Why a record of processing activities is necessary under DPDPA
The DPDPA does not contain a standalone provision requiring a data register. But the duties it does impose cannot be met without one:
- Section 5 requires an itemised notice of each purpose before or at the time of collection. Without a register of purposes, the notice will be incomplete.
- Section 6 requires consent for each specified purpose. Without a register, the organisation cannot verify that consent covers every purpose.
- Section 7 lists the purposes that may be processed without consent. Without a register, the organisation cannot show that each such purpose falls within Section 7.
- Section 8(1) and 8(2) require the Data Fiduciary to engage each Data Processor under a valid contract. Without a register of processors, the organisation cannot verify full coverage.
- Section 8(7) requires erasure when the purpose is fulfilled or consent is withdrawn, unless retention is necessary for compliance with law. Without a retention schedule linked to purposes, this duty cannot be enforced.
- Section 16 restricts transfers outside India. Without a register of transfers, the organisation cannot verify that no data flows to a restricted country.
The fields a DPDPA-ready RoPA should contain
Each row in the register represents a processing activity — a combination of data set, purpose and system. The minimum fields needed to support the statutory duties are:
| Field | Supports | Example |
|---|---|---|
| Data set / category | Section 5 notice, Section 8(7) retention | Customer contact details |
| Purpose | Section 5, Section 6 consent, Section 7 legitimate use | Fulfilling a purchase order |
| Lawful ground | Section 6 (consent) or Section 7 (legitimate use) | Consent obtained at checkout |
| Categories of Data Principals | Section 9 (children), Section 5 notice | Adult customers |
| Systems / applications | Section 8(5) security safeguards | CRM, ERP, payment gateway |
| Data Processors | Section 8(1), 8(2) contract | Cloud hosting vendor, analytics vendor |
| Retention period | Section 8(7), Rule 8 | 3 years from last transaction |
| Transfer outside India | Section 16, Rule 15 | Analytics data to Singapore |
| Owner / business unit | Internal accountability | Sales department |
How to build the register
Building the register is a data-collection exercise that touches every business unit. The steps are:
- 01
Identify business units
List every department or function that collects or processes personal data: HR, sales, marketing, IT, finance, operations, customer support.
- 02
Interview data owners
For each unit, ask: what personal data do you collect, from whom, for what purpose, in which systems, with which vendors, and for how long?
- 03
Map lawful grounds
For each purpose, determine whether it relies on consent (Section 6) or a legitimate use (Section 7). Record the specific sub-clause.
- 04
Identify processors and transfers
For each system or vendor, determine whether it constitutes a Data Processor and whether data is transferred outside India.
- 05
Set retention periods
For each data set and purpose, set a retention period and the legal basis for any retention beyond the purpose.
- 06
Validate and sign off
Each business unit owner reviews and confirms the entries for their function. The register is dated and stored as evidence.
Keeping the register current
A register that is accurate on the day it is built and inaccurate six months later is a compliance risk, not an asset. Updates are triggered by:
- A new product, feature or service that processes personal data for a new purpose.
- A new vendor, system or cloud service that receives or stores personal data.
- A change in the country of processing or storage.
- A change in retention requirements, including a new law or regulation.
- A personal data breach that reveals undocumented processing.
A quarterly review cycle catches changes that were not flagged at the time. The register is also reviewed during each annual audit (Rule 13 for Significant Data Fiduciaries).
How AMLEGALS helps build the register
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
The team conducts the business-unit interviews, maps the lawful grounds, reviews processor arrangements, sets the retention schedule and delivers the register as a working document with an update protocol.

