Every other DPDP obligation assumes you know where personal data lives. This is the map the rest of the platform reads from.
Not the systems you would list in a meeting — the ones you would remember on the third pass.
Eight systems, plus the paper case sheets at reception and the WhatsApp group the doctors use.
Production, the warehouse, the support tool, and the analytics vendor a growth engineer added.
The ATS, the payroll bureau, the background-check agency, and a spreadsheet on a recruiter’s laptop.
Data mapping is not paperwork you do for its own sake. Each of these needs an answer it can only get from an inventory.
Keep personal data secure with reasonable safeguards. You cannot protect a system nobody has written down.
Data RegistryReport a breach to the Board within 72 hours. The first question is which data was affected, and in what.
BreachAnswer a rights request. Finding one person means knowing every system that could be holding them.
RightsErase data once its purpose is served. Retention runs against a catalogue, or it does not run at all.
RetentionKnow what leaves India. A transfer you have not recorded is one you cannot disclose in a notice.
Cross-borderA data inventory that copies your data has doubled your exposure. This one holds metadata and nothing else.
System names, table and column names, data types, who owns them, which category each holds and where it sits. The shape of your estate, not its contents.
No values. Not a name, not an email, not a row, not a sample. The endpoint that takes your schema rejects any field that is not a column name or a type.
A second check reads anything a person types into a note and refuses it if it looks like an email, a phone number, an Aadhaar or a PAN.
This matters commercially as well as legally. A registry holding copies of your records becomes a Data Fiduciary problem of its own — another system in scope, another breach surface, another thing to answer for. Ours cannot be, because there is nothing in it to lose.
Systems hold categories. Activities describe why. The registry keeps all three joined so a question can be answered once.
Everything that holds personal data, including the things nobody counts as a system — a shared drive, an agency’s spreadsheet, the register at reception. Each has an owner, a hosting location and a residency flag.
What kind of personal data each system holds, graded by sensitivity. Health records, financial details and children’s data carry weight the Act gives them, and that weight drives everything downstream.
Why you hold it, on what basis, who it is shared with and for how long. This is the record of processing itself — not a document written once a year, but the thing the rest of the platform reads.
It takes months when you start from an empty spreadsheet. You do not start from an empty spreadsheet.
Pick your industry and the registry opens with the systems, categories and activities a business like yours actually runs. A hospital gets its clinical estate; a lender gets its own.
The work becomes correcting a draft — deleting what you do not have, adding what is missing, naming owners. Reviewing a list is a different job from writing one.
Export your table and column names and the rule library grades them by sensitivity. Every suggestion is reviewed one column at a time before it counts.
Our consultants read your documents, interview your people and walk your premises — and you keep the registry whether or not you buy anything else.
A list of four hundred assets tells you nothing. The registry orders them by what the Act would actually penalise.
A system holding children’s data or health records outranks one holding office contact details, because the Act treats them differently and so should your queue.
A system with no owner, a category with no lawful basis, personal data crossing a border with no notice clause — each surfaces as something to resolve, not a colour on a chart.
Closing a finding records who closed it and why. Accepting a risk deliberately is a defence; having never noticed it is not.
The registry is not a document that sits beside the platform. It is the thing the other modules read.
Each category is linked to the notice that authorises it, so a category with no lawful basis behind it is visible rather than assumed.
A request becomes one task per system that could hold the person, because the registry already knows which systems those are.
When an incident names a system, what it holds and who is affected is already recorded — on the clock that matters.
Erasure schedules attach to categories, so the clock is per kind of data rather than one blunt rule over everything.
The data-mapping dimension of the DPDP Scorecard reads the registry directly instead of asking you to grade yourself.
Built from what you maintain day to day, so producing it is an export rather than a project.
Systems, categories, activities, bases, recipients and retention — drawn from the records your team already keeps current, not typed again into a template.
Anything still in draft or awaiting review is left out. A record of processing that includes guesses is worse than not having one.
Downloading it needs your password again, and every export is written to an audit trail that cannot be edited afterwards.
No adequacy list to check — under the 2025 Rules transfer is permitted except where restricted.
Where it is hosted and whether that is inside India. A vendor console you signed up for in an afternoon is a transfer, and it counts.
The model is a blacklist, not an allow-list. Where the government restricts a country, the registry marks systems hosted there rather than leaving you to notice.
A transfer abroad has to be disclosed. Where a system leaves India and the notice covering it says nothing, that mismatch is raised.
Today the schema comes from you. Direct connectors are being built, and they will read structure only.
Read table and column names straight from your database instead of pasting an export. The same rule library, the same per-column review, no values read.
Surface the tools your teams signed up for without telling anyone, which is where most unmapped personal data actually sits.
Notice when a new column appears in a system already mapped, so the registry keeps pace with your engineering team.
One thing will not change when those ship: none of them will read a value. Discovery works on names and types, because a compliance tool that copies your personal data has made your problem bigger.
Not in those words, and that is the honest answer. No section says “maintain a data inventory”. What the Act does is impose duties that cannot be discharged without one — securing personal data under §8(5), reporting a breach within 72 hours under Rule 7, answering rights requests, erasing data when its purpose ends under §8(7). Every one of those begins with knowing what you hold and where. Significant Data Fiduciaries have the sharpest version of this, because Rule 13 requires an independent audit and an auditor asks for the inventory first.
No, and the product is built so it cannot. The registry holds metadata — system names, table and column names, types, owners, categories, locations. The endpoint that accepts a schema rejects any field that is not a column name or a type, and a second check refuses free text that looks like an email, a phone number, an Aadhaar or a PAN. If you have been shown a data mapping tool that samples rows of your live data to detect personal information, ask where those samples are stored and who can read them.
A working first pass in an afternoon for a single-location business, because the registry opens pre-filled for your sector rather than empty. Confirming and correcting a draft is a different task from composing one. Getting it genuinely complete — every shared drive, every agency, every spreadsheet somebody keeps locally — takes longer, and that is true of any method. We would rather say that than sell you a scan that claims to find things it cannot see.
Anything holding personal data, whatever it runs on. The hospital case makes the point: the registration counter’s paper case sheets are as much in scope as the hospital information system, and neither a scan nor a connector would ever find them. The Act does not care what the data is written on.
Yes. It is assembled from the live registry rather than maintained separately, so it reflects what you actually hold on the day you export it. Only confirmed entries are included — drafts and unreviewed findings are left out. Export requires you to re-enter your password, and each one is written to an audit trail that cannot be edited.
On infrastructure in India, along with everything else. Data at rest, backups included, stays in-country. And because the registry holds only metadata, the question carries less weight here than it would for a tool holding copies of your records.
Real client quotes, attributed by role and sector — we never name a client.
Working across
A registry with systems, categories and activities already in it — the risk queue, the cross-border flags, and a record of processing exported live.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.