Sec. 8(1) · Rule 8
AvailableThe register the Act never names, and assumes
The DPDP Act does not ask for a record of processing activities. It asks you to answer for processing done on your behalf, erase on a clock, and report a breach in 72 hours — three questions about a specific activity. This is where the answer lives.
- Row per activity
- 1
- Sec. 8(1)
- Fields the Rules imply
- 7
- Rule 7 · Rule 8
- Spreadsheets in the loop
- 0
- —
- Breach report window
- 72h
- Rule 7
For the DPO or the compliance lead building the first inventory, usually from a spreadsheet.
| Activity | Purpose | Data categories | Recipients | Retention | Cross-border | Consent purpose |
|---|---|---|---|---|---|---|
| Customer onboarding | Account creation and KYC | Name · Mobile · PAN · Address | KYC vendor (processor) | 7 years after closure | None | acct.create |
| Marketing email | Promotional communication | Name · Email | ESP (processor) | Until withdrawal | None | mkt.email |
| Product analytics | Feature usage measurement | Pseudonymous ID · Events | Analytics (processor) | 26 months | Flagged | analytics.product |
| Support tickets | Grievance and service requests | Name · Email · Free text | Helpdesk (processor) | 3 years | None | — (Sec. 7(i)) |
Four things a register has to do
- Sec. 6(1)
Built on the purposes you already have
The register does not start empty. Every purpose in the Consent Manager's Purpose Registry is already an activity here, with the consents attached to it, so the first draft is generated rather than typed.
- Sec. 8(1)
One row per processing activity
Not one per system, and not one per department. The row is the unit the Act reasons about — a purpose, the data it needs, and who touches it — which is why a withdrawal and an erasure request both resolve to the same place.
- Sec. 8(7) · Rule 8
Retention and cross-border at the row
The retention clock and the transfer flag are fields on the activity, not a policy paragraph elsewhere. When the clock expires the erasure job has something specific to act on, and the transfer register is a query rather than an exercise.
- Rule 7
Export as the audit pack
The register exports to Excel or PDF with the consent counts, the retention state and the chain digest of the day it was drawn. A breach report under Rule 7 needs the particulars of the affected activity; this is where they come from.
The register, as a spreadsheet
The same seven columns, in a file you can fill in without buying anything. It is deliberately not gated behind an email address — a template you have to trade a contact for is a lead magnet pretending to be a resource, and the register is more useful to the market than the lead is to us.
RoPA register template (.xlsx)Import-compatible with the product. Nothing to undo later.
Works with
- Sec. 10 · Rule 13RoadmapDPIAThe impact assessment a Significant Data Fiduciary owes every twelve months.
- Sec. 8(2)RoadmapVendor RiskEvery processor you engage, the contract that permits it, and what it may process.
- Sec. 8(6) · Rule 7RoadmapBreach NotificationIntimation to every affected principal, and the Board report, on a 72-hour clock.
Questions people ask
- Is a RoPA mandatory under the DPDP Act?
- No — and any vendor telling you otherwise is selling past the Act. The DPDP Act, 2023 never uses the term, and unlike the GDPR it contains no standalone article requiring a record of processing activities. What it does contain are duties you cannot discharge without one: Sec. 8(1) makes you answerable for processing carried out on your behalf irrespective of any agreement to the contrary, Sec. 8(7) with Rule 8 puts a retention clock on personal data you no longer need, and Rule 7 requires breach particulars within 72 hours. Each of those questions is asked about a specific processing activity. A register is how you have the answer before you are asked.
- How does this differ from a GDPR Article 30 record?
- Article 30 prescribes the fields and applies above a headcount threshold. The DPDP Act prescribes neither, so a register here is shaped by the duties rather than by a list: retention (Rule 8), cross-border destination (Sec. 16, Rule 15), the processors engaged under Sec. 8(2), and the consent purposes the activity depends on. If you already keep an Article 30 record, it is a good starting draft and it is missing the consent-purpose link and the Eighth Schedule language of the notice.
- Do we need a register if we are not a Significant Data Fiduciary?
- The Sec. 10 obligations — the annual Data Protection Impact Assessment and audit under Rule 13 — apply only once you are notified as a Significant Data Fiduciary. The Sec. 8 duties are not conditional on that. Every Data Fiduciary carries them, which is why the register is not an SDF artefact even though an SDF has the most obvious use for one.
- Can we import what we already have?
- Yes. The template below is the same column set the product imports, so a spreadsheet you already maintain can be brought in without being retyped. The columns that usually need filling in afterwards are the retention basis and the consent purpose, because those are the two most spreadsheets leave implicit.
- Is RoPA available today?
- Yes. RoPA is available: the register, import and export, the erasure clock under Rule 8 and the overdue-versus-waiting queue all ship. What it deliberately does not do is scan and classify your own databases — data discovery is an adjacent market we decided against, so you bring the activities or import them, and RoPA is the register the other modules read from.
Next step
See it against your own processing
A walkthrough runs on your activities and your purposes, not a demo tenant. Thirty minutes, and you keep the notes.
Book a demo