Chapter II · Obligations of Data Fiduciary
Section 4: Grounds for processing personal data
Section 4 is the gateway to Chapter II: you may process personal data only for a lawful purpose, and only on one of two grounds, the Data Principal's consent, or a listed legitimate use.
- Chapter
- Chapter II · Obligations of Data Fiduciary
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027
- Applies to
- Data Fiduciaries
- Official citation
- DPDP Act, 2023, s.4
- Reading time
- 5 min
- Updated
- August 2026
At a glance
Section 4 establishes that a person may process personal data only in accordance with the Act and for a lawful purpose, and only where the Data Principal has given consent (Section 6) or for certain legitimate uses (Section 7). A lawful purpose is any purpose not expressly forbidden by law. Everything else in Chapter II builds on this two-ground structure.
Key takeaways
- You may process personal data only for a lawful purpose, one not expressly forbidden by law.
- There are exactly two grounds: the Data Principal's consent, or a listed legitimate use.
- Consent is governed by Section 6; legitimate uses by Section 7.
- There is no general "legitimate interests" ground as in the GDPR, the legitimate uses are a closed list.
- Pick and record the correct ground for each processing purpose.
Who should read this
Read this before you rely on consent or claim a legitimate use, it tells you the only two lawful bases available and frames Sections 5 to 7.
In plain language
Section 4 is the hinge of the Act's obligations. It says you may process personal data only in accordance with the Act and only for a lawful purpose, defined as any purpose not expressly forbidden by law.
It then narrows the lawful bases to two: either the Data Principal has given consent under Section 6, or the processing falls within one of the certain legitimate uses listed in Section 7. Unlike some regimes, there is no open-ended "legitimate interests" test, the legitimate uses are a fixed list.
In practice this means, for every processing activity, you should be able to name the ground: consent, or a specific legitimate use. If you cannot, you should not be processing.
The text of the law
Section 4: Grounds for processing personal data
4(1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose, (a) for which the Data Principal has given her consent; or (b) for certain legitimate uses.
4(2) For the purposes of this section, the expression "lawful purpose" means any purpose which is not expressly forbidden by law.
Wording reproduced or summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
What this means for you
- For each processing purpose, record whether you rely on consent or a specific legitimate use.
- Do not assume a GDPR-style "legitimate interests" balancing test, it does not exist here.
- If consent is your ground, you must also serve a Section 5 notice.
- Retire any processing you cannot tie to a lawful ground.
Frequently asked questions
What are the lawful grounds for processing under the DPDP Act?
Is there a legitimate interests ground like the GDPR?
What is a lawful purpose?
Do I need a ground for every activity?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.