Assess · Data Discovery & RoPA

Data Discovery & RoPA

Find where personal data actually sits, then turn it into the record four different people will ask you for.

Scope the discovery One record, four demands Built once, in your own tenant, and yours to keep.
Two things, one exercise

Discovery finds it. The RoPA explains it.

Vendors conflate these constantly, and the difference is the difference between a list and a defence.

01

Discovery — where it is

Every system, drive, inbox, file and piece of paper holding personal data, with an owner, a category and a hosting location against each. The map.

02

RoPA — why you have it

For each activity: the purpose, the lawful basis, whose data it is, who receives it, whether it leaves India, and how long you keep it. The justification.

03

You need both, in that order

A RoPA built without discovery documents the processing somebody remembered. That is the version that survives right up until an auditor asks about the system nobody mentioned.

What we actually do

The engagement, in four steps

Discovery is ours to run. The part that needs your people is short, and it is the part that finds what no scan can.

1

We find where personal data sits

Across your systems, and on the field names and types rather than the values inside them. A discovery run reads structure, never a patient record or a salary.

2

We ask the people who know the rest

The paper file at reception, the WhatsApp group, the personal spreadsheet, the tool somebody expensed. Short conversations, and this is where the surprises are.

3

We write the record itself

Purpose, lawful basis, categories, recipients, retention and transfers — per activity, with provenance and a confidence level against every line.

4

We set it up to stay true

A review cadence, so each entry knows when it was last verified and flags itself when it goes stale. A record nobody trusts is one nobody maintains.

What you end up holding

  • A maintained record of processing activities, in a tenant that is yours
  • An inventory of systems, categories, owners and hosting locations
  • Cross-border transfers identified and checked against what your notice says
  • Provenance, confidence and a last-verified date on every entry
  • Exports in the shapes the four audiences ask for, including a questionnaire answer
  • A review rhythm your own team can run, with or without us

What we do not do

  • Read the contents of your records. Discovery works on names and types, never values
  • Certify you to ISO. That is a separate exercise with an accredited body
  • Leave you with a document that ages quietly and is wrong within a year
  • Charge you again to find the same things next time

Built once, and then used for DPDP, for Article 30 if the EU is in scope, for an ISO 27701 assessment, and for the next customer questionnaire.

Being straight about it

The DPDP Act never asks for a RoPA

No provision names one. Six obligations are undischargeable without it, which is a different and more useful fact.

§8(5)₹250 Cr

Reasonable security safeguards. You cannot protect, encrypt or control access to a system nobody has written down.

Security
§8(6) · Rule 7₹200 Cr

Notify a breach without delay. The first question is whose data was in it, and the answer comes from the map or from guesswork.

Breach
§8(7) · Rule 8₹50 Cr

Erase when the purpose ends. Retention runs per category against a schedule, so without categories it does not run at all.

Retention
§11–14₹50 Cr

Answer a rights request. Finding one person means knowing every system that could be holding them — including the ones nobody lists.

Rights
§10 · Rule 13₹150 Cr

A Significant Data Fiduciary owes a periodic impact assessment and an annual independent audit. The auditor asks for the inventory first.

SDF
§16 · Rule 15₹50 Cr

Know what leaves India and disclose it. A transfer you have not recorded is one your notice cannot mention.

Cross-border

This is worth knowing before you buy from anybody. A vendor telling you the DPDP Act mandates a record of processing has read Article 30 of a different regulation. The real argument is stronger anyway: you cannot do six things the Act does require unless you have one.

The part nobody prices in

Four people will ask you for this

In four formats, at four different times. Most businesses build it four times because nobody told them it was the same underlying record.

1

Your DPDP obligations

The six above. None of them names a record of processing, and not one of them can be discharged without knowing what you hold, why, for how long and who else sees it.

2

GDPR Article 30, if you touch the EU

Here it is named and mandatory, for controllers and processors alike. The small-organisation derogation is narrow — it falls away where processing is regular, risky, or involves special categories, which describes most businesses holding customer data.

3

ISO 27701, and the 27001 asset inventory

A privacy information management system requires you to identify and document your processing of personal information. The same discovery also populates the asset inventory 27001 expects, so one exercise feeds both.

4

Your customer’s procurement team

The one that actually arrives, usually with a deadline attached. What data do you hold on our behalf, where, who else sees it, how long. Answerable in an afternoon from a maintained record, or a fortnight of interviews without one.

This is the honest reason to do the work properly rather than minimally. The cheapest version satisfies nobody twice; a real one is the single artefact you hand to a regulator, an auditor, a certification body and a customer, and each of them gets the answer they wanted.

The finding

What a scan will never return

Automated discovery is genuinely useful for databases. These are the entries a data inventory misses, and they are where the exposure usually is.

01

Paper

The register at reception, consent forms in a drawer, the file that was never scanned. The Act does not care what the data is written on.

02

The local copy

An export on a laptop, a spreadsheet a manager maintains, last quarter’s CSV in a downloads folder. Nobody lists these because nobody calls them systems.

03

The tool bought on a card

Scheduling, surveys, messaging. Never through procurement, holding customer contact details, and invisible to any inventory built from the finance ledger.

04

The people, not the systems

Housekeeping with a key to the records room. A visiting consultant who sees customers weekly. Both are processing personal data whatever their contract says.

05

The agency’s agency

Your marketing partner subcontracts. Your accountable chain does not stop at the party you signed with, and the second link is never on the first list.

So discovery here is people plus tooling. Where you have databases we classify the schema — column names and types, never values. Where you have a building, we walk it.

The record itself

A RoPA that knows when it is stale

Every entry carries where the information came from and when it was last confirmed, which almost no record of processing does.

01

The standard fields

Purpose, lawful basis, categories of personal data, the systems holding it, who receives it, retention period, and whether it crosses a border.

02

Cross-border, and whether you disclosed it

Not just that a transfer happens, but whether the notice covering it actually says so. That mismatch is a finding rather than a footnote.

03

Provenance

Where each entry came from — observed in the walk-through, declared by a system owner, inferred from a schema. You can see which parts rest on somebody’s word.

04

Confidence

How firmly each entry is established. A record that presents a guess and a verified fact identically is the reason most RoPAs cannot be relied on.

05

Last verified, and a review cadence

Entries age. The record shows when each was last confirmed and flags what is overdue, so the document degrades visibly rather than silently.

Built in your tenant, not in our template.

The register and the RoPA live in software you keep and your team maintains. Exportable, and nothing about leaving is designed to be difficult.

Questions

About discovery and RoPA

Does the DPDP Act require a RoPA?

No, and be careful with anyone who tells you otherwise — they are quoting GDPR Article 30, which is a different regulation. No provision of the DPDP Act names a record of processing activities. What the Act does is impose six duties you cannot discharge without one: securing personal data under §8(5), notifying a breach under Rule 7, erasing under §8(7), answering rights requests, the Rule 13 audit if you are a Significant Data Fiduciary, and disclosing cross-border transfers under §16.

We already did this for GDPR. Do we start again?

No — you extend it. An Article 30 record is most of the way there; what it typically lacks is the Indian-specific parts: which processing runs on a §7 legitimate use rather than consent, whether any Fourth Schedule children's exemption applies, retention against Rule 8 classes, and residency in Indian terms rather than adequacy terms. We map what you have and fill the gaps rather than rebuilding it.

Can this satisfy ISO 27701 as well?

It gives you the substance a privacy information management system needs — identified and documented processing of personal information, with purposes, categories, recipients, retention and transfers. Certification is a separate exercise with an accredited body, and we would not describe a record as certifying anything. What we will say is that clients doing both find this is the artefact both auditors ask for, and the discovery also populates the asset inventory 27001 expects.

Do you need access to our databases?

Not to your data. Where you have databases we classify the schema — table and column names and types, never values — and every suggestion is reviewed one column at a time before it counts. Everything the registry holds is metadata. A consultant walking away with copies of your customer records has made your problem larger, not smaller.

How long does it take?

For a single-location business, two to three weeks elapsed with about a day of your team's time inside it. Several sites, several entities or a large system estate takes longer and we say so before quoting. The work is front-loaded: heavy once, then maintained by your own team in minutes when something changes.

What stops it going stale?

Two things. Every entry records when it was last verified and against a review cadence, so the record shows you what is ageing rather than looking equally confident about all of it. And it lives in the platform the other modules read from — so when a notice is published or a vendor agreement lapses, the same record moves. A RoPA maintained in a spreadsheet beside the business is accurate on the day it is written and never again.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Build it once. Use it four times.

The regulator, the auditor, the certification body and your customer’s procurement team are all asking the same question in different words.