Find where personal data actually sits, then turn it into the record four different people will ask you for.
Vendors conflate these constantly, and the difference is the difference between a list and a defence.
Every system, drive, inbox, file and piece of paper holding personal data, with an owner, a category and a hosting location against each. The map.
For each activity: the purpose, the lawful basis, whose data it is, who receives it, whether it leaves India, and how long you keep it. The justification.
A RoPA built without discovery documents the processing somebody remembered. That is the version that survives right up until an auditor asks about the system nobody mentioned.
Discovery is ours to run. The part that needs your people is short, and it is the part that finds what no scan can.
Across your systems, and on the field names and types rather than the values inside them. A discovery run reads structure, never a patient record or a salary.
The paper file at reception, the WhatsApp group, the personal spreadsheet, the tool somebody expensed. Short conversations, and this is where the surprises are.
Purpose, lawful basis, categories, recipients, retention and transfers — per activity, with provenance and a confidence level against every line.
A review cadence, so each entry knows when it was last verified and flags itself when it goes stale. A record nobody trusts is one nobody maintains.
Built once, and then used for DPDP, for Article 30 if the EU is in scope, for an ISO 27701 assessment, and for the next customer questionnaire.
No provision names one. Six obligations are undischargeable without it, which is a different and more useful fact.
Reasonable security safeguards. You cannot protect, encrypt or control access to a system nobody has written down.
SecurityNotify a breach without delay. The first question is whose data was in it, and the answer comes from the map or from guesswork.
BreachErase when the purpose ends. Retention runs per category against a schedule, so without categories it does not run at all.
RetentionAnswer a rights request. Finding one person means knowing every system that could be holding them — including the ones nobody lists.
RightsA Significant Data Fiduciary owes a periodic impact assessment and an annual independent audit. The auditor asks for the inventory first.
SDFKnow what leaves India and disclose it. A transfer you have not recorded is one your notice cannot mention.
Cross-borderThis is worth knowing before you buy from anybody. A vendor telling you the DPDP Act mandates a record of processing has read Article 30 of a different regulation. The real argument is stronger anyway: you cannot do six things the Act does require unless you have one.
In four formats, at four different times. Most businesses build it four times because nobody told them it was the same underlying record.
The six above. None of them names a record of processing, and not one of them can be discharged without knowing what you hold, why, for how long and who else sees it.
Here it is named and mandatory, for controllers and processors alike. The small-organisation derogation is narrow — it falls away where processing is regular, risky, or involves special categories, which describes most businesses holding customer data.
A privacy information management system requires you to identify and document your processing of personal information. The same discovery also populates the asset inventory 27001 expects, so one exercise feeds both.
The one that actually arrives, usually with a deadline attached. What data do you hold on our behalf, where, who else sees it, how long. Answerable in an afternoon from a maintained record, or a fortnight of interviews without one.
This is the honest reason to do the work properly rather than minimally. The cheapest version satisfies nobody twice; a real one is the single artefact you hand to a regulator, an auditor, a certification body and a customer, and each of them gets the answer they wanted.
Automated discovery is genuinely useful for databases. These are the entries a data inventory misses, and they are where the exposure usually is.
The register at reception, consent forms in a drawer, the file that was never scanned. The Act does not care what the data is written on.
An export on a laptop, a spreadsheet a manager maintains, last quarter’s CSV in a downloads folder. Nobody lists these because nobody calls them systems.
Scheduling, surveys, messaging. Never through procurement, holding customer contact details, and invisible to any inventory built from the finance ledger.
Housekeeping with a key to the records room. A visiting consultant who sees customers weekly. Both are processing personal data whatever their contract says.
Your marketing partner subcontracts. Your accountable chain does not stop at the party you signed with, and the second link is never on the first list.
So discovery here is people plus tooling. Where you have databases we classify the schema — column names and types, never values. Where you have a building, we walk it.
Every entry carries where the information came from and when it was last confirmed, which almost no record of processing does.
Purpose, lawful basis, categories of personal data, the systems holding it, who receives it, retention period, and whether it crosses a border.
Not just that a transfer happens, but whether the notice covering it actually says so. That mismatch is a finding rather than a footnote.
Where each entry came from — observed in the walk-through, declared by a system owner, inferred from a schema. You can see which parts rest on somebody’s word.
How firmly each entry is established. A record that presents a guess and a verified fact identically is the reason most RoPAs cannot be relied on.
Entries age. The record shows when each was last confirmed and flags what is overdue, so the document degrades visibly rather than silently.
The register and the RoPA live in software you keep and your team maintains. Exportable, and nothing about leaving is designed to be difficult.
No, and be careful with anyone who tells you otherwise — they are quoting GDPR Article 30, which is a different regulation. No provision of the DPDP Act names a record of processing activities. What the Act does is impose six duties you cannot discharge without one: securing personal data under §8(5), notifying a breach under Rule 7, erasing under §8(7), answering rights requests, the Rule 13 audit if you are a Significant Data Fiduciary, and disclosing cross-border transfers under §16.
No — you extend it. An Article 30 record is most of the way there; what it typically lacks is the Indian-specific parts: which processing runs on a §7 legitimate use rather than consent, whether any Fourth Schedule children's exemption applies, retention against Rule 8 classes, and residency in Indian terms rather than adequacy terms. We map what you have and fill the gaps rather than rebuilding it.
It gives you the substance a privacy information management system needs — identified and documented processing of personal information, with purposes, categories, recipients, retention and transfers. Certification is a separate exercise with an accredited body, and we would not describe a record as certifying anything. What we will say is that clients doing both find this is the artefact both auditors ask for, and the discovery also populates the asset inventory 27001 expects.
Not to your data. Where you have databases we classify the schema — table and column names and types, never values — and every suggestion is reviewed one column at a time before it counts. Everything the registry holds is metadata. A consultant walking away with copies of your customer records has made your problem larger, not smaller.
For a single-location business, two to three weeks elapsed with about a day of your team's time inside it. Several sites, several entities or a large system estate takes longer and we say so before quoting. The work is front-loaded: heavy once, then maintained by your own team in minutes when something changes.
Two things. Every entry records when it was last verified and against a review cadence, so the record shows you what is ageing rather than looking equally confident about all of it. And it lives in the platform the other modules read from — so when a notice is published or a vendor agreement lapses, the same record moves. A RoPA maintained in a spreadsheet beside the business is accurate on the day it is written and never again.
Real client quotes, attributed by role and sector — we never name a client.
Working across
The regulator, the auditor, the certification body and your customer’s procurement team are all asking the same question in different words.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.