AMLEGALS — Strategic Lawyering

DPDPA Data Mapping: The Map Is the Defence

DPDPA Data Mapping: The Map Is the Defence

Your data map is your defence map. Without one, you have no defence.

The scene

A customer asked for her data to be erased. It took the team eleven days to find her in the CRM, the billing system, two marketing tools, a support platform and a spreadsheet on a sales manager's laptop. They erased five copies. The sixth was in a backup nobody remembered.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

IT knows where the data is.

IT knows systems. Business teams create spreadsheets, exports and shadow tools.

Map with the business, not just the servers.

We mapped it last year.

A map from last year is a map of a company that no longer exists.

Tie the map to procurement and product releases so it updates itself.

We only need to map customer data.

Employees, candidates and vendor staff are Data Principals too.

Map people, not only products.

What a DPDPA data map must answer

For each dataset: whose data, collected where, for which purpose, on what basis, stored where, shared with which processors, retained until when. If any cell is blank, the corresponding obligation cannot be met.

Why rights depend on it

Access, correction, erasure and grievance rights under Sections 11 to 13 each require you to find every copy. The Rules expect responses within set timelines. Without a map, every request is a search.

Monday morning

01 List every system that holds a name, phone number or email.

02 Add the three spreadsheets everyone knows exist.

03 Assign an owner to each row. An unowned dataset is an unmanaged risk.

Questions, answered plainly

Is a data map mandatory under DPDPA? +

The Act does not use the term, but its obligations on notice, purpose limitation, security, erasure and Data Principal rights cannot be met without knowing where personal data sits. Significant Data Fiduciaries must also carry out data protection impact assessments, which depend on one.

What should a DPDPA data inventory contain? +

At minimum: the category of Data Principal, data fields, source, purpose, legal basis, storage location, processors, cross-border transfers, retention period and accountable owner.

Argument 04 Consent is not a checkbox. It is a contract you have to prove. Read →

Argument 05 Silence after a breach is the most expensive sound. Read →

Argument 06 You can outsource the processing. You cannot outsource the liability. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).