{GyaanGRID}
18.  Creating The Data Inventory Table
ISSUE #101Published: 9/27/2026

18. Creating The Data Inventory Table

Ankur Srivastava

Ankur Srivastava

Deputy-CISO / CISSP

Cyber Security & Business Continuity Expert with over 15 years of experience orchestrating InfoSec Governance, risk mitigation frameworks, and disaster recovery architectures. CISSP | M.S. in Cyber Laws & Information Security (IIIT).

Access Price

₹40
Preview

Description

Build your DPDPA data inventory with a scope note, system list, version information, and a structured table capturing what data you collect, why, where it's stored, and retention periods—because undocumented data collection is like black money: against the law.

The Second Schedule provides minimum standards for two special situations: government schemes (Section 7(b)) and research/archival purposes (Section 17(2)(b)), offering a lighter compliance regime if you follow its checklist.

Key Second Schedule requirements include ensuring processing is lawful, data is used only for the stated purpose, and appropriate safeguards are maintained.

A well-built data inventory is the backbone of DPDPA compliance—without it, you cannot secure, retain, or delete data effectively.