Data mapping collection · Why you process it
The DPDP Act lets you process personal data for a lawful purpose with consent, or for certain legitimate uses listed in Section 7. This guide shows how to record, for each processing activity, the purpose, the ground you rely on, the evidence and the owner. It builds on your data inventory. It includes a worked example and a free Excel map.
In short
A purpose and ground map links each processing activity to its specified purpose and to the Section 4 ground that supports it: consent, or one of the nine certain legitimate uses in Section 7. It also records the notice, the consent record, the owner and the route that stops processing. The Act does not require the map. It is the practical way to show, activity by activity, why you hold the data.
The basics
It means recording, for every processing activity, what the purpose is and which Section 4 ground you rely on, so that you can show why each set of personal data is held. The ground is either consent or one of the certain legitimate uses in Section 7. The map sits on top of your personal data inventory, which says what data you hold, and your data flow map, which says where it goes.
In this guide, applicable ground is our plain shorthand for the Section 4 route that supports an activity. The Act's heading for Section 4 is “Grounds for processing personal data”. We avoid “lawful basis” and “legitimate interest”, which are terms from other laws.
| Concept | Core question | What the map records | Where it is covered |
|---|---|---|---|
| Purpose | Why are we processing this personal data? | One specified purpose per activity, in the notice's words | Mapping purpose |
| Legitimate uses | Are we relying on one of the specified uses in Section 7? | The clause, (a) to (i), and a written reason | Mapping legitimate uses |
| Consent | Did we obtain, and can we show, consent where we rely on it? | The notice version, the consent record and the withdrawal route | Mapping consent and evidence |
Read each row as one chain: processing activity, personal data, purpose, consent or the applicable legitimate use, system, evidence, owner. Not every activity needs consent. Each row records the one ground it relies on.
It does not teach consent management. For notice wording, valid consent, records and withdrawal, use the consent management guide, valid consent under Section 6, notice vs consent and how to prove consent. This page is about connecting each activity to its purpose and ground.
The method
Each row follows seven links: activity, personal data, purpose, applicable ground, notice or consent evidence, system and owner. A row with a missing link is a gap. The first four links answer why you process. The last three answer how you can show it and who is responsible.
The law
Section 4 is the gate. It allows processing for a lawful purpose either with consent or for certain legitimate uses. Sections 5 and 6 govern the notice and the consent. Section 7 lists the legitimate uses. The table paraphrases these provisions.
The table is a short paraphrase. It is not a quotation and it is not legal advice. Read the exact words in the Act and the Rules before relying on any row.
| Provision | What it says, in short | What it means for the map |
|---|---|---|
| Section 4 | Personal data may be processed only in accordance with the Act and for a lawful purpose, for which the Data Principal has given consent or for certain legitimate uses. A lawful purpose is one not expressly forbidden by law. | Every row needs one of two grounds: consent or a Section 7 use. |
| Section 2, specified purpose | The purpose mentioned in the notice given to the Data Principal under the Act. | Write the purpose in the notice's words. |
| Section 5 and Rule 3 | A request for consent must be accompanied or preceded by a notice. Rule 3 requires an itemised description of the data, the specified purposes, the goods, services or uses enabled, and how to withdraw consent, exercise rights and complain. | Record the notice version for each purpose. |
| Section 6(1) | Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action. It covers the specified purpose and only the data necessary for it. | One purpose per row. Do not collect extra data under the same consent. |
| Sections 6(4) and 6(6) | Consent can be withdrawn, with ease comparable to giving it. After withdrawal the Data Fiduciary must, within a reasonable time, cease processing and cause its Data Processors to cease, unless the law requires or authorises it. | Record the route that stops processing, including at vendors. |
| Section 6(10) | Where a question arises, the Data Fiduciary must prove that notice was given and that consent was given in line with the Act and Rules. | Attach a consent record to every consent row. |
| Section 7 | A Data Fiduciary may process personal data for any of nine listed uses, clauses (a) to (i). | Quote the clause, and check that your facts fit its words. |
| Section 9 | Separate rules apply to the personal data of a child. | Flag any row that involves a child and read Section 9 first. |
What we found no provision for: a requirement to keep a purpose and ground map, a ground called legitimate interest, or a separate ground for performing a contract. The map is a practical tool. It is not a legal duty, and the ground you record is your own documented view.
Write it well
A mappable purpose is specific, covers one thing, and uses the same words as the notice. Vague purposes make the ground impossible to judge, because you cannot test whether an activity stays inside a purpose that has no edges.
| Weak | Better | Why |
|---|---|---|
| Business purposes | Process the order and arrange delivery | Says what actually happens to the data. |
| Marketing and improvement | Send offers by email; measure which pages are used | Two purposes, two rows, probably two grounds. |
| Legal compliance | Keep invoices as required by a named law | Names the source, so the retention rule can cite it. |
When a purpose changes, add a new row. Do not edit the old one in place. The new purpose needs its own notice wording and its own ground, and the old row keeps the history.
Keep them apart
Section 4 is the framework with two grounds. Section 7 is the list that fills in the second ground. Consent is the first ground. Certain legitimate uses is the second, and Section 7 says what those uses are. They are not three separate routes, and Section 7 is not the Act's version of “legitimate interest”.
Lawful basis and legitimate interest come from the GDPR. The Act speaks of grounds for processing and certain legitimate uses, and Section 7 is a closed list of nine named uses. Contract is not a ground in the Act either. For a service activity, the question is whether consent or a Section 7 clause fits, and for many service activities the clause to examine is 7(a). Whether it fits depends on the facts, so get legal advice for hard cases.
| Clause | Use in short |
|---|---|
| 7(a) | The specified purpose for which the person voluntarily provided her data, where she has not indicated that she does not consent to that use. |
| 7(b) | The State and its instrumentalities giving a prescribed subsidy, benefit, service, certificate, licence or permit (Rule 5 and the Second Schedule apply). |
| 7(c) | The State performing a function under a law, or acting in the interest of sovereignty, integrity or security. |
| 7(d) | Meeting a legal obligation to disclose information to the State or its instrumentalities. |
| 7(e) | Complying with a judgment, decree or order, including certain orders on contractual or civil claims under a law outside India. |
| 7(f) | Responding to a medical emergency involving a threat to life or an immediate threat to health. |
| 7(g) | Medical treatment or health services during an epidemic, outbreak or other public health threat. |
| 7(h) | Safety, assistance or services during a disaster or a breakdown of public order. |
| 7(i) | Employment, and safeguarding the employer from loss or liability. |
Clause 7(d) is narrower than “any legal obligation”. It speaks of an obligation to disclose information to the State. A law that makes you keep records is a different point: Section 8(7) allows retention where it is necessary for compliance with law, and our retention and erasure mapping guide covers that. Exemptions under Section 17 are also separate from Section 7. Map them only after legal advice.
Decide
Ask where the data came from, whether a Section 7 clause fits its words, whether you can ask for consent for this purpose alone, whether the purpose is in the notice, and whether a child is involved. If the answer is unclear, write To confirm and ask for legal advice. Do not guess.
Prove it
The evidence depends on the ground: for consent, the notice version and the consent record; for Section 7(a), the source and any notice; for other clauses, the clause, the legal source and who approved. The map points to the evidence. It does not replace it.
| Ground | Attach to the row | Stop route |
|---|---|---|
| Consent | Notice version and date; consent record (who, when, what they saw, what they did); withdrawal log. | Withdrawal as easy as giving consent (Section 6(4)), reaching systems and vendors (Section 6(6)). |
| Section 7(a) | That the person gave the data herself for this purpose; the notice, if you gave one; any record that she objected. | The use ends if she indicates she does not consent to it. |
| Other Section 7 clause | The clause; the law, order or emergency that fits it; the limit of what you may do; who approved. | The clause's own end point, for example the order being met. |
Section 5 ties notice to requests for consent, and Rule 3 describes the notice as giving the details needed for specific and informed consent. Yet the Act defines the specified purpose by the notice, and Section 7(a) refers to the specified purpose. We found no provision that settles whether every Section 7 use needs a notice. Many advisers suggest giving one anyway. Take legal advice for your case, and use the notice column to see where there is none.
Worked example
Seven activities, each with a purpose, a ground, a reason and its evidence, and four of them with a gap that a first pass would find. The rows are fictional and show how to fill in the map. The grounds are not legal conclusions for any real business.
| Activity | Personal data | Source | Specified purpose | Applicable ground and reason | Notice and consent evidence | System and owner | Gap flag |
|---|---|---|---|---|---|---|---|
| M-001 Customer account · PA-002 | Name, email, phone, address | Given by the person for this purpose | Run the customer account and show past orders | Consent The account is optional. The customer ticks a box at sign-up for this purpose only. | Notice: N-02 v2, 1 Sep 2026 Consent record: Sign-up checkbox log, time-stamped Approved: Legal counsel, 2 Oct 2026 | Web shop, order database Customer team | None |
| M-002 Order fulfilment · PA-001 | Name, delivery address, phone, items ordered | Given by the person for this purpose | Deliver the order | S7(a) Voluntarily provided The customer gave the address to receive this order and has not objected. | Notice: N-02 v2, 1 Sep 2026 Consent record: none Approved: Legal counsel, 2 Oct 2026 | Order database, courier portal Operations | None |
| M-003 Newsletter · PA-003 | Name, email | Given by the person for another purpose | Send offers and the newsletter | Consent Marketing is a different purpose from the order, so it needs its own consent. | Notice: N-03 v1, 1 Sep 2026 Consent record: none Approved: Marketing head, 2 Oct 2026 | Email platform Marketing | No consent record |
| M-004 Support tickets · PA-004 | Name, email, order number, message | Given by the person for this purpose | Answer the customer query | S7(a) Voluntarily provided The customer wrote in to get help and has not objected. | Notice: N-02 v2, 1 Sep 2026 Consent record: none Approved: no | Helpdesk software Support | Ground not approved |
| M-005 Server access logs · PA-006 | IP address, user ID, time | Collected automatically | Detect and investigate unauthorised access | To confirm (no reason written) | Notice: none Consent record: none Approved: no | Web server, log store IT | Ground to confirm |
| M-006 CVs sent by recruiters · PA-008 | CV, contact details | Received from a third party | Assess candidates for the open role | S7(a) Voluntarily provided The recruiter sent the CV for this role. | Notice: none Consent record: none Approved: HR head, 2 Oct 2026 | Hiring tool HR | 7(a) needs data given for this purpose |
| M-007 Payroll and staff records · PA-007 | Name, bank details, salary, attendance | Given by the person for this purpose | Pay salaries and manage employment | S7(i) Employment The processing is for employment purposes. | Notice: Staff notice v1, 1 Apr 2026 Consent record: none Approved: HR head and counsel, 2 Oct 2026 | HR system HR | None |
The flags show the first gap found in each row.
The retention and erasure guide set every example row to consent, to keep that page simple. Here the choice is examined. A real business should decide each row on its own facts.
Build and use it
The map is one working sheet with 18 fields, a filled example, gap flags and a summary. Enter your details and your download link appears on the next page.
Excel (.xlsx), about 21 KB. Sheets: Start here, Map (60 rows), Example, Summary, Lists. Gap flags are formulas. The example is fictional and its grounds are not legal conclusions.
The 18 fields fall into five groups. Identify: map ID, activity ID, activity, personal data, whose data. Source and purpose: how the data reached you, the specified purpose. Ground: the applicable ground, why it applies, who approved it. Evidence: notice version, consent record, child data. Run: systems, processor IDs, owner, the route that stops processing, last verified date. It uses the same activity IDs as the inventory and the same processor IDs as the flow worksheet.
A gap flag shows the first gap found in a row. It is a prompt to check, not a finding of non-compliance. A row is flagged when it has no purpose, a ground still to confirm, a Section 7(a) ground on data the person did not give for this purpose, a consent ground with no record, no notice recorded, no written reason, no approver, child data, no owner, no stop route or no verification date.
Build and use it
Pull the activities from your inventory, write each purpose in the notice's words, record the data source, choose and justify the ground, attach the evidence and stop route, then review the gaps. Each step has an output you can check.
Build and use it
Most weak maps use one ground for everything, borrow terms from other laws or leave out the evidence. These seven are the usual causes.
| Mistake | Why it hurts | Fix |
|---|---|---|
| 1. Setting every row to consent | Consent can be withdrawn and must be provable. It is not the only ground, and a weak consent is a weak ground. | Decide each row on its facts, and record the reason. |
| 2. Treating 7(a) as a catch-all | It covers data the person provided for the specified purpose, not every use of any data. | Check the source and the purpose before using it. |
| 3. Importing GDPR terms | Lawful basis and legitimate interest are not Act terms, and the reasoning does not carry over. | Use consent and the named Section 7 clauses. |
| 4. Bundling purposes | One ground cannot cover two different purposes. | One purpose per row. |
| 5. Choosing a ground with no reason or approver | Nobody can review or defend it. | Write one sentence and name the approver. |
| 6. Mapping the ground but not the stop route | A withdrawal or objection does not reach every system. | Record the route and the vendors it must reach. |
| 7. Skipping child data | Section 9 sets separate rules. | Flag the row and read Section 9 first. |
Questions
It means recording, for each processing activity, the specified purpose, the Section 4 ground you rely on (consent or a Section 7 use), the evidence and the owner. We found no provision that requires it. It is a practical way to show why you hold each set of data.
No. Section 4 allows processing for a lawful purpose with the Data Principal's consent or for certain legitimate uses. Section 7 lists nine such uses. Which ground applies depends on the facts. Where no Section 7 clause fits, consent is the route.
We found no ground called legitimate interest. The Act speaks of certain legitimate uses and lists nine of them in Section 7. They are named and narrow, and they are not a general business-interest test. Do not carry over reasoning from other laws.
Section 4 sets the two grounds for processing: consent, or certain legitimate uses. Section 7 lists what those legitimate uses are. Section 7 therefore sits inside the framework of Section 4 and does not stand beside it.
No. Section 7(a) covers the specified purpose for which the person voluntarily provided her data, where she has not indicated that she does not consent to that use. The Act's own illustration is a pharmacy using a phone number given for a receipt to send the receipt. A different purpose, such as marketing, or data that came from someone else, is outside that wording and needs a separate look.
We found no separate ground for performing a contract. For a service activity, the question is whether consent or a Section 7 clause fits the facts. Many service activities are examined under Section 7(a). Whether it fits is a legal judgment, so take advice and record who approved the call.
Section 5 ties notice to requests for consent, and Rule 3 describes notice content for specific and informed consent. The Act also defines the specified purpose by reference to a notice. We found no provision that settles whether every Section 7 use needs one. Many advisers suggest giving a notice anyway, so take legal advice for your case.
We found no express duty to keep a record of processing activities. Section 6(10) does place the burden of proving notice and consent on the Data Fiduciary, which is a practical reason to keep records. See data mapping vs data inventory vs RoPA for the comparison.
Add a new row. Consent is specific to a purpose under Section 6(1), so on a plain reading consent for the old purpose does not stretch to the new one. The new purpose needs its own notice wording and ground.
The stop route column shows how a withdrawal reaches each activity and vendor. Under Section 6(6), after withdrawal you must cease processing within a reasonable time and cause processors to cease, unless the law requires or authorises otherwise. Erasure is a separate step under Section 8(7). See consent withdrawal and retention and erasure mapping.
Related
Go to the full method, the legal text and the practical tools. When you are ready to move from records to working controls, see the DPDP implementation framework.
Sources
Consultant-led and partner-backed.