Data mapping collection · Understand
A clear, section-by-section answer for compliance leads, founders and counsel: what the Act and Rules do and do not say about data maps, inventories and records of processing, and how much mapping you actually need.
In short
No. Data mapping is not an express obligation under the DPDP Act. The Act does not use the words data map, data inventory or record of processing, and it has no general equivalent of GDPR Article 30. But several duties, including the right to a summary of your processing and sharing under Section 11(1), are hard to meet and harder to prove without one. Treat a data map as practical compliance infrastructure, not as a legal requirement.
The answer
The honest answer has three layers, and mixing them up is where most online advice goes wrong. The law does not require a map by name. The law does require outcomes that you cannot reliably deliver without the information a map holds. And if you are ever challenged, a map is the quickest way to show what you did.
This page deals only with the question “is it mandatory?” For the method, the fields and the roadmap, use the complete DPDP data mapping guide.
The answer
The Act is outcome-based. It tells a Data Fiduciary what it must achieve, such as erasing data or protecting it, and leaves the method to the organisation. We found no provision that prescribes a record, register or map as the method.
Section 11(1) lets a Data Principal obtain from a Data Fiduciary to whom she has given consent: (a) a summary of the personal data being processed and the processing activities undertaken with respect to it; and (b) the identities of all other Data Fiduciaries and Data Processors with whom the data has been shared, with a description of the data shared. The Act does not say how you must keep that information. The practical answer is a maintained inventory.
Section 8(4) adds that a Data Fiduciary must implement “appropriate technical and organisational measures” to ensure effective observance of the Act. Section 8(4) does not mention mapping. It is, however, the general accountability duty under which many organisations place their inventory, because a documented view of processing is a common organisational measure. That is our reading of how it is used, not a statement that the section requires it.
The answer
Not every link is equally strong. The table grades how closely each duty depends on the information in a data map, so you can separate what the Act says from what we advise.
| Provision | What the Act requires | Why a map matters | Link |
|---|---|---|---|
| 11(1)(a), (b) | On request, give a summary of data and processing activities, and the identities of those the data was shared with. | This is the information a map holds. Without it you rebuild the answer from scratch each time. | Direct |
| 8(7) | Erase data when consent is withdrawn or the purpose is no longer served, and cause processors to erase it. | You cannot erase from systems and processors you have not listed. | Strong |
| 6(6) | On withdrawal, cease processing and cause processors to cease. | Shows every system and processor that must stop. | Strong |
| 8(1), 8(2) | You stay responsible for processors and may engage them only under a valid contract. | A processor list with contract status is the control that proves this. | Strong |
| 8(6) | Intimate the Board and each affected Data Principal of a personal data breach, in the prescribed form and manner. | Tells you who is affected and what data was involved. | Strong |
| 8(5) | Protect personal data with reasonable security safeguards, including data processed by processors. | Safeguards need to be placed where the data actually is. | Supporting |
| 6(10), 5 | Give notice, and prove notice and consent if a question arises in a proceeding. | Links each activity to a notice version and consent record. | Supporting |
| 12, 8(3) | Correct, complete, update and erase on request. Keep data complete, accurate and consistent where it drives decisions or is disclosed. | Shows where each copy of the data lives. | Supporting |
| 8(4) | Implement appropriate technical and organisational measures to ensure effective observance. | A documented view of processing is one common such measure. | Supporting |
| 9 | Verifiable parental consent for children; no tracking or targeted advertising directed at children. | Flags where minors’ data is held and used. | Supporting |
Direct means the duty is, in substance, to produce what a data map contains. Strong means the duty is very hard to perform reliably without that information. Supporting means a map helps but other controls also matter. The grading is our editorial judgment, not a statement in the Act.
The comparisons
GDPR Article 30 expressly requires records of processing. DPDP has no general equivalent. Teams with GDPR experience often assume the two match. They do not, and repeating the GDPR rule as a DPDP rule is the most common error in this topic.
| Question | GDPR | DPDP Act |
|---|---|---|
| Is there an express records duty? | Yes. Article 30 requires controllers and processors to keep records of processing, with a limited exemption for some smaller organisations. | No general equivalent was found in the Act. |
| Are the fields prescribed? | Yes. Article 30(1) lists what a controller’s record must contain. | No. You choose what to record. |
| Must the record be shown to the regulator? | Yes, on request, under Article 30(4). | No equivalent obligation was found. |
| What is the basis for processing? | Six lawful bases, including legitimate interests. | Consent, or the specific “certain legitimate uses” in Section 7. There is no general legitimate-interest basis. |
| Practical effect | A register is a compliance deliverable in itself. | A register is a tool for meeting other duties. |
Say “a data inventory in RoPA format”, not “the DPDP RoPA”. Use “applicable basis” (consent or a Section 7 use), not “lawful basis” or “legitimate interest”. See the plain-language comparison of data map, data inventory and RoPA.
The comparisons
We have not relied on any rule as imposing a data mapping or RoPA duty. The Rules were notified on 13 November 2025 and supply the detail the Act leaves to rules: the content of notices, breach intimation, retention and erasure details, Consent Manager registration and Significant Data Fiduciary measures.
Those topics matter because each one is a place where a map earns its keep. A notice must describe the data and purpose. A breach intimation must describe what happened. Erasure and retention rules need to be applied to specific systems. None of this turns a map into a legal requirement, but it raises the cost of operating without one.
Rule numbers and exact wording should be checked against the Gazette text (G.S.R. 846(E)) before you cite them in a policy, contract or client advice. See our DPDP Rules 2025 explainer. Core Data Fiduciary duties apply from 13 May 2027, and Consent Manager registration opens on 13 November 2026.
The comparisons
Not by name, but this is where mapping is hardest to avoid. Section 10(2) requires a notified Significant Data Fiduciary to appoint a Data Protection Officer based in India and an independent data auditor, and to undertake periodic Data Protection Impact Assessments and periodic audits.
For the governance model, see Significant Data Fiduciary under the DPDP Act.
The comparisons
Not for the absence of a map as such. The Schedule to the Act attaches monetary penalties to breaches of specific provisions, and the Board decides after an inquiry (Section 33).
| Duty | Maximum penalty | Where a map helps |
|---|---|---|
| Reasonable security safeguards to prevent a breach (Section 8(5)) | Up to Rs 250 crore | Locating systems, processors and data that need safeguards. |
| Intimation of a personal data breach (Section 8(6)) | Up to Rs 200 crore | Identifying affected people and data fast. |
| Children’s data obligations (Section 9) | Up to Rs 200 crore | Flagging where minors’ data is collected and used. |
Other provisions carry other maximums, listed in the Schedule. These are ceilings, not fixed fines. Section 33 requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of data and the steps taken to mitigate. A documented, working inventory is one way to show the steps you took. The practical risk of having no map is therefore indirect: you are more likely to fail a duty that carries a penalty, and less able to show your efforts.
What to do
If you can answer all five without asking around, you effectively have one. If not, the gaps tell you where to start.
What to do
The Act does not set a standard, so match depth to risk. The table is our practical guidance and should be tested against your own facts.
| Profile | Reasonable depth | Start with |
|---|---|---|
| Small business, one or two systems, few vendors | A one-page register in a spreadsheet, reviewed twice a year. | Purposes, systems, vendors, retention. |
| Growing company with a SaaS stack and several processors | A full inventory with owners, processor list and a simple flow diagram. | The processor list and erasure paths. |
| Regulated or data-heavy business: fintech, health, education, children’s data | A full inventory plus flow maps, cross-border flags and a children’s data flag, reviewed on change. | High-risk activities and breach impact. |
| Likely Significant Data Fiduciary or large enterprise | A governed programme: ownership, change control, audit evidence, DPIA linkage. | Governance and evidence. |
What to do
If you do nothing else, capture these four things for every processing activity. This is enough to answer most of the self-test.
The full set of fields is in the minimum inventory fields table. A free Data Inventory Workbook is planned for this collection.
What to do
Precise wording protects you in policies, proposals and board papers. These are the claims we see most often, with a safer version.
| Claim you may see | Why it is risky | Say instead |
|---|---|---|
| “DPDP mandates a RoPA.” | Imports GDPR Article 30. No general equivalent was found. | “DPDP does not require a RoPA, but a RoPA-style inventory helps meet several duties.” |
| “Data mapping is required for compliance.” | Overstates. It is not named as a duty. | “Data mapping is practically necessary to implement and demonstrate several duties.” |
| “You will be fined for not having a data map.” | Penalties attach to specific duties, not to the absence of a map. | “Without a map you are more likely to fail duties that carry penalties.” |
| “Only Significant Data Fiduciaries need one.” | Section 10 does not name mapping, and other fiduciaries have the same underlying duties. | “SDF duties make mapping harder to avoid, and the same duties apply in lighter form to everyone.” |
| “A consent banner is enough.” | Consent is one control. Erasure, processors and breach response need to know where data sits. | “Consent captures permission. A map shows what that permission covers.” |
Score your readiness against the Act and Rules, then get matched with an implementation partner who can own the mapping work. Prefer to talk scope first? See data mapping services.
FAQ
No. The Act does not name data mapping, a data inventory or a register of processing as an obligation. However, duties such as the Section 11(1) summary of data and sharing, erasure under Section 8(7), processor control under Section 8(1) and breach intimation under Section 8(6) are hard to meet reliably without the information a data map holds.
No. We found no general records-of-processing requirement for ordinary Data Fiduciaries. GDPR Article 30 has one; the DPDP Act does not. A RoPA-style inventory is a useful format, but it should not be described as a DPDP legal requirement.
Section 11(1) is the closest, because it gives a Data Principal a right to a summary of data and processing and a list of those it was shared with. Sections 8(1), 8(2), 8(5), 8(6), 8(7), 6(6), 6(10) and 12 are also much easier to meet and demonstrate with a maintained inventory.
Not for the absence of a map as such. The Schedule attaches penalties to breaches of specific provisions, for example up to Rs 250 crore for failing to take reasonable security safeguards. Having no map makes it more likely you fail such a duty and harder to show the steps you took.
The Act does not exempt small businesses from the underlying duties, and it does not prescribe how much mapping they need. A simple one-page register of purposes, systems, vendors and retention is a proportionate starting point.
Not by name. Section 10(2) requires a notified Significant Data Fiduciary to appoint a Data Protection Officer and an independent data auditor and to undertake periodic Data Protection Impact Assessments and audits. Those tasks are much easier with a current inventory.
We have not relied on any rule as imposing a data mapping or RoPA duty. The Rules cover notices, breach intimation, retention and erasure details, Consent Managers and Significant Data Fiduciary measures. Confirm exact rule wording against the Gazette text before citing it.
For many organisations, yes. What matters is that it names an owner for each activity, is verified against real systems and vendors, and is reviewed when something changes. Move to a tool when the volume of systems or change makes a spreadsheet unreliable.
Use wording such as: “Data mapping is not an express obligation under the DPDP Act, but it is a practical control that supports consent, processor oversight, retention and erasure, rights handling and breach response.” Have counsel confirm it for your own context.
Related
Go to the full method, the legal text and the practical tools. When you are ready to move from records to working controls, see the DPDP implementation framework.
Sources
Consultant-led and partner-backed.