Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

DPDP RoPA · India

DPDP RoPA: Build a Record of Processing Activities You Can Stand Behind

A RoPA, or Record of Processing Activities, is a register of what personal data your organisation processes, why, who receives it, how long it is kept and who is accountable. The DPDP Act, 2023 does not require one by name, but it is the clearest way to show your processing is organised and defensible.

Partner-driven delivery. We scope your RoPA first, then match you with a specialist partner suited to your sector, so you get the right depth of work without paying for the wrong one.

A RoPA register built from a data map, with fields for purpose, data, recipients, retention and owner A data map feeds a register of processing activities. Each row records the activity, purpose, data categories, recipients, retention and an accountable owner, and the register is reviewed on a schedule. Data map where data is Register of processing activities ACTIVITYPURPOSEDATAOWNER PayrollPay staffBank, IDHR NewsletterUpdatesEmailMktg EnquiriesRespondName, phoneSales SupportResolveChat logsCX Recipients Retention Safeguards Reviewed on a schedule Updated when systems, vendors or purposes change
ForLegal, privacy, compliance and audit teams
ScopeEvery processing activity
OutputA living processing register
DeliverySpecialist partners matched to your scope
Statutory statusGood practice, not named in the DPDP Act

DPDP RoPA in short

What it is
A register of your processing activities: purpose, personal data involved, recipients, retention, safeguards and the person accountable for each.
Is it required?
The DPDP Act, 2023 and the DPDP Rules, 2025 do not require a RoPA by name. The concept comes from GDPR Article 30. Many organisations keep one because it supports accountability and makes the DPDP duties easier to meet and evidence.
What you get
A completed RoPA, ownership and review rules, and a list of gaps it exposes.
Who does the work
You, with specialist partners matched through DPDPActIndia where the work needs them. We scope first and you decide whether to proceed.
Start from
Your data map. The map shows where data is; the RoPA records why it is processed.

Last updated 3 October 2026 · Based on the DPDP Act, 2023 and the DPDP Rules, 2025 · Editorial policy

Definition

What is a RoPA under the DPDP Act?

A RoPA is a structured register of the ways your organisation processes personal data. For each activity, such as payroll, a newsletter or customer support, it records the purpose, the categories of personal data involved, who the data comes from, who receives it, how long it is kept, the safeguards in place and the person accountable. A RoPA is closely related to a data map, but it answers a different question: not where the data is, but why it is being processed.

At a glance

  • Also called: record of processing, processing register, ROPA
  • Typical owner: privacy, legal or compliance lead
  • Main output: a processing-activity register
  • Legal status: good practice under DPDP
  • Built from: your data map

Is it required?

Is a RoPA mandatory under the DPDP Act?

Not by name. But several statutory duties are hard to meet or evidence without one.

DPDP dutyHow a RoPA helpsLegal basis / status
NoticeLists the purposes and data categories the notice must describeStatutory S.5
ConsentShows which activities rely on consent and which on certain legitimate usesStatutory S.6 and S.7
Accuracy and retentionRecords how long each category is kept and whyStatutory S.8(3) and S.8(7)
ProcessorsIdentifies who processes data on your behalfStatutory S.8(2)
Security safeguardsRecords the safeguards applied to each activityStatutory S.8(5) + Rules
Data Principal rightsShows where to look when a request arrivesStatutory S.11–14
Accountability to the BoardGives you an organised record if the Data Protection Board asks how you process dataPractical

Fields

What should a DPDP RoPA record?

A useful RoPA has one row per processing activity, with these fields.

FieldWhat to recordWhy it matters
ActivityThe processing activity, for example payrollGives each row a clear owner
PurposeWhy the data is processedSupports notice and purpose limits
BasisConsent or a certain legitimate useShows why processing is permitted
Data PrincipalsWhose data: customers, employees, applicantsSets who the notice goes to
Data categoriesThe kinds of personal data involvedLinks to security and retention choices
SourceWhere the data comes fromHelps answer access requests
RecipientsProcessors and other parties who receive itDrives processor contracts
TransfersAny transfer outside IndiaSupports review under S.16
RetentionHow long it is kept and the deletion triggerSupports erasure and S.8(7)
SafeguardsSecurity controls appliedEvidences S.8(5)
OwnerThe accountable person or teamMakes updates someone’s job
Last reviewedDate of the last checkShows the record is current

How to do it

How to create a RoPA, step by step.

Start from your data map if you have one. If not, the first steps build it.

1

List your activities

Identify what your teams do with personal data, such as payroll, marketing, support and recruitment.

2

Start from the data map

Pull in the systems, data categories and vendors for each activity from your data map.

3

Record the purpose and basis

Write down why each activity happens and whether it relies on consent or a certain legitimate use.

4

Assign an owner

Name one accountable person for each row, then confirm the details with them.

5

Review on a schedule

Set a review cycle and triggers for change, such as a new vendor, system or purpose.

Start with the activities that carry the most risk or the most data. A RoPA that is accurate for ten activities is more useful than one that is vague for a hundred.

Example and template

DPDP RoPA example and template structure.

An illustrative extract only. Your own RoPA reflects your actual activities, and the basis for each should be confirmed with your legal adviser.

ActivityPurposeBasisData categoriesRecipientsRetentionOwner
NewsletterSend updates people asked forConsent (S.6)Name, emailEmail delivery providerUntil consent is withdrawnMarketing
Enquiry handlingRespond to website enquiriesConsent (S.6)Name, work email, phoneCRM vendorPer retention scheduleSales
PayrollPay employeesTo be confirmed with counsel (consent or certain legitimate use, S.7)Identity, bank and attendance dataPayroll providerPer retention scheduleHR

RoPA by function: where to start

FunctionTypical activities to recordTypical recipients
HRRecruitment, onboarding, payroll, attendance, background checksPayroll provider, HRMS vendor, verification agency
MarketingNewsletters, campaigns, lead capture, analyticsEmail platform, ad platforms, analytics vendor
SalesEnquiry handling, quotations, account managementCRM vendor, dialer and messaging providers
Customer supportTicketing, call recording, chat, complaintsHelpdesk, telephony and chat providers
FinanceInvoicing, collections, vendor paymentsPayment gateway, banks, accountants
Product and ITAccount management, logging, backups, testingCloud, monitoring and analytics providers

Know the difference

DPDP vs GDPR Article 30: how RoPA differs.

Useful if you already keep a RoPA for GDPR purposes.

GDPR Article 30DPDP Act, 2023
Record required by lawYes, for many controllers and processorsNot by name
Basis termsIncludes legitimate interestsConsent and certain legitimate uses (S.7). It has no GDPR-style “legitimate interests”
RegulatorSupervisory authoritiesData Protection Board of India
Practical useCompulsory registerAccountability and evidence for notices, consent, rights, retention and security

An existing GDPR RoPA is a good starting point, but the basis column and the notice, consent and Board-related fields need to be re-mapped to the DPDP Act.

Know the difference

RoPA vs data mapping.

Data mappingRoPA
Main questionWhere is personal data and how does it move?Why is each activity carried out, and who is accountable?
FocusSystems, flows, vendors and locationsPurposes, categories, recipients, retention, safeguards and owners
Typical readerIT, security, data and engineering teamsLegal, privacy, compliance and audit teams

The data mapping service has its own page: DPDP Data Mapping. A data map is the input and the RoPA is the accountable record built from it.

Partner-driven delivery

We scope it. Specialist partners deliver it. You decide.

DPDPActIndia is a partner-driven platform. We don’t sell a one-size-fits-all consulting package. We define the RoPA work first and then, only when you ask, match you with a specialist partner suited to your sector and size.

STEP 1

You describe the need

Tell us which teams and activities are involved, or start with the free assessment.

STEP 2

We scope the RoPA

We turn it into defined work, not a vague enquiry.

STEP 3

We match a specialist partner

Where the work needs specialist delivery, we identify partners suited to it.

STEP 4

You decide whether to proceed

You stay in control of whether to work with any provider introduced.

Which specialist for which part

  • Purposes, basis, notices and contracts: privacy and legal specialist
  • Discovery behind the register: data governance specialist
  • Safeguards recorded for each activity: cybersecurity specialist
  • Ongoing ownership or a DPO appointment: appropriate DPO specialist via DPOIndia
We may work with specialist service and technology providers depending on the requirement. Organisations remain free to decide whether to proceed with any provider introduced through the platform. Looking for one now? Find your DPDP Act implementation partner.

Deliverables

A register your teams will keep up to date.

Depending on scope, outputs may include:

  • A completed RoPA covering your processing activities
  • Purpose and basis recorded for each activity
  • Recipient and processor list linked to each activity
  • Retention periods and deletion triggers
  • Named owners and a review cycle
  • A gap list covering notices, consent, contracts and retention

Avoid these

Common RoPA mistakes.

  • Building a RoPA without a data map, so entries are guesses
  • Copying a GDPR RoPA without re-checking the basis and notice fields
  • Describing purposes too broadly, such as “business operations”
  • Leaving out processors and sub-processors
  • No owner for each row, so the record is never updated
  • Treating it as a one-off document instead of a living register

Timing

Why build a RoPA now?

13 Nov 2025

Board framework

Sections 18–26 commenced, establishing the Data Protection Board framework.

13 Nov 2026

Consent Manager milestone

Consent Manager registration: S.6(9), S.27(1)(d) and Rule 4.

13 May 2027

Substantive duties

Main Data Fiduciary duties, Data Principal rights and most Board inquiry, adjudication and penalty provisions commence.

By sector

RoPA by sector.

The activities and vendors differ by sector. See what the DPDP Act means for yours.

Questions

Frequently asked questions about the DPDP RoPA.

What is a RoPA under the DPDP Act?
A RoPA, or Record of Processing Activities, is a register of what personal data an organisation processes and why. For each activity it records the purpose, data categories, recipients, retention, safeguards and the person accountable. The DPDP Act does not use the term, but a RoPA supports its duties on notice, consent, rights, retention and security.
Is a RoPA mandatory under the DPDP Act?
No. The DPDP Act, 2023 and the DPDP Rules, 2025 do not require a stand-alone RoPA by name. The concept comes from GDPR Article 30. Many organisations keep one because it makes the statutory DPDP duties easier to meet and to evidence.
What should a DPDP RoPA include?
For each processing activity: the purpose, the basis (consent or a certain legitimate use), whose data it is, the data categories, the source, recipients and processors, any transfer outside India, the retention period, the safeguards applied, an accountable owner and the date last reviewed.
What is the difference between a RoPA and a data map?
A data map shows where personal data is and how it moves between systems and vendors. A RoPA records why each activity is carried out, along with data categories, recipients, retention, safeguards and ownership. The data map is the input to the RoPA.
What is the difference between a RoPA under the DPDP Act and GDPR Article 30?
GDPR Article 30 requires many controllers and processors to keep a record of processing. The DPDP Act does not require one by name. DPDP also uses consent and certain legitimate uses rather than GDPR legitimate interests, so the basis fields in a GDPR RoPA need to be re-mapped.
How do you create a RoPA step by step?
List your processing activities, pull in systems and vendors from your data map, record the purpose and basis for each activity, assign an owner, confirm the details with that owner and set a review schedule. The step-by-step section on this page sets this out in more detail.
Is there a DPDP RoPA template?
The example and field tables on this page show a workable structure. A template only helps if the information in it is accurate, which is why a data map usually comes first.
Who is responsible for maintaining the RoPA?
Typically a privacy, legal or compliance lead owns the register as a whole, while each row has an accountable owner in the team that runs the activity. A named owner per row is what keeps the record up to date.
How often should a RoPA be updated?
On a set schedule, such as every six or twelve months, and whenever something changes: a new system, vendor, purpose or type of data. Treat it as a living register, not a one-off document.
Does a RoPA need to include processors and cross-border transfers?
Good practice is yes. Recording processors supports the processor duties in S.8(2), and recording transfers outside India supports review under S.16. The RoPA records the facts; it does not decide whether a transfer is lawful.
How much does a RoPA project cost?
It is scoped to your organisation. Cost depends on the number of entities, business units, activities and vendors, and on whether a data map already exists. The free assessment is a useful first step.
Who builds the RoPA, DPDPActIndia or a partner?
DPDPActIndia is partner-driven. We help you scope the RoPA work and, when you ask, introduce specialist partners suited to your sector and size. You decide whether to proceed with any of them.

Start where you actually are.

Ten minutes now shows which areas need attention first, including where a RoPA would help most.