Quick question for every CXO reading this: Do you know where your company’s personal data actually lives?
Not in theory. Not in the privacy policy PDF nobody reads. Actually — which system, which vendor, which spreadsheet somebody’s ex-employee built in 2019.
If the honest answer is “not really,” you’re not alone. And here’s the plot twist: the DPDP Act never even uses the word “ROPA” (Record of Processing Activities). It’s not a legal requirement by name.
But try doing any of these without one, and watch the wheels fall off:
Responding to a consent withdrawal
Fulfilling a data erasure request within timelines
Reporting a breach coherently to the Board
Answering a regulator’s “show me” moment
A ROPA isn’t a compliance checkbox. It’s your organization’s data GPS. Done right, for every process you should be able to double-click into:
Why do we collect this?
Whose data is it?
Which system holds it?
Which vendor touches it?
How long do we keep it?
Where does it travel?
For a CXO, that’s not a legal artifact — that’s risk visibility. It’s the difference between telling your Board “we’re investigating” and “here’s exactly what happened, to whom, and our containment plan” during a breach.
The uncomfortable truth: building this the first time is tedious. Multiple departments, multiple systems, plenty of “wait, who owns this data again?” conversations. It won’t be perfect on day one. That’s fine — ship it, validate it, keep it alive as your business evolves.
Because privacy risk, like cyber risk, can’t be managed from a slide. It has to be managed from a map.
If your DPO can’t show you that map today — that’s the real finding.