Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsDPDP Data Mapping · India
Data mapping finds the personal data your organisation handles and records where it is stored, who can access it and which vendors receive it. It is the practical starting point for notices, consent, rights requests, retention and breach response under the DPDP Act, 2023 and the DPDP Rules, 2025.
Partner-driven, not a one-size-fits-all consultancy. We scope your data mapping first, then match you with a specialist partner suited to your systems, so you don’t buy consulting you don’t need.
Last updated 3 October 2026 · Based on the DPDP Act, 2023 and the DPDP Rules, 2025 · Editorial policy
The problem
Personal data rarely sits in one place. It spreads across your CRM, HRMS, website forms, WhatsApp and email, support tools, analytics, spreadsheets and vendor systems. Under the DPDP Act, your notice has to describe what you collect and why, a withdrawn consent has to be acted on, and erasure has to reach every copy. None of that works reliably until you know what you hold, where it is and who receives it.
Definition
DPDP data mapping is the process of finding the digital personal data your organisation handles and recording where it comes from, why it is collected, where it is stored, who can access it, which vendors receive it, where it travels and when it should be deleted. The result is a data inventory and a set of data-flow maps that your work under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 can be built on.
The DPDP Act does not use the term “data map” or require one as a stand-alone document. Data mapping is an implementation control: it is how organisations make the statutory duties on notice, consent, rights, retention, security and breach response workable in practice.
Why it comes first
Each duty below depends on knowing what data you hold and where it goes.
| DPDP duty | What the data map tells you | Legal basis / status |
|---|---|---|
| Notice | What personal data you collect and for which purposes, so the notice is accurate | Statutory S.5 |
| Consent and withdrawal | Where consent is captured and which systems and vendors must act on a withdrawal | Statutory S.6 |
| Data Principal rights | Where a person’s data sits, so access, correction and erasure requests can be answered | Statutory S.11–14 |
| Retention and erasure | Where copies live, including backups and exports, and when each should go | Statutory S.8(7) + Rules |
| Processors | Which vendors handle personal data on your behalf and need a contract | Statutory S.8(2) |
| Security safeguards | Which systems hold the most sensitive data and need the strongest controls | Statutory S.8(5) + Rules |
| Breach response | Which systems, vendors and people are affected when something goes wrong | Statutory S.8(6) + Rules |
| Cross-border transfers | Whether and where personal data leaves India | Statutory S.16 |
Coverage
Scope is agreed up front. Most projects start with the highest-risk systems and widen from there.
How to do it
A practical sequence that works for most organisations. Start small, then widen.
Pick one business unit or process to start with, such as customer onboarding, HR or marketing, instead of the whole company at once.
List where personal data enters: website and app forms, calls, WhatsApp, email, events and partner feeds.
Interview the people who handle the data every day to learn where it is stored and who it is shared with.
Record how data moves through internal systems, payment gateways and vendors, and any transfers outside India, through to deletion.
Check the map with owners, rank the gaps and set triggers to update it when systems, vendors or purposes change.
Spreadsheets are enough for small estates with a handful of systems. Discovery tools help when there are many systems, a lot of unstructured data or frequent change.
Example and template
An illustrative extract only. Your own map reflects your actual systems and vendors.
| System | Data held | Source | Purpose | Shared with | Retention |
|---|---|---|---|---|---|
| Website enquiry form | Name, work email, phone | Website visitors | Respond to enquiries | CRM vendor, email platform | Per retention schedule |
| HRMS | Employee identity, bank and attendance data | Employees | Payroll and HR administration | Payroll provider | Per retention schedule |
| Marketing automation | Name, email, campaign activity | Leads and subscribers | Send updates people asked for | Email delivery provider | Until consent is withdrawn or the purpose ends |
| Team | Typical personal data | Typical systems | Question to ask |
|---|---|---|---|
| Marketing | Names, emails, phone numbers, campaign and web activity | Marketing automation, website forms, analytics, ad platforms | Where did consent for each list come from, and who else receives it? |
| Sales | Contact and company details, call notes | CRM, email, dialers, WhatsApp | Who holds exports, and where are old leads kept? |
| HR | Identity, bank, attendance, leave and applicant data | HRMS, payroll, recruitment tools | How long are unsuccessful applicant records kept? |
| Customer support | Identity, order history, call recordings, chat logs | Helpdesk, telephony, chat tools | How long are recordings kept, and who can access them? |
| Finance | Customer and vendor identity, bank and tax data | ERP, accounting, payment gateways | Which gateways and advisers receive the data? |
| Product and engineering | Account data, usage logs, device identifiers | Databases, logs, backups, analytics SDKs | Where do logs and test copies of production data end up? |
Partner-driven delivery
DPDPActIndia is a partner-driven platform. We don’t sell a one-size-fits-all consulting package. We define the mapping work first and then, only when you ask, match you with a specialist partner suited to your systems and sector.
STEP 1
Tell us which systems, teams and vendors are involved, or start with the free assessment.
STEP 2
We turn it into a defined piece of work, not a vague enquiry.
STEP 3
Where the work needs specialist delivery, we identify partners suited to it.
STEP 4
You stay in control of whether to work with any provider introduced.
Deliverables
Depending on scope, outputs may include:
Know the difference
Closely linked, but different documents for different readers. Neither is a stand-alone requirement under the DPDP Act.
| Data mapping | RoPA | |
|---|---|---|
| Main question | Where is personal data and how does it move? | Why is each activity carried out, and who is accountable? |
| Focus | Systems, flows, vendors and locations | Purposes, data categories, recipients, retention, safeguards and owners |
| Typical reader | IT, security, data and engineering teams | Legal, privacy, compliance and audit teams |
| Output | Inventory and data-flow maps | A processing-activity register |
The RoPA service has its own page: DPDP RoPA. A data map is the input, and the RoPA is the accountable record built from it.
Avoid these
For context: in an EY India survey reported in February 2026, around 38% of respondents said they had begun categorising personal data and identifying third-party vendors. Source: Social Samosa.
Timing
Sections 18–26 commenced, establishing the Data Protection Board framework.
Consent Manager registration: S.6(9), S.27(1)(d) and Rule 4.
Main Data Fiduciary duties, Data Principal rights and most Board inquiry, adjudication and penalty provisions commence.
Mapping depends on people and systems across several teams. Starting early leaves room for notices, consent, retention and rights processes to be built on an accurate picture.
By sector
The systems and vendors differ by sector. See what the DPDP Act means for yours.
Questions
Ten minutes now shows which areas need attention first, including where a data map would help most.
What’s next
Consultant-led and partner-backed.