You cannot protectwhat you have not named.

Every DPDPA obligation assumes you know where the data is. Most organisations are guessing.

In one line: The Act does not use the term, but its obligations on notice, purpose limitation, security, erasure and Data Principal rights cannot be met without knowing where personal data sits. Significant Data Fiduciaries must also carry out data protection impact assessments, which depend on one.

The estate · You cannot protect what you have not namedHover to inspect

Your data map is your defence map. Without one, you have no defence.

The scene

A customer asked for her data to be erased. It took the team eleven days to find her in the CRM, the billing system, two marketing tools, a support platform and a spreadsheet on a sales manager's laptop. They erased five copies. The sixth was in a backup nobody remembered.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
IT knows where the data is. IT knows systems. Business teams create spreadsheets, exports and shadow tools. Map with the business, not just the servers.
We mapped it last year. A map from last year is a map of a company that no longer exists. Tie the map to procurement and product releases so it updates itself.
We only need to map customer data. Employees, candidates and vendor staff are Data Principals too. Map people, not only products.

What a DPDPA data map must answer

For each dataset: whose data, collected where, for which purpose, on what basis, stored where, shared with which processors, retained until when. If any cell is blank, the corresponding obligation cannot be met.

Why rights depend on it

Access, correction, erasure and grievance rights under Sections 11 to 13 each require you to find every copy. The Rules expect responses within set timelines. Without a map, every request is a search.

Monday morning

  1. 01List every system that holds a name, phone number or email.
  2. 02Add the three spreadsheets everyone knows exist.
  3. 03Assign an owner to each row. An unowned dataset is an unmanaged risk.

Questions, answered plainly

Is a data map mandatory under DPDPA?

The Act does not use the term, but its obligations on notice, purpose limitation, security, erasure and Data Principal rights cannot be met without knowing where personal data sits. Significant Data Fiduciaries must also carry out data protection impact assessments, which depend on one.

What should a DPDPA data inventory contain?

At minimum: the category of Data Principal, data fields, source, purpose, legal basis, storage location, processors, cross-border transfers, retention period and accountable owner.

Argument 04Consent is not a checkbox. It is a contract you have to prove.Read → Argument 05Silence after a breach is the most expensive sound.Read → Argument 06You can outsource the processing. You cannot outsource the liability.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner