Data discovery: how to map where personal data lives in your business
Data discovery means finding and cataloguing every place your business holds personal data — apps, databases, spreadsheets, inboxes, chats, backups and vendors — into a single data inventory. It's the first step of DPDP compliance because every other obligation (erasure, safeguards, breach reporting, retention) depends on knowing where the data is. A focused first pass takes an SME two to four weeks.
Ask a business "where is your customer data?" and you'll hear "in the CRM." Ask their sales team, and you'll hear about the export someone keeps on their laptop, the WhatsApp group with lead photos, and the agency that still has last year's campaign list. The gap between those two answers is exactly what the DPDP Act punishes — and what data discovery closes.
Why discovery comes first
Every obligation in the Act quietly assumes you know where the data is:
- Erasure requests — you must delete a person's data everywhere, including the copies you forgot about.
- Security safeguards — you can't protect a spreadsheet nobody knows exists; unknown copies are unprotected by definition.
- Breach notification — "what leaked, and whose data was it?" is answerable only against an inventory.
- Retention limits — data that should have been deleted years ago is usually data nobody remembered holding.
- Your privacy notice — it must state what you collect and why, which you can only write after mapping it.
Where personal data hides
The systems everyone remembers: CRM, billing/accounting, your product database, HR software. The ones that surface in every discovery exercise we run:
- Spreadsheet exports — on laptops, shared drives, and attached to old emails. Every export is a fork of your database with no security and no owner.
- Inboxes — years of customer details, ID proofs and KYC documents sitting in mail threads.
- WhatsApp Business and chat tools — numbers, addresses, documents shared in chats, then backed up to personal devices.
- Marketing and analytics stacks — email tools, ad audiences, form builders, each holding its own contact list.
- Support desks — tickets contain whatever customers typed into them, which is everything.
- Backups and old systems — the CRM you migrated away from in 2023 still holds every record it ever did.
- Vendors and agencies — lists shared for campaigns, logistics, or verification, living on in someone else's systems.
The 5-step method
Step 1 — Inventory your systems
List every application, database, drive and device that could hold personal data. Start from finance: the software subscriptions you pay for are a surprisingly complete map of your stack. Add the unofficial layer — shared drives, exports, personal WhatsApp — which no invoice will show you.
Step 2 — Interview the teams
Thirty minutes each with sales, marketing, support, HR and finance: "Walk me through what happens to a customer's details from first contact." People don't hide data on purpose; they simply use whatever tool was convenient. The interviews find what the system list misses.
Step 3 — Classify what each system holds
For each system, record which categories of personal data it contains — contact details, identity documents, financial data, health data, children's data — and roughly how many people. Sensitivity drives priority: a spreadsheet of 50,000 customers with ID numbers outranks a newsletter list.
Step 4 — Map the flows and the vendors
Data rarely stays put. Record how it moves: web form → CRM → email tool → agency. Every arrow crossing your company boundary is a vendor relationship that needs a data-processing agreement under the Act.
Step 5 — Assign owners and write the record
Every system gets one named owner responsible for its data. Then write it all into a single inventory. One line per system is enough to start:
That last field — risk — is where discovery pays for itself. Most businesses finish the exercise with a short, very actionable list: kill the exports, close the old system, sign the missing DPA, delete what expired.
Keeping it alive
- Review quarterly — new tools, new vendors, new forms all change the map.
- Gate new software — a two-line question in procurement ("will it hold personal data? who owns it?") keeps the inventory current for free.
- Tie it to your grievance process — when an erasure request arrives, the inventory is the search checklist.
- Clean as you go — discovery always surfaces duplicates and dead records; cleansing them shrinks both your risk and your storage bill.
Not sure where you stand?
Take our free, 2-minute DPDP Readiness Scorecard — answer 12 questions and get a per-area gap report showing exactly what to fix first.
How Ronin Works helps
Discovery is our first engagement with almost every client. We run the system inventory and team interviews, classify and risk-rank what we find, map the vendor flows, and hand you a living data inventory — then cleanse and de-duplicate what's in it, so the map describes data worth keeping. Clean data is compliant data.
Keep reading
- DPDP Act 2023: a practical compliance checklist for Indian businesses
- Why your CRM is full of duplicates — and what it's costing you
The DPDP Act gives individuals rights too. Saaph.in — a Ronin Works product — finds where your personal data is exposed across the open web and gets it removed under the Act, then keeps watch.
Scan your exposure at Saaph.in →Want help mapping your data?
Send us a note — we reply within one working day.
This article is general information, not legal advice. The DPDP Act's rules and enforcement timeline are determined by the Government of India and may change. For a formal assessment of your obligations, consult a qualified professional or talk to Ronin Works.