DataSurity

Data Mapping & RoPA

Every processing activity, mapped, justified and kept current.

A living record of what you process, why, for whom, where and with whom. Each activity carries one lawful basis from the Act and a named owner, and stays true as the business changes.

Trusted by leading enterprises

  • Indiabulls Securities
  • KDSG Super-Speciality Hospital
  • Modicare
  • Express Inn Hotels & Resorts
  • Econo Broking
  • DAMS
  • Freesia by Express Inn
  • MBL
  • Trident Group
  • Dhani
  • Indiabulls Asset Reconstruction

Everything the business does with data, in one register

Discovery findings, interviews and sector knowledge come in. A register your teams own comes out.

  • Discovery findings
  • Sector activity packs
  • Process owner interviews
  • Existing registers and spreadsheets
  • Vendor contracts
  • Group structure
DataSurity Data Mapping
  • Record of processing activities
  • Lawful-basis register
  • Systems and third-party registers
  • Data-flow map
  • Retention reconciliation
  • Findings for gaps
Built on the Act

A register that knows the law as well as your business

  • 5 lanes

    Consent, a specific legitimate use, an exemption, out of scope, or flagged as unjustified

  • 8 Data Principal types

    Customers, applicants, employees, contractors, guarantors and family, business contacts, children, and people with guardians

  • Every edit versioned

    Each change is kept, so any past answer can be traced to the register as it stood

How it works

Five steps from blank page to living register

Features

What mapping does for you

01

A lawful basis the Act would recognise

Every activity takes one lane: consent, a specific legitimate use under Section 7, an exemption, out of scope, or flagged. The rules come from the Act. Marketing can't claim a legitimate use. Employment doesn't cover guarantors. A Section 7(d) claim needs the Indian law cited. There's no "legitimate interests", because the Act doesn't have it.

02

Every Data Principal counted

Most registers stop at customers. Each activity here names every population it touches, from rejected applicants and co-borrowers to nominees, contractors and children. The right basis, notice and retention follow from who the person is.

03

Retention reconciled with sector law

For each record class: when the purpose ends, which law says keep it longer, and the rule that results. Section 8(7) meets PMLA, RBI KYC, SEBI and IRDAI requirements in one worksheet, with each conflict resolved and cited.

04

Built for groups, versioned for audit

Map a group once. Shared functions are recorded once and inherited. Each flow between sister companies gets its own basis and notice, because they're separate Data Fiduciaries. Every change is versioned, so any past report can be traced to the register it used.

What the Act asks, and how Data Mapping answers

The register is where most obligations start. Each row below draws on it directly.

Section
  • s.4

    A lawful ground for every processing

    One lane per activity, with activities lacking a basis raised as findings

  • s.5

    A notice that describes the data and purpose

    Purposes and data categories per activity feed the notice

  • s.6, s.7

    Consent, or a specific legitimate use

    Lane rules drawn from each clause of Sections 6 and 7

  • s.8(2)

    Processors only under a valid contract

    Third-party register with contract checks and vendor questionnaires for every processor

  • s.8(7), Rule 8

    Erase when the purpose ends, unless law requires retention

    Retention worksheet reconciling the Act with sector rules

  • s.9

    Care with children's data

    Child populations tagged on every activity that touches them

  • s.11

    Tell a person who their data has been shared with

    Recipients per activity, ready for an access request

  • s.16

    Cross-border transfers

    Destination country recorded on every flow

Deploy it your way

Built for regulated Indian enterprises: your data stays where your policies say it must.

  • 01

    SaaS, hosted in India

    Managed by SARC AI on infrastructure in Indian data centres.

  • 02

    Private cloud

    Runs in your own cloud account, under your keys and access policies.

  • 03

    On-premises

    Installed in your data centre. Scanners read in place, and nothing leaves your network.

Connects to

  • PostgreSQL
  • MySQL
  • Oracle Database
  • Microsoft SQL Server
  • MongoDB
  • MariaDB
  • IDIBM Db2
  • SAP HANA
  • Snowflake
  • Amazon Redshift
  • Google BigQuery
  • Databricks
  • Teradata
  • Amazon DynamoDB
  • Azure SQL
  • Apache Cassandra
  • Redis
  • Elasticsearch
  • Couchbase
  • ClickHouse
  • Apache Hive
  • Apache Kafka
  • SQLite
  • Neo4j

Connectors are enabled during onboarding. Logos belong to their owners and indicate compatibility, not endorsement.

Certified

  • CERTIFIEDISO 27001INFORMATION SECURITY
  • CERTIFIEDISO 27701PRIVACY INFORMATION

Frequently asked questions

Does the DPDP Act require a RoPA?

The Act doesn't use the term. It requires a lawful ground for every processing, purpose-bound notices, erasure when the purpose ends and, for access requests, a list of everyone the data was shared with. None of that can be shown without a record of processing. In practice, it's the first thing an auditor or the Board will ask for.

Why is there no "legitimate interests" option?

It exists in the GDPR, not in the DPDP Act. Registers built on GDPR tools often file marketing and profiling under it. Under the Act those need consent. DataSurity only offers the grounds the Act contains, so the register can't be wrong on this point.

Do employees, applicants and guarantors count?

Yes. Anyone whose personal data you process is a Data Principal: current and former staff, rejected applicants, co-borrowers, guarantors, nominees and business contacts. Each activity names the populations it touches, so none is left out of notices, retention or rights handling.

How are vendors and processors assessed?

Every third party is recorded with its role for each activity, processor or separate Data Fiduciary. Its contract is checked for DPDP clauses, and it answers a questionnaire in the platform about how it protects your data. Controls are then tested on it according to its role, so a staffing agency and a cloud host are assessed differently.

How does the register stay current?

Three ways. Discovery rescans flag new systems and data categories the register doesn't hold yet. Owners review their activities on a schedule you set. Every edit is versioned, so changes are visible and nothing is quietly overwritten. The register reflects what's been confirmed, which keeps it accurate.

We're a group of companies. How does that work?

One map for the group, with each legal entity visible. Shared functions such as HR or IT are recorded once and inherited. Data moving between sister companies is treated as its own flow with its own basis and notice, since each company is a separate Data Fiduciary.

How are cross-border transfers handled?

Every flow records whether data leaves India and where it goes. The Act allows transfers except to countries the government restricts. Sector rules still apply on top, such as RBI's payment data localisation, and the register records both.

Trusted by leaders across industries

“We knew patient data sat in our hospital information system. We didn't know how much had spread into lab exports, scanned reports and shared drives until DataSurity's assessment showed us. The team understood hospital realities, from paediatric records to staff data, and gave us a plan we could actually run. Implementation is now moving ward by ward, with consent and rights handled in one place.”

Rakesh G

Head - Compliance, KDSG Hospitals (350-bed multispecialty hospital)

Knowledge resources

Start with one business line. Watch your register take shape.