Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →
Resource / Framework

Data Mapping Framework

You cannot protect what you cannot see. This framework helps you document every flow of personal data across your systems — the record-of-processing that underpins consent, retention and breach response.

The six columns of a data map

For every personal-data processing activity, capture these six dimensions. Together they answer the auditor's core question: what data, for what purpose, held where, and for how long?

01
Data Element

What category of personal data is it? (e.g. name, email, payment, location, health)

02
Source

Where does it come from — the Data Principal directly, a partner, or a third party?

03
Purpose

The specific, lawful purpose it is processed for, mapped to the consent you captured.

04
Storage

Which system or vendor holds it, and in which jurisdiction it is stored.

05
Access

Which teams, roles and processors can read or modify the data.

06
Retention

How long you keep it, and the trigger that starts the erasure clock.

How to build your map

01
Identify systems

List every application, database, spreadsheet and SaaS vendor that stores or processes personal data.

02
Trace the flows

For each system, record how data enters, moves between systems, and leaves — including cross-border transfers.

03
Attach a lawful basis

Link every processing activity to the specific consent or legitimate use that permits it under the DPDP Act.

04
Keep it living

Re-review the map whenever you add a system, purpose or vendor — a data map is only useful while it is current.

Automate discovery instead

DPDP Guard's Cookie & Tracker Discovery scans your live domains and classifies what it finds — turning a manual mapping exercise into a living inventory.