Data mapping & registry

You cannot protect what you cannot find

Every other DPDP obligation assumes you know where personal data lives. This is the map the rest of the platform reads from.

Book a demo See what we never store Or check your DPDP score first — free, five minutes, no account.
Sound familiar?

Where does personal data actually live?

Not the systems you would list in a meeting — the ones you would remember on the third pass.

Hospital or clinic

Eight systems, plus the paper case sheets at reception and the WhatsApp group the doctors use.

SaaS or platform

Production, the warehouse, the support tool, and the analytics vendor a growth engineer added.

HR, staffing or payroll

The ATS, the payroll bureau, the background-check agency, and a spreadsheet on a recruiter’s laptop.

Why this comes first

Four obligations that fail without it

Data mapping is not paperwork you do for its own sake. Each of these needs an answer it can only get from an inventory.

§8(5)₹250 Cr

Keep personal data secure with reasonable safeguards. You cannot protect a system nobody has written down.

Data Registry
§8(6)₹200 Cr

Report a breach to the Board within 72 hours. The first question is which data was affected, and in what.

Breach
§11–§14₹50 Cr

Answer a rights request. Finding one person means knowing every system that could be holding them.

Rights
§8(7)₹50 Cr

Erase data once its purpose is served. Retention runs against a catalogue, or it does not run at all.

Retention
§16₹50 Cr

Know what leaves India. A transfer you have not recorded is one you cannot disclose in a notice.

Cross-border
The line we drew

We hold the map, never the territory

A data inventory that copies your data has doubled your exposure. This one holds metadata and nothing else.

01

What goes in

System names, table and column names, data types, who owns them, which category each holds and where it sits. The shape of your estate, not its contents.

02

What never goes in

No values. Not a name, not an email, not a row, not a sample. The endpoint that takes your schema rejects any field that is not a column name or a type.

03

Why it is enforced, not promised

A second check reads anything a person types into a note and refuses it if it looks like an email, a phone number, an Aadhaar or a PAN.

This matters commercially as well as legally. A registry holding copies of your records becomes a Data Fiduciary problem of its own — another system in scope, another breach surface, another thing to answer for. Ours cannot be, because there is nothing in it to lose.

The inventory

Three layers, one record

Systems hold categories. Activities describe why. The registry keeps all three joined so a question can be answered once.

1

Systems

Everything that holds personal data, including the things nobody counts as a system — a shared drive, an agency’s spreadsheet, the register at reception. Each has an owner, a hosting location and a residency flag.

2

Categories

What kind of personal data each system holds, graded by sensitivity. Health records, financial details and children’s data carry weight the Act gives them, and that weight drives everything downstream.

3

Processing activities

Why you hold it, on what basis, who it is shared with and for how long. This is the record of processing itself — not a document written once a year, but the thing the rest of the platform reads.

app.ruleexpert.in/registry/catalogue
The data catalogue screen, listing data categories with their sensitivity grade and the systems that hold each one.
The objection

“Mapping our estate will take months”

It takes months when you start from an empty spreadsheet. You do not start from an empty spreadsheet.

01

Your sector arrives pre-filled

Pick your industry and the registry opens with the systems, categories and activities a business like yours actually runs. A hospital gets its clinical estate; a lender gets its own.

02

You confirm rather than compose

The work becomes correcting a draft — deleting what you do not have, adding what is missing, naming owners. Reviewing a list is a different job from writing one.

03

Paste a schema, get a classification

Export your table and column names and the rule library grades them by sensitivity. Every suggestion is reviewed one column at a time before it counts.

The assessment that makes the rest of it possible.

Our consultants read your documents, interview your people and walk your premises — and you keep the registry whether or not you buy anything else.

Risk

An inventory that ranks itself

A list of four hundred assets tells you nothing. The registry orders them by what the Act would actually penalise.

01

Weighted by sensitivity

A system holding children’s data or health records outranks one holding office contact details, because the Act treats them differently and so should your queue.

02

Gaps become findings

A system with no owner, a category with no lawful basis, personal data crossing a border with no notice clause — each surfaces as something to resolve, not a colour on a chart.

03

Resolved, with a reason

Closing a finding records who closed it and why. Accepting a risk deliberately is a defence; having never noticed it is not.

Downstream

Mapped once, used by everything

The registry is not a document that sits beside the platform. It is the thing the other modules read.

01

Consent knows what it covers

Each category is linked to the notice that authorises it, so a category with no lawful basis behind it is visible rather than assumed.

02

Rights requests fan out

A request becomes one task per system that could hold the person, because the registry already knows which systems those are.

03

Breach scoping starts answered

When an incident names a system, what it holds and who is affected is already recorded — on the clock that matters.

04

Retention runs per category

Erasure schedules attach to categories, so the clock is per kind of data rather than one blunt rule over everything.

05

Your score reflects reality

The data-mapping dimension of the DPDP Scorecard reads the registry directly instead of asking you to grade yourself.

Evidence

A record of processing, on demand

Built from what you maintain day to day, so producing it is an export rather than a project.

01

Assembled from the live registry

Systems, categories, activities, bases, recipients and retention — drawn from the records your team already keeps current, not typed again into a template.

02

Confirmed entries only

Anything still in draft or awaiting review is left out. A record of processing that includes guesses is worse than not having one.

03

Re-authentication before export

Downloading it needs your password again, and every export is written to an audit trail that cannot be edited afterwards.

app.ruleexpert.in/registry/activities
The processing activities screen, showing each activity with its purpose, lawful basis, recipients and retention period.
§16 · Rule 15

What leaves India, and what that requires

No adequacy list to check — under the 2025 Rules transfer is permitted except where restricted.

01

Every system carries a location

Where it is hosted and whether that is inside India. A vendor console you signed up for in an afternoon is a transfer, and it counts.

02

Restricted destinations are flagged

The model is a blacklist, not an allow-list. Where the government restricts a country, the registry marks systems hosted there rather than leaving you to notice.

03

Notices are checked against it

A transfer abroad has to be disclosed. Where a system leaves India and the notice covering it says nothing, that mismatch is raised.

On the roadmap

What is coming, said plainly

Today the schema comes from you. Direct connectors are being built, and they will read structure only.

Direct database connectors

Coming soon

Read table and column names straight from your database instead of pasting an export. The same rule library, the same per-column review, no values read.

SaaS estate discovery

Coming soon

Surface the tools your teams signed up for without telling anyone, which is where most unmapped personal data actually sits.

Continuous re-scan

Coming soon

Notice when a new column appears in a system already mapped, so the registry keeps pace with your engineering team.

One thing will not change when those ship: none of them will read a value. Discovery works on names and types, because a compliance tool that copies your personal data has made your problem bigger.

Questions

About data mapping

Does the DPDP Act require a data inventory?

Not in those words, and that is the honest answer. No section says “maintain a data inventory”. What the Act does is impose duties that cannot be discharged without one — securing personal data under §8(5), reporting a breach within 72 hours under Rule 7, answering rights requests, erasing data when its purpose ends under §8(7). Every one of those begins with knowing what you hold and where. Significant Data Fiduciaries have the sharpest version of this, because Rule 13 requires an independent audit and an auditor asks for the inventory first.

Do you connect to our databases and read our data?

No, and the product is built so it cannot. The registry holds metadata — system names, table and column names, types, owners, categories, locations. The endpoint that accepts a schema rejects any field that is not a column name or a type, and a second check refuses free text that looks like an email, a phone number, an Aadhaar or a PAN. If you have been shown a data mapping tool that samples rows of your live data to detect personal information, ask where those samples are stored and who can read them.

How long does the first map actually take?

A working first pass in an afternoon for a single-location business, because the registry opens pre-filled for your sector rather than empty. Confirming and correcting a draft is a different task from composing one. Getting it genuinely complete — every shared drive, every agency, every spreadsheet somebody keeps locally — takes longer, and that is true of any method. We would rather say that than sell you a scan that claims to find things it cannot see.

What counts as a system?

Anything holding personal data, whatever it runs on. The hospital case makes the point: the registration counter’s paper case sheets are as much in scope as the hospital information system, and neither a scan nor a connector would ever find them. The Act does not care what the data is written on.

Can we export a record of processing?

Yes. It is assembled from the live registry rather than maintained separately, so it reflects what you actually hold on the day you export it. Only confirmed entries are included — drafts and unreviewed findings are left out. Export requires you to re-enter your password, and each one is written to an audit trail that cannot be edited.

Where does the registry itself live?

On infrastructure in India, along with everything else. Data at rest, backups included, stays in-country. And because the registry holds only metadata, the question carries less weight here than it would for a tool holding copies of your records.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

See an estate already mapped.

A registry with systems, categories and activities already in it — the risk queue, the cross-border flags, and a record of processing exported live.