DPDP NavigatorAct 2023 · Rules 2025
All templates
Internal Registers & TrackersSection 8

Record of Processing Activities (ROPA) Template

A structured register for logging every personal data processing activity to support Section 8 accountability obligations.

Template
RECORD OF PROCESSING ACTIVITIES (ROPA)

Organization: [Organization Name]
Register Owner: [DPO Name / Privacy Team]
Last Updated: [DD-MM-YYYY]
Review Frequency: [Quarterly / Half-Yearly]

1. PURPOSE

This register documents every activity through which [Organization Name] processes digital personal data, in line with the accountability and record-keeping expectations under Section 8 of the DPDP Act, 2023. It is the single source of truth used to respond to Data Principal requests, Board inquiries, and internal audits, and to demonstrate that processing rests on a lawful ground under Section 4.

2. INSTRUCTIONS FOR USE

Every business function that collects, stores, uses, discloses, or transfers personal data must have at least one entry below. Update an entry whenever the purpose, data categories, processor, or retention period changes. Do not leave the "Lawful Basis" or "Retention Period" columns blank.

3. REGISTER

Column headers: Activity ID | Processing Activity / Purpose | Function / Department | Categories of Personal Data | Categories of Data Principals | Lawful Basis (Consent / Section 7 Legitimate Use) | Notice Reference | Processor(s) Engaged | Cross-Border Transfer (Y/N, Country) | Retention Period & Trigger | Key Security Safeguards | Owner

Example Row 1:
Activity ID: RPA-001
Processing Activity / Purpose: Employee payroll and statutory compliance
Function / Department: Human Resources
Categories of Personal Data: Name, bank account details, PAN, salary, attendance
Categories of Data Principals: Current and former employees
Lawful Basis: Section 7 - Employment purposes
Notice Reference: [HR Privacy Notice v2]
Processor(s) Engaged: [Payroll Processor Pvt. Ltd.]
Cross-Border Transfer: N
Retention Period & Trigger: 7 years post separation, per statutory record norms
Key Security Safeguards: Role-based access, encryption at rest, access logs retained 1 year
Owner: [Head of HR]

Example Row 2:
Activity ID: RPA-002
Processing Activity / Purpose: Website account creation and login
Function / Department: Product / Engineering
Categories of Personal Data: Name, email, mobile number, device identifiers
Categories of Data Principals: Registered users (customers)
Lawful Basis: Consent (Section 6)
Notice Reference: [Signup Consent Notice v3, dated DD-MM-YYYY]
Processor(s) Engaged: [Cloud Hosting Provider], [Consent Manager, if applicable]
Cross-Border Transfer: Y - [Country], subject to no government restriction under Section 16
Retention Period & Trigger: Duration of active account plus [90] days after deletion request or consent withdrawal, per Section 8(7)
Key Security Safeguards: TLS in transit, encryption at rest, MFA for admin access
Owner: [Product Owner Name]

Example Row 3:
Activity ID: RPA-003
Processing Activity / Purpose: Marketing communications and promotional offers
Function / Department: Marketing
Categories of Personal Data: Name, email, purchase history, preferences
Categories of Data Principals: Prospects and existing customers who opted in
Lawful Basis: Consent (Section 6), separate from transactional notice
Notice Reference: [Marketing Consent Notice v1]
Processor(s) Engaged: [Email Marketing Platform]
Cross-Border Transfer: Y - [Country]
Retention Period & Trigger: Until consent withdrawn or 24 months of inactivity, whichever is earlier
Key Security Safeguards: Suppression list honored within [48] hours of withdrawal, access restricted to marketing team
Owner: [Marketing Lead]

4. REVIEW LOG

Date Reviewed | Reviewed By | Changes Made | Next Review Due
[DD-MM-YYYY] | [Name] | [Summary of changes] | [DD-MM-YYYY]

5. NOTES

This register should be cross-referenced with the Vendor Risk Register (for processor due diligence), the Retention Schedule (for erasure triggers), and the DPIA Template (for high-risk activities involving a Significant Data Fiduciary or children's data).

This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.