How do I create a data inventory for DPDP?
The foundation every other DPDP task depends on.
What to capture
For each data store, record the data categories, source, purpose, lawful basis, internal access, third parties and processors involved, storage location, and retention period. Cover the unglamorous places too — spreadsheets, shared drives, email, support tools and backups.
How to run it
Interview each team about the data they collect and use, then validate against systems. Start broad and refine. The first pass is rarely perfect; the value is in surfacing the data you'd forgotten you held, which is usually where the risk hides.
Keep it alive
An inventory is only useful if it's current. Assign ownership, update it when you add systems or vendors, and use it to drive every other compliance artifact. Most DPDP work becomes straightforward once the inventory exists.
Frequently asked questions
Why is a data inventory the first step?
Because your notice, retention, vendor assessments, DSAR responses and breach plan all depend on knowing what data you hold and where. Everything else builds on it.
What should each inventory entry include?
Data category, source, purpose, basis, access, processors, storage location and retention period.
How detailed does it need to be?
Detailed enough to answer a rights request and prove accountability. Start broad and refine over iterations.
Build your data inventory
Use the Data Inventory Builder to capture every store of personal data in a structured format.
Data Inventory Builder