Data Mapping Framework
You cannot protect what you cannot see. This framework helps you document every flow of personal data across your systems — the record-of-processing that underpins consent, retention and breach response.
The six columns of a data map
For every personal-data processing activity, capture these six dimensions. Together they answer the auditor's core question: what data, for what purpose, held where, and for how long?
What category of personal data is it? (e.g. name, email, payment, location, health)
Where does it come from — the Data Principal directly, a partner, or a third party?
The specific, lawful purpose it is processed for, mapped to the consent you captured.
Which system or vendor holds it, and in which jurisdiction it is stored.
Which teams, roles and processors can read or modify the data.
How long you keep it, and the trigger that starts the erasure clock.
How to build your map
List every application, database, spreadsheet and SaaS vendor that stores or processes personal data.
For each system, record how data enters, moves between systems, and leaves — including cross-border transfers.
Link every processing activity to the specific consent or legitimate use that permits it under the DPDP Act.
Re-review the map whenever you add a system, purpose or vendor — a data map is only useful while it is current.
Automate discovery instead
DPDP Guard's Cookie & Tracker Discovery scans your live domains and classifies what it finds — turning a manual mapping exercise into a living inventory.