How to build a data inventory and data mapping exercise for DPDP
You cannot protect data you do not know you have. Here is how to conduct a data inventory and map your data flows for DPDP compliance.
What is a data inventory and why does DPDP require it?
A data inventory lists every personal data asset in your organisation: the data category (email, financial, health), the source (customer registration, employee onboarding, vendor invoices), the purpose of processing, the lawful basis, the storage location (CRM, HR system, email archive, file server), who has access, third parties it is shared with, and the retention period. The DPDP Act does not explicitly require a ROPA for all Fiduciaries, but a data inventory is implicitly necessary to fulfil: writing an accurate privacy notice, honoring data access requests, implementing correct retention and deletion, and demonstrating compliance to the Board on inquiry.
How do you scope a data inventory exercise?
Start by identifying your business systems — CRM, HRMS, ERP, email, file storage, analytics, payment, marketing automation, helpdesk, cloud storage. Map each system to the personal data it contains and the business processes it supports. Then identify data flows between systems: where does customer data from your website go? Into the CRM, email marketing tool, analytics platform, data warehouse. Who sends data in (sources) and who receives data out (downstream systems and third parties)? Involve system owners from IT, HR, Finance, Sales, and Operations — they know what data their systems hold.
What should each row in a data inventory contain?
For each processing activity, record: activity name and business owner; data categories and specific fields; data subjects (customers, employees, vendors); collection source; purpose of processing; lawful basis (consent, contract, statutory obligation); storage location (system name, cloud provider, geography); access control (who can see the data, role-based); third parties and Data Processors who receive the data; retention period and deletion schedule; and any cross-border transfer. This level of detail makes the inventory useful for privacy notices, DPA negotiations, and access request responses.
How do you conduct the data mapping interviews?
Run structured interviews with the owner of each business system: What personal data does your system hold? Where does it come from? What do you use it for? Who else can see it? Where does it go? How long do you keep it? Record answers consistently — use a template so data from all interviews can be consolidated. Supplement interviews with technical discovery: review system access logs, API integrations, and data export configurations. Many organisations find shadow IT (data held in personal drives, WhatsApp groups, spreadsheets) during this exercise.
How do you prioritise your data inventory for DPDP?
Not all data is equally sensitive. Prioritise: systems holding sensitive personal data (health, financial, biometric) first; systems holding large volumes of data second; systems with cross-border data flows third; and systems processing children's data fourth. Map these high-risk systems thoroughly and early. Lower-risk systems (internal project management tools with minimal personal data) can be mapped in a later phase. A risk-prioritised approach lets you deploy DPDP controls where they matter most first.
How do you keep a data inventory current?
A data inventory becomes stale quickly as systems change. Build a process to update it: new system acquisitions trigger a data inventory update; major product launches trigger a privacy impact assessment which feeds back into the inventory; vendor changes (new DPAs, vendor exits) update the third-party sharing section; annual privacy reviews audit whether the inventory reflects current practice. Assign ownership of the inventory to a specific role (DPO, Privacy Officer, or Legal) so there is accountability for keeping it current.
Frequently asked questions
What is the difference between a data inventory and a data map?
A data inventory is a structured list or register — typically a spreadsheet or ROPA tool — that records what personal data you hold and the associated processing details. A data map is a visual representation of how data flows through your organisation — showing collection points, processing steps, storage systems, and sharing with third parties. Both are complementary: the inventory is the detailed source of truth; the data map is the communication tool for executives and auditors. For DPDP, you need both.
Do we need a data inventory if we are a small company?
The DPDP Act applies to organisations of all sizes. Even a small company with 20 employees processing customer data for an e-commerce business needs to understand what data it holds and how it flows. A simple spreadsheet covering your 5–10 key systems is sufficient for a small company — you do not need an enterprise ROPA tool. The investment in a basic data inventory is far less than the cost of a Board inquiry where you cannot demonstrate that you know what data you process.
Can we use our IT asset register as a starting point for data inventory?
Your IT asset register (a list of systems and servers) is a useful starting point for identifying which systems to include in the data inventory. But the IT register typically does not capture what personal data each system holds, who owns the data, or how it flows between systems — that information requires business-process-level discovery. Start with the IT asset register to identify systems, then conduct data mapping interviews with business owners to understand what personal data each system processes.
Build your DPDP data inventory
Niti Bharat's Data Inventory Template and DPDP Readiness Assessment guide you through the full data mapping exercise — structured interview templates, ROPA format, and data flow mapping tools.
Start Data Inventory Review