In late August 2025, an outside research team found a public cloud storage bucket holding 273,160 PDF files. Each documented a single bank transfer through India’s National Automated Clearing House: unredacted account numbers, transaction amounts, and in many files the names, phone numbers and email addresses of individuals. At least 38 banks and lenders appeared in the sample. Roughly 3,000 new files were being added every day.
The interesting part is not the exposure. It is that for a month, nobody would claim it. Researchers wrote to the most-represented lender, then to the body overseeing the clearing house, then to CERT-In. The bucket was secured on 4 September. Ownership stayed unresolved until 26 September, when a Gurugram fintech, Nupay, confirmed it had addressed a configuration gap in its storage. This is the exact failure that DPDP data mapping exists to prevent, and most mid-market estates are carrying a version of it right now.
What a Data Map Has to Do Under DPDP
DPDP data mapping is a maintained inventory of what personal data your organisation holds, which system each category sits in, who can reach it, how it moves between systems, and when it gets deleted. A diagram drawn once and filed does not qualify. Under the Digital Personal Data Protection Rules 2025, notified on 13 November 2025 with substantive obligations enforceable from 13 May 2027, nearly every obligation assumes this inventory already exists. Breach reporting, erasure requests, retention limits and processor oversight all require you to state where the data is. Without the map, each obligation becomes a research project run under time pressure.
A 2026 readiness survey of roughly 150 privacy and security professionals across Indian industries found that only about 38% of organisations have begun categorising personal data at all, and over 83% have not started end-to-end implementation.
The Systems Your Map Will Miss

Most mapping exercises open with a questionnaire to department heads. That method finds the systems people remember. It does not find the ones that are working correctly and quietly.
The NACH bucket was not abandoned in a careless sense. It was doing precisely what it was built to do, receiving mandate forms, for months. The earliest document in it was dated 10 April 2025. What was missing was anyone whose job included asking what was inside.
So start from the money and the access rather than the org chart. Pull cloud billing detail for the last 24 months and list every storage bucket, database and object store that has ever incurred a charge, including the ones costing four hundred rupees a month. Then pull your identity provider and list every application holding an active SSO integration or OAuth grant. The gap between those two lists and the systems your department heads named is your real exposure surface, and it is usually larger than anyone in the room expects. This is the same drift that turned shadow AI into the new shadow IT, arriving through procurement nobody logged.
For each system that survives that exercise, ask three questions. What personal data does this hold. Who can read it without asking permission from anyone. What would happen if it stopped existing tonight. The third question earns its place because it surfaces systems nobody would miss, and a system nobody would miss is a system nobody is watching.
When Your Vendor’s Mistake Becomes Your Penalty
The banks whose customers appeared in that dataset misconfigured nothing. Their customers’ account details were indexed and publicly searchable anyway, and they learned about it from a journalist’s outreach rather than a vendor disclosure.
The legal split is what makes this expensive. A processor handles personal data on your instruction. You remain the Data Fiduciary. When a processor suffers a breach affecting data you entrusted to them, the obligation to notify the Data Protection Board and every affected individual sits with you. Their incident becomes your filing, your clock and your penalty exposure. The ceilings stack: up to ₹250 crore for failing to maintain reasonable security safeguards under the Act, and up to ₹200 crore separately for failing to notify a breach properly. A single incident can trigger both.
Which changes what belongs in a vendor review. Asking whether a vendor is DPDP compliant produces a yes and tells you nothing. Ask them instead to name every storage location where your data physically rests, and to commit contractually to notifying you within a fixed number of hours of becoming aware of any incident. If they cannot produce that list inside a week, they do not have a map either, and their gap is now sitting on your risk register. This is the distance between a passed audit and a business that is actually safe.
The 72-Hour Clock Starts Earlier Than You Think

Rule 7 sets out what happens after a breach. You notify each affected individual without delay, give the Board an initial intimation without delay, and file a detailed report within 72 hours covering the circumstances, the causes, the remedial measures taken, findings on who was responsible, and a summary of the notices you sent. CERT-In directions run a separate and faster six-hour window for cybersecurity incidents.
The clock runs from organisational awareness, not from the incident itself. That sounds generous until you consider how awareness gets reconstructed afterwards. If an analyst saw an anomaly on Monday and escalated on Wednesday, the defensible start is Monday. Rule 6 requires log retention for a year, so the record of when your systems first knew survives, and it is available to a regulator whether or not it flatters you.
Now read the report content again. It asks which individuals were affected and what data reached where. If the map does not exist, you spend the 72 hours building one while your incident response team is also running the incident, and you end up choosing between filing something incomplete and filing something late.
There is a drill worth running this quarter. Pick your most sensitive system and time how long it takes to produce a list of affected individuals, data categories and downstream systems the data flowed into. Anything beyond a working day means you would miss the statutory deadline once a real incident adds pressure and half your team is on a call with counsel.
Nine Months, In This Order
The sequence matters because two of these steps depend on people outside your control.
Discovery goes first, because everything downstream consumes its output. Give it eight weeks and run it against cloud billing and identity data rather than questionnaires. Processor contracts should start in parallel from month two, not month seven, since renegotiation moves at the speed of vendors who feel no urgency on your behalf. Retention decisions run in the middle, weeks eight to sixteen, and they are slow for an internal reason: someone has to decide, category by category, when data stops being needed, and that decision is a business judgement rather than an IT one.
One correction saves real time here. Employment purposes fall under the legitimate uses in Section 7 of the Act, so salary records and background checks held for employment do not need a consent flow. Notice and security obligations still apply, and retention still applies. Teams that miss this spend six weeks building consent architecture for HR data that never required consent, then arrive at the customer data, where consent genuinely is required, with no time left.
The honest tradeoff: manual discovery is slower than buying a scanning tool, and it is still the right order. A discovery tool finds personal data in the systems you point it at. Until someone has walked the cloud accounts and the vendor list, you do not know what to point it at. Buy tooling to keep the map current, not to build it in the first place. That distinction is also why so many mid-market cybersecurity audits fail: the instrument was fine and the scope was wrong.
The Question Someone Should Be Able to Answer on a Tuesday
The uncomfortable detail in the NACH case is not the misconfiguration. Configuration mistakes happen in every estate, including well-run ones. It is that a quarter of a million files accumulated over four and a half months, sat exposed, and then took a month to find an owner, inside an organisation that certainly had a security policy. Nobody was negligent in a way an audit would catch. No single person’s job covered knowing what was in that bucket.
Nine months from now, that structural gap stops being an operational weakness and becomes a filing you cannot complete inside 72 hours. The organisations that will be fine in May 2027 share one trait: someone can be asked, with no notice on an ordinary afternoon, where the customer financial data lives, and can answer in minutes. Find out this week whether that person exists in your organisation. If assembling the answer takes a fortnight and three meetings, you have just scoped your first project.


