Back to Resources
Guide
Data Mapping Guide
Step-by-step guidance on cataloging personal data across organizational systems under the DPDPA.
- 1
Identify Data Sources
Begin by cataloging every system, application, form, and process within your organization that collects or receives digital personal data. This includes websites, mobile applications, CRM systems, HR platforms, customer support tools, and any third-party integrations. See the definitions for what constitutes personal data under the Act.- List all digital touchpoints where personal data enters the organization.
- Include both automated systems (APIs, web forms) and manual processes (email, physical forms later digitized).
- Document the type of personal data collected at each source (names, emails, phone numbers, financial data, etc.).
- Identify whether data is collected directly from Data Principals or obtained from third parties.
- 2
Classify Personal Data
Categorize the personal data you have identified based on its nature, sensitivity, and the category of Data Principal it relates to. The DPDPA does not create a separate 'sensitive data' category, but certain data types (children's data, health data) may carry additional obligations.- Classify data by type: identity data, contact data, financial data, behavioral data, etc.
- Flag data relating to children (individuals under 18) for enhanced protection requirements.
- Identify data that may be subject to sector-specific regulations (e.g., financial data under RBI guidelines).
- Note any data that is publicly available and may fall outside certain consent requirements.
- 3
Document Data Flows
Map how personal data moves through your organization - from the point of collection through processing, storage, sharing, and eventual deletion. Understanding data flows is essential for identifying risks and ensuring compliance at every stage.- Create data flow diagrams showing data movement between systems, departments, and external parties.
- Identify all storage locations (databases, cloud services, file servers, backup systems).
- Document data sharing arrangements with third parties, including Data Processors and partners.
- Note all cross-border data transfers and the destination countries or territories.
- 4
Assess Legal Basis
For each processing activity, determine and document the lawful basis under the DPDPA. The Act primarily recognizes consent and certain legitimate uses (such as voluntary provision of data, State functions, employment, and medical emergencies).- Map each processing activity to its legal basis: consent, legitimate use under Section 7, or other lawful ground.
- For consent-based processing, verify that consent meets the Act's requirements (free, specific, informed, unambiguous).
- Document the specific purpose for each processing activity - purpose limitation is a core principle.
- Identify processing activities that may require re-consent due to changes in purpose or scope.
- 5
Map Third-Party Relationships
Identify and document all third parties that process personal data on your behalf or receive personal data from you. This includes Data Processors, cloud service providers, analytics vendors, payment processors, and any other external entities.- List all Data Processors and their processing activities on your behalf.
- Verify that contractual agreements with processors include DPDPA compliance obligations.
- Assess whether processors transfer data outside India and to which jurisdictions.
- Evaluate each processor's security measures and breach notification capabilities.
- 6
Establish Governance & Review
Data mapping is not a one-time exercise. Establish governance processes to keep your data inventory current and accurate as your organization evolves, new systems are introduced, and processing activities change.- Assign ownership for maintaining the data map to a specific role or team (e.g., the DPO).
- Schedule periodic reviews (at least annually) to update the data inventory.
- Integrate data mapping updates into project management processes for new systems or features.
- Use the data map to support Data Protection Impact Assessments and compliance audits.
Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
