Readiness assessment
Share this section

Chapter II · Obligations of Data Fiduciary

Section 7: Certain legitimate uses

Section 7 lists the situations where a Data Fiduciary may process personal data without fresh consent, from data a person voluntarily provides, to medical emergencies, legal duties and certain employment purposes.

Official text
Section 7Certain legitimate uses
Chapter
Chapter II · Obligations of Data Fiduciary
Status
Enacted · phased commencement
Full compliance
13 May 2027
Applies to
Data Fiduciaries
Official citation
DPDP Act, 2023, s.7
Reading time
5 min
Updated
August 2026

At a glance

Section 7 sets out a closed list of legitimate uses that let a Data Fiduciary process personal data without consent. These include data the person voluntarily provided for a specified purpose, certain State functions and subsidy or service delivery, legal obligations and court orders, medical emergencies and public-health measures, disaster and public-order response, and specified employment purposes. It is a fixed list, not an open balancing test.

Applies to Data FiduciariesChapter Chapter IIEffective 13 May 2027Read time 6 min

Key takeaways

  • Legitimate uses are an alternative to consent, a closed, listed set of situations.
  • The most common one for business: data a person voluntarily provided for a specified purpose and has not objected to.
  • Covers medical emergencies and public-health measures during epidemics or outbreaks.
  • Covers disaster and breakdown of public order response.
  • Covers specified employment purposes and safeguarding the employer from loss or liability.
  • There is no open "legitimate interests" test, if your use is not on the list, you need consent.

Who should read this

Read this if you want to process data without asking for consent, it tells you the only situations where that is allowed, and how narrow they are.

FoundersLegal / DPOCompliance leadsProduct / engineering

In plain language

Section 7 is the counterweight to consent. It recognises that some processing should not need a consent click, and lists the situations where a Data Fiduciary may process without consent. The catch: it is a closed list. If your use is not on it, consent is your route.

For ordinary businesses, the workhorse is the first item: where a person has voluntarily provided their data for a specified purpose and has not indicated they object, you may use it for that purpose. Think of someone handing over an email to get an invoice.

The rest of the list is about necessity and public interest: medical emergencies, public-health measures during outbreaks, disaster and public-order response, legal obligations, court orders, certain State functions, and defined employment purposes such as protecting the employer from loss or liability.

The text of the law

Section 7: Certain legitimate uses (summary of the listed uses)

Voluntary provision Where the Data Principal has voluntarily provided her personal data for a specified purpose and has not indicated that she objects to its use.

State functions and benefits For the State and its instrumentalities to provide or issue a subsidy, benefit, service, certificate, licence or permit, subject to conditions; and for performance of functions under law or in the interest of the sovereignty, integrity and security of India.

Legal obligations and orders For fulfilling any legal obligation to disclose information to the State, and for compliance with any judgment, decree or order under law.

Medical and public health For responding to a medical emergency involving a threat to life or health, and for measures during an epidemic, outbreak of disease or other threat to public health.

Disaster and public order For measures to ensure safety of, or provide assistance or services to, individuals during a disaster or any breakdown of public order.

Employment For employment purposes, including safeguarding the employer from loss or liability (such as protecting confidentiality of trade secrets or classified information) or providing a service or benefit to an employee.

This is a plain-language summary of the legitimate uses listed in Section 7. Always confirm against the official Gazette text for authoritative language.

What this means for you

  • Prefer the voluntary provision use for straightforward, expected processing, but honour any objection.
  • Do not stretch a legitimate use to cover marketing or profiling, those generally need consent.
  • For each legitimate use you rely on, document why it fits the listed category.
  • Remember the security, breach and erasure duties in Section 8 still apply.

Frequently asked questions

What are the legitimate uses under the DPDP Act?
A closed list in Section 7: voluntarily provided data, certain State functions and benefits, legal obligations and court orders, medical emergencies and public-health measures, disaster and public-order response, and specified employment purposes.
Can I use legitimate uses instead of consent for marketing?
Generally no. Marketing and behavioural profiling fall outside the listed legitimate uses and typically require consent.
Is there a legitimate interests balancing test?
No. Unlike the GDPR, the Act uses a fixed list rather than an open balancing test.
Do other duties still apply if I rely on a legitimate use?
Yes. Security safeguards, breach notification, accuracy and erasure duties under Section 8 apply regardless of the ground.

Sources

This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.

Start readiness assessment