A data inventory lists where personal data lives — which databases, object stores, SaaS applications and file shares hold it. A RoPA describes what you do with that data: the processing activity, its purpose, the lawful basis, the recipients and the retention period. The inventory is a map of locations; the RoPA is a record of conduct, and it is built on top of the inventory.
The order matters. You cannot describe a processing activity accurately for data you have not found, which is why discovery comes first in any workable DPDP programme.
In practice organisations that skip the inventory end up with a RoPA describing the systems they remembered, which is a different set from the systems they operate.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Dinkar Singh — Dinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →