a specified purpose (7(a)) or employment (7(i)). Other duties still apply.
Neither fitsDo not process on a hunch. Seek valid consent, narrow the purpose or drop the activity.
Typical basis by activity (confirm with counsel for your facts)
ActivityTypical basisWhat to record in the map
Marketing email listConsent (Section 6)Notice version, tick-box evidence, unsubscribe path.
Sending a receipt after a purchaseSection 7(a), voluntarily provided for a purposeThe specified purpose and that the person has not objected.
Payroll and employee benefitsSection 7(i), employment purposesThe employment purpose, retention and payroll processors.
Complying with a court orderSection 7(e)The order reference and who holds the data.
Medical emergency responseSection 7(f)The emergency use and a deletion trigger afterwards.
Watch out

Section 7(a) covers the specified purpose for which the person voluntarily gave the data. Reusing that data for an unrelated purpose, such as marketing, needs a fresh basis.

Go deeper in Consent vs Certain Legitimate Uses, Mapping Consent, Purpose and Legitimate Uses (link each activity to its purpose and ground), the side-by-side comparison, Valid Consent Under Section 6 and How to Prove Consent. Start from the full consent management guide.

Map in depth

Data retention and erasure mapping: when must personal data go?

Under Section 8(7), erase personal data when consent is withdrawn or when it is reasonable to assume the purpose is no longer served, whichever is earlier, unless law requires you to keep it. You must also cause your processors to erase data you gave them.

For the full method, with the trigger table, the backup approach and a free Excel register, read the data retention and erasure mapping guide.

  1. Purpose beginsRecord the trigger up front. State the specified purpose and what will end it, such as account closure or contract completion.
  2. Active useKeep only what the purpose needs. Consent and notice are tied to necessary data (Section 6(1)).
  3. Trigger firesWithdrawal, or purpose no longer served. Section 8(8) deems a purpose no longer served if the person neither approaches you nor exercises rights for a period the Rules prescribe for each class.
  4. Notice stepCheck for an advance-notice duty. For the classes covered by the Rules’ Third Schedule, Rule 8 sets retention limits and an advance notice before erasure. Confirm whether you are in scope.
  5. Erase everywhereSystems, backups and processors. Include replicas, exports and test copies. Instruct processors and collect confirmation (Section 8(7)(b)).
  6. Keep what law requiresRetention under another law overrides erasure. Record the law and the period, and limit use to that legal need. The Rules also set minimum retention for certain logs, so do not delete them too early.
  7. EvidenceLog what was erased, when and by whom. Keep the processor confirmations with the log.
Withdrawal, cessation and erasure are different

Withdrawing consent stops consent-based processing (Section 6(6)). Erasure is a separate duty under Section 8(7) and Section 12(3). Read the consent withdrawal guide and the glossary entries for data retention and consent withdrawal.

Map in depth

Can you answer a Data Principal request or a breach in time? Map for rights and incidents

Your map is the lookup table for two stressful moments: a person asking about their data, and a personal data breach. If the map is current, both become a search, not an investigation.

A Data Principal asks

  • Find them: which identifiers each system uses (email, phone, customer ID).
  • Summary: the data and processing activities (Section 11(1)(a)).
  • Sharing list: fiduciaries and processors it was shared with, and what was shared (Section 11(1)(b)).
  • Correct, complete, update: every system that holds the field (Section 12(2)).
  • Erase: unless retention is necessary for the specified purpose or law (Section 12(3)).
  • Grievance: owner and response period (Section 13).

A breach happens

  • Systems: which systems and which owner are involved.
  • Data: which categories were exposed or lost.
  • People: which Data Principals to tell (Section 8(6)).
  • Processors: who else holds the affected data (Section 8(5)).
  • Board intimation: the facts the Rules ask for, within their timelines.
  • Lessons: update safeguards and the map afterwards.

Sections 11 and 12 apply to a Data Principal who has given consent, including the Section 7(a) voluntary-provision case. Follow the step-by-step guide to reporting a DPDP breach, the explainer on breach notification timing and the glossary pages for access and correction and erasure. For the request side in depth, see Data Mapping for Data Principal Requests, which turns this lookup into a request log and a free worksheet. For incident response, Data Mapping for Breach Readiness shows how the same map helps scope a personal data breach before you follow the reporting steps.

Map in depth

Children’s data, cross-border flows and high-risk processing: what to flag

Add a flag column so high-risk activities get a second look. The flags below come straight from the Act.

Risk flags to add to every inventory row
FlagWhat to look forAct reference
Children’s dataAnyone under 18, or a person with a disability who has a lawful guardian. Verifiable consent of the parent or guardian, no tracking or behavioural monitoring, no targeted advertising directed at children, subject to exemptions.Section 9; glossary
Cross-borderCountries where data is stored, accessed or sent. No country restriction had been notified when this guide was last updated, and sector rules can be stricter.Section 16; glossary
Decision-makingData used to make a decision that affects a person, or disclosed to another fiduciary. Check completeness, accuracy and consistency.Section 8(3)
Volume and sensitivityLarge volumes or high-risk data. Volume and sensitivity are factors for notifying a Significant Data Fiduciary.Section 10(1)
Claimed exemptionAny activity relying on a Section 17 exemption. Record the exact clause and who approved it.Section 17

Run and prove

Keeping your data map alive: ownership, change triggers and audit evidence

A data map is only useful while it is current. Give every row an owner, define what triggers an update and keep dated snapshots as evidence.

Who does what
RoleResponsibility
Business process ownersOwn their rows and attest that they are correct at each review.
Privacy lead or DPO contactMaintains the standard, reviews gaps and answers questions (Section 8(9) contact).
IT and securityKeeps the systems list current and links security controls.
ProcurementBlocks new vendors that are not added to the processor list.
LegalConfirms the basis, contract terms and retention rules.
HROwns employee and applicant data rows.
Update the map when
You launch a feature or product, add a vendor, enter a new country, start a new purpose, merge or acquire, suffer an incident, or a new Rule or notification changes a duty.
Keep as audit evidence
Dated inventory snapshots, notice and consent versions, processor contracts, erasure logs, breach records and review sign-offs.
Significant Data Fiduciaries

If the Central Government notifies you as a Significant Data Fiduciary, Section 10(2) adds a Data Protection Officer based in India, an independent data auditor, periodic Data Protection Impact Assessments and audits. These duties may benefit from a stronger inventory, though Section 10 does not mandate mapping. No Significant Data Fiduciary class had been notified when this guide was last updated. See who may qualify, the glossary entry and DPIA.

Roles: see the guides for DPOs, legal teams and founders.

Run and prove

A 30/60/90-day data mapping roadmap to 13 May 2027

If you start in October 2026, a 90-day plan finishes in early January 2027, leaving about four months before core duties apply on 13 May 2027.

Days 1 to 30Scope
  • Name a sponsor and process owners
  • Define scope and entities
  • List processing activities
  • Pull the vendor and SSO lists
  • Set up the inventory template
  • Take the readiness assessment
Days 31 to 60Map
  • Complete your top ten processes
  • Trace flows and processors
  • Record basis and consent proof
  • Flag children and cross-border
  • List contract gaps
Days 61 to 90Operate
  • Set retention and erasure schedule
  • Link rights and breach playbooks
  • Owners attest their rows
  • Publish the contact point
  • Schedule reviews and fix contracts

Pair this plan with the DPDP 2027 compliance roadmap, the compliance timeline and the compliance checklist.

Run and prove

7 data mapping mistakes that weaken DPDP readiness

Most failed mapping projects fail for organisational reasons, not technical ones.

1
Mapping only the website
Include internal systems, spreadsheets, backups and vendors. Fix: start from business processes.
2
Starting from systems
A system list does not explain purpose. Fix: one row per activity, then attach systems.
3
Missing shadow vendors
Teams sign up for tools on their own. Fix: reconcile finance, SSO and cloud lists.
4
Ignoring backups and exports
Erasure fails if copies survive. Fix: record backup rotation and export locations.
5
Copying GDPR language
Claiming DPDP requires a RoPA or “legitimate interest” is wrong. Fix: use Section 4 and 7 terms.
6
One-off project, no owner
A stale map misleads. Fix: owners, change triggers and a review calendar.
7
Map not linked to workflows
A map that does not drive notices, consent, rights and erasure is paperwork. Fix: link rows to playbooks.

Run and prove

Data mapping by sector: fintech, SaaS, healthcare, e-commerce, HR and AI

The method is the same in every sector; the data flows differ. Start with the sector hub, then adapt your inventory.

Live
Fintech and NBFC
Lending lifecycle, lending service providers, credit bureaus, KYC vendors. See fintech and the fintech implementation guide.
Live
SaaS and IT
Product telemetry, trial leads, support, billing and sub-processors. See SaaS.
Live
Healthcare
Patient records, labs, insurers, devices and emergency uses. See healthcare.
Live
E-commerce
Orders, logistics partners, payments and ad networks. See e-commerce.
Live
HR and employee data
Applicants, payroll, benefits, Section 7(i) uses. See HR teams.
Soon
AI systems
Training data, prompts, outputs, retrieval and model vendors. A dedicated guide is planned.

Browse all industries, including education, where children’s data is central.

Could you answer a data access request today?

Score your readiness against the Act and Rules, then get matched with an implementation partner who can own the mapping work. Prefer to talk through scope first? See data mapping services.

FAQ

Frequently asked questions about DPDP data mapping

What is data mapping under the DPDP Act?

It is a living record of the personal data you process, the purpose, the systems, the processors and recipients, and the retention period. The Act does not name it as a duty, but it helps you meet several duties.

Is data mapping mandatory under the DPDP Act?

No. The Act has no provision requiring a data map or register. Duties such as proving consent, controlling processors, erasing data and responding to rights requests are easier to meet with one.

Does DPDP require a RoPA like GDPR Article 30?

No. The DPDP Act has no general records-of-processing requirement for ordinary Data Fiduciaries. A RoPA-style layout is a useful format, but it should not be described as a legal requirement.

What is the difference between a data map and a data inventory?

A data inventory is the structured list of activities, data, systems, owners and retention. A data flow map is the diagram of movement between parties. “Data map” often covers both.

What should a DPDP data inventory include?

At minimum: activity, owner, Data Principal category, data elements, source, purpose, applicable basis, notice and consent record, systems, processors, transfers, retention, erasure path, security controls, children’s flag and review date.

How does data mapping help with Data Principal requests?

It shows which systems hold a person’s data and which processors received it, so you can provide the Section 11 summary and sharing list, correct data under Section 12 and erase it where required.

How does data mapping help with a personal data breach?

It tells you which systems, data and people a breach touched, so you can intimate the Board and each affected Data Principal as Section 8(6) and the Rules require.

Do I need to map paper records?

The Act covers digital personal data, including data collected offline and digitised later (Section 3). Map paper records once they are scanned or entered into a system.

How often should a data map be updated?

Update it whenever a trigger occurs, such as a new product, vendor, country or purpose, and review it on a fixed calendar. Review high-risk rows more often than low-risk ones.

Do small businesses and startups need a data map?

Section 17(3) lets the Central Government exempt certain classes, including startups, from some provisions, so check current notifications. Even where exempt, a simple spreadsheet map helps you answer requests and manage vendors.

Do I need software, or is a spreadsheet enough?

A spreadsheet is enough to start for most small and mid-sized organisations. Dedicated tools become useful when systems, vendors and update frequency grow beyond what a spreadsheet can keep accurate.

Browse by topic

Explore data mapping

The specialist guides below go deeper on each part of this guide. They publish in priority order; this guide and the readiness assessment are live now.

Sources

Primary sources and regulatory references

  1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India, 11 August 2023. Sections 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17 and 33 and the Schedule are cited in this guide.
  2. The Digital Personal Data Protection Rules, 2025, notified 13 November 2025 (G.S.R. 846(E)), Gazette of India. See our plain-language DPDP Rules 2025 explainer.
  3. Our section-by-section pages on the Act and the glossary.
About this guide. Prepared by the DPDPActIndia editorial team under our editorial policy. It explains the Act and Rules in general terms and is not legal advice (disclaimer). Rule references and commencement dates should be confirmed against the Gazette text before you rely on them. Spotted an error? Tell us.