Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Data mapping collection · Why you process it

Mapping Consent, Purpose and Legitimate Uses Under the DPDP Act

The DPDP Act lets you process personal data for a lawful purpose with consent, or for certain legitimate uses listed in Section 7. This guide shows how to record, for each processing activity, the purpose, the ground you rely on, the evidence and the owner. It builds on your data inventory. It includes a worked example and a free Excel map.

By the DPDPActIndia editorial team · Last updated 4 October 2026 · About 21 minute read · Checked against the Act text and the DPDP Rules, 2025 · Editorial policy

In short

A purpose and ground map links each processing activity to its specified purpose and to the Section 4 ground that supports it: consent, or one of the nine certain legitimate uses in Section 7. It also records the notice, the consent record, the owner and the route that stops processing. The Act does not require the map. It is the practical way to show, activity by activity, why you hold the data.

  • What the Act says: Section 4 allows processing for a lawful purpose with the Data Principal's consent or for certain legitimate uses. Section 7 lists those uses, clauses (a) to (i).
  • What it does not say: not every activity needs consent, and Section 7 is not a general business-interest ground. We found no ground called legitimate interest and no separate ground for contract performance.
  • The method: one row per activity and purpose, a ground chosen on the facts, a reason written down, and evidence attached.
Phase 1
Name
Write each purpose in the words of the notice.
Phase 3
Prove
Attach the notice, the record and the stop route.
In this article
  1. The basics
  2. Three concepts, one map
  3. The 7 columns of the map
  4. What the DPDP Act says
  5. Purpose, legitimate uses and consent
  6. Mapping purpose
  7. Mapping legitimate uses: Section 4 vs Section 7
  8. How to choose the ground
  9. Mapping consent and evidence
  10. Fill it in
  11. Worked example: a fictional store
  12. Build and use it
  13. The free map
  14. Step-by-step implementation
  15. 7 common mistakes
  16. FAQ
  17. Related resources
  18. Primary sources

The basics

What is consent, purpose and legitimate uses mapping? Three concepts, one map

It means recording, for every processing activity, what the purpose is and which Section 4 ground you rely on, so that you can show why each set of personal data is held. The ground is either consent or one of the certain legitimate uses in Section 7. The map sits on top of your personal data inventory, which says what data you hold, and your data flow map, which says where it goes.

In this guide, applicable ground is our plain shorthand for the Section 4 route that supports an activity. The Act's heading for Section 4 is “Grounds for processing personal data”. We avoid “lawful basis” and “legitimate interest”, which are terms from other laws.

Three concepts and the question each answers
ConceptCore questionWhat the map recordsWhere it is covered
PurposeWhy are we processing this personal data?One specified purpose per activity, in the notice's wordsMapping purpose
Legitimate usesAre we relying on one of the specified uses in Section 7?The clause, (a) to (i), and a written reasonMapping legitimate uses
ConsentDid we obtain, and can we show, consent where we rely on it?The notice version, the consent record and the withdrawal routeMapping consent and evidence

Read each row as one chain: processing activity, personal data, purpose, consent or the applicable legitimate use, system, evidence, owner. Not every activity needs consent. Each row records the one ground it relies on.

What this page does not do

It does not teach consent management. For notice wording, valid consent, records and withdrawal, use the consent management guide, valid consent under Section 6, notice vs consent and how to prove consent. This page is about connecting each activity to its purpose and ground.

The method

The 7 columns of the map: from activity to owner

Each row follows seven links: activity, personal data, purpose, applicable ground, notice or consent evidence, system and owner. A row with a missing link is a gap. The first four links answer why you process. The last three answer how you can show it and who is responsible.

1ActivityWhat you do.From the inventory
2Personal dataWhich categories.Only what is needed
3PurposeIn the notice's words.The specified purpose
4Applicable groundConsent or Section 7.With a written reason
5EvidenceNotice and record.Version and date
6SystemWhere it runs.Including vendors
7OwnerWho answers for it.And the stop route

The law

What the DPDP Act says about purpose, consent and legitimate uses

Section 4 is the gate. It allows processing for a lawful purpose either with consent or for certain legitimate uses. Sections 5 and 6 govern the notice and the consent. Section 7 lists the legitimate uses. The table paraphrases these provisions.

Legal position

The table is a short paraphrase. It is not a quotation and it is not legal advice. Read the exact words in the Act and the Rules before relying on any row.

Provisions behind the purpose and ground map
ProvisionWhat it says, in shortWhat it means for the map
Section 4Personal data may be processed only in accordance with the Act and for a lawful purpose, for which the Data Principal has given consent or for certain legitimate uses. A lawful purpose is one not expressly forbidden by law.Every row needs one of two grounds: consent or a Section 7 use.
Section 2, specified purposeThe purpose mentioned in the notice given to the Data Principal under the Act.Write the purpose in the notice's words.
Section 5 and Rule 3A request for consent must be accompanied or preceded by a notice. Rule 3 requires an itemised description of the data, the specified purposes, the goods, services or uses enabled, and how to withdraw consent, exercise rights and complain.Record the notice version for each purpose.
Section 6(1)Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action. It covers the specified purpose and only the data necessary for it.One purpose per row. Do not collect extra data under the same consent.
Sections 6(4) and 6(6)Consent can be withdrawn, with ease comparable to giving it. After withdrawal the Data Fiduciary must, within a reasonable time, cease processing and cause its Data Processors to cease, unless the law requires or authorises it.Record the route that stops processing, including at vendors.
Section 6(10)Where a question arises, the Data Fiduciary must prove that notice was given and that consent was given in line with the Act and Rules.Attach a consent record to every consent row.
Section 7A Data Fiduciary may process personal data for any of nine listed uses, clauses (a) to (i).Quote the clause, and check that your facts fit its words.
Section 9Separate rules apply to the personal data of a child.Flag any row that involves a child and read Section 9 first.

What we found no provision for: a requirement to keep a purpose and ground map, a ground called legitimate interest, or a separate ground for performing a contract. The map is a practical tool. It is not a legal duty, and the ground you record is your own documented view.

Write it well

Mapping purpose: how to write a purpose you can map, specific, single and in the notice's words

A mappable purpose is specific, covers one thing, and uses the same words as the notice. Vague purposes make the ground impossible to judge, because you cannot test whether an activity stays inside a purpose that has no edges.

Weak purposes and better versions (illustrative)
WeakBetterWhy
Business purposesProcess the order and arrange deliverySays what actually happens to the data.
Marketing and improvementSend offers by email; measure which pages are usedTwo purposes, two rows, probably two grounds.
Legal complianceKeep invoices as required by a named lawNames the source, so the retention rule can cite it.

When a purpose changes, add a new row. Do not edit the old one in place. The new purpose needs its own notice wording and its own ground, and the old row keeps the history.

Keep them apart

Mapping legitimate uses: Section 4 grounds vs Section 7 legitimate uses and how they fit together

Section 4 is the framework with two grounds. Section 7 is the list that fills in the second ground. Consent is the first ground. Certain legitimate uses is the second, and Section 7 says what those uses are. They are not three separate routes, and Section 7 is not the Act's version of “legitimate interest”.

Ground 1: consent

  • Given by the Data Principal for a specified purpose.
  • Preceded by a notice (Section 5).
  • Free, specific, informed, unconditional and unambiguous (Section 6(1)).
  • Can be withdrawn at any time (Section 6(4)).
  • You must be able to prove it (Section 6(10)).

Ground 2: certain legitimate uses

  • Nine named uses in Section 7, clauses (a) to (i).
  • No consent is needed for that use, but the facts must fit the clause.
  • For a detailed side-by-side, see consent vs certain legitimate uses.
Three terms to keep out of your map

Lawful basis and legitimate interest come from the GDPR. The Act speaks of grounds for processing and certain legitimate uses, and Section 7 is a closed list of nine named uses. Contract is not a ground in the Act either. For a service activity, the question is whether consent or a Section 7 clause fits, and for many service activities the clause to examine is 7(a). Whether it fits depends on the facts, so get legal advice for hard cases.

The nine certain legitimate uses in Section 7, in plain words (paraphrase)
ClauseUse in short
7(a)The specified purpose for which the person voluntarily provided her data, where she has not indicated that she does not consent to that use.
7(b)The State and its instrumentalities giving a prescribed subsidy, benefit, service, certificate, licence or permit (Rule 5 and the Second Schedule apply).
7(c)The State performing a function under a law, or acting in the interest of sovereignty, integrity or security.
7(d)Meeting a legal obligation to disclose information to the State or its instrumentalities.
7(e)Complying with a judgment, decree or order, including certain orders on contractual or civil claims under a law outside India.
7(f)Responding to a medical emergency involving a threat to life or an immediate threat to health.
7(g)Medical treatment or health services during an epidemic, outbreak or other public health threat.
7(h)Safety, assistance or services during a disaster or a breakdown of public order.
7(i)Employment, and safeguarding the employer from loss or liability.

Clause 7(d) is narrower than “any legal obligation”. It speaks of an obligation to disclose information to the State. A law that makes you keep records is a different point: Section 8(7) allows retention where it is necessary for compliance with law, and our retention and erasure mapping guide covers that. Exemptions under Section 17 are also separate from Section 7. Map them only after legal advice.

Decide

How to choose the applicable ground for each activity: five questions

Ask where the data came from, whether a Section 7 clause fits its words, whether you can ask for consent for this purpose alone, whether the purpose is in the notice, and whether a child is involved. If the answer is unclear, write To confirm and ask for legal advice. Do not guess.

1Did the person give this data herself, for this purpose?

Why it matters
Section 7(a) covers data the person voluntarily provided for the specified purpose. Data you received from a third party, collected automatically or created yourself is not obviously within it. Check the source column in your inventory.

2Does another Section 7 clause fit the facts?

Why it matters
Employment (7(i)), a legal duty to disclose to the State (7(d)) and a court order (7(e)) are the ones most businesses meet. Read the clause itself, not a summary, and use it only for what the clause covers.

3If neither fits, can you ask for consent for this purpose alone?

Why it matters
Consent must be specific, unconditional and limited to the data necessary for the purpose (Section 6(1)). You need a notice first, a clear affirmative action, and a way for the person to withdraw.

4Is the purpose in the notice, in the same words?

Why it matters
The specified purpose is defined by the notice. A purpose that appears in the map and not in the notice is a gap worth fixing before anything else.

5Does the activity involve a child's data?

Why it matters
Section 9 sets separate rules. Flag the row and read Section 9 and the related Rules before choosing a ground.

Prove it

Mapping consent and evidence: what to attach to each ground

The evidence depends on the ground: for consent, the notice version and the consent record; for Section 7(a), the source and any notice; for other clauses, the clause, the legal source and who approved. The map points to the evidence. It does not replace it.

What to record for each ground
GroundAttach to the rowStop route
ConsentNotice version and date; consent record (who, when, what they saw, what they did); withdrawal log.Withdrawal as easy as giving consent (Section 6(4)), reaching systems and vendors (Section 6(6)).
Section 7(a)That the person gave the data herself for this purpose; the notice, if you gave one; any record that she objected.The use ends if she indicates she does not consent to it.
Other Section 7 clauseThe clause; the law, order or emergency that fits it; the limit of what you may do; who approved.The clause's own end point, for example the order being met.
Notice and Section 7 uses

Section 5 ties notice to requests for consent, and Rule 3 describes the notice as giving the details needed for specific and informed consent. Yet the Act defines the specified purpose by the notice, and Section 7(a) refers to the specified purpose. We found no provision that settles whether every Section 7 use needs a notice. Many advisers suggest giving one anyway. Take legal advice for your case, and use the notice column to see where there is none.

Worked example

Worked example: a purpose and ground map for a fictional online store

Seven activities, each with a purpose, a ground, a reason and its evidence, and four of them with a gap that a first pass would find. The rows are fictional and show how to fill in the map. The grounds are not legal conclusions for any real business.

Purpose and ground map for the fictional store (illustrative)
ActivityPersonal dataSourceSpecified purposeApplicable ground and reasonNotice and consent evidenceSystem and ownerGap flag
M-001
Customer account · PA-002
Name, email, phone, addressGiven by the person for this purposeRun the customer account and show past ordersConsent
The account is optional. The customer ticks a box at sign-up for this purpose only.
Notice: N-02 v2, 1 Sep 2026
Consent record: Sign-up checkbox log, time-stamped
Approved: Legal counsel, 2 Oct 2026
Web shop, order database
Customer team
None
M-002
Order fulfilment · PA-001
Name, delivery address, phone, items orderedGiven by the person for this purposeDeliver the orderS7(a) Voluntarily provided
The customer gave the address to receive this order and has not objected.
Notice: N-02 v2, 1 Sep 2026
Consent record: none
Approved: Legal counsel, 2 Oct 2026
Order database, courier portal
Operations
None
M-003
Newsletter · PA-003
Name, emailGiven by the person for another purposeSend offers and the newsletterConsent
Marketing is a different purpose from the order, so it needs its own consent.
Notice: N-03 v1, 1 Sep 2026
Consent record: none
Approved: Marketing head, 2 Oct 2026
Email platform
Marketing
No consent record
M-004
Support tickets · PA-004
Name, email, order number, messageGiven by the person for this purposeAnswer the customer queryS7(a) Voluntarily provided
The customer wrote in to get help and has not objected.
Notice: N-02 v2, 1 Sep 2026
Consent record: none
Approved: no
Helpdesk software
Support
Ground not approved
M-005
Server access logs · PA-006
IP address, user ID, timeCollected automaticallyDetect and investigate unauthorised accessTo confirm
(no reason written)
Notice: none
Consent record: none
Approved: no
Web server, log store
IT
Ground to confirm
M-006
CVs sent by recruiters · PA-008
CV, contact detailsReceived from a third partyAssess candidates for the open roleS7(a) Voluntarily provided
The recruiter sent the CV for this role.
Notice: none
Consent record: none
Approved: HR head, 2 Oct 2026
Hiring tool
HR
7(a) needs data given for this purpose
M-007
Payroll and staff records · PA-007
Name, bank details, salary, attendanceGiven by the person for this purposePay salaries and manage employmentS7(i) Employment
The processing is for employment purposes.
Notice: Staff notice v1, 1 Apr 2026
Consent record: none
Approved: HR head and counsel, 2 Oct 2026
HR system
HR
None

The flags show the first gap found in each row.

  • M-003, newsletter: the email came from checkout, so it was given for another purpose. Marketing needs its own consent, and the row has no consent record yet.
  • M-004, support tickets: the ground is chosen but nobody approved it.
  • M-005, server logs: the ground is not decided and the row is unverified.
  • M-006, recruiter CVs: Section 7(a) covers data the person voluntarily provided. The candidate did not send this CV herself, so the clause needs a second look.
Why some rows differ from the retention guide

The retention and erasure guide set every example row to consent, to keep that page simple. Here the choice is examined. A real business should decide each row on its own facts.

Build and use it

The free Purpose and Basis Map: Excel file, fields and gap flags

The map is one working sheet with 18 fields, a filled example, gap flags and a summary. Enter your details and your download link appears on the next page.

DPDP Act Purpose and Basis Map 2026

Excel (.xlsx), about 21 KB. Sheets: Start here, Map (60 rows), Example, Summary, Lists. Gap flags are formulas. The example is fictional and its grounds are not legal conclusions.

Get the Purpose and Basis Map (free .xlsx)

Enter your details and you will get your download link on the next page. All fields except phone are required.

Free. Internal self-assessment aid, not certification or legal advice. If you do not get your download link, write to hi@dpdpactindia.in.

The 18 fields fall into five groups. Identify: map ID, activity ID, activity, personal data, whose data. Source and purpose: how the data reached you, the specified purpose. Ground: the applicable ground, why it applies, who approved it. Evidence: notice version, consent record, child data. Run: systems, processor IDs, owner, the route that stops processing, last verified date. It uses the same activity IDs as the inventory and the same processor IDs as the flow worksheet.

How the gap flags work

A gap flag shows the first gap found in a row. It is a prompt to check, not a finding of non-compliance. A row is flagged when it has no purpose, a ground still to confirm, a Section 7(a) ground on data the person did not give for this purpose, a consent ground with no record, no notice recorded, no written reason, no approver, child data, no owner, no stop route or no verification date.

Build and use it

Step-by-step implementation: map purpose and ground in 6 steps

Pull the activities from your inventory, write each purpose in the notice's words, record the data source, choose and justify the ground, attach the evidence and stop route, then review the gaps. Each step has an output you can check.

1Pull the activities from the inventory

What to do
Copy the activity IDs, activity names and data categories from your personal data inventory. Start with the busiest or most sensitive activities.
Output
One map row per activity.

2Write each purpose in the notice's words

What to do
Open the notice that people see and copy the purpose wording. Split bundled purposes into separate rows.
Output
One specified purpose per row.

3Record how the data reached you

What to do
Mark each row as given by the person for this purpose, given for another purpose, collected automatically, received from a third party, created by you or received from the State or a court.
Output
A source value on every row.

4Choose the ground and write the reason

What to do
Use the five questions above. Pick consent, a named Section 7 clause or To confirm. Write one sentence on why the facts fit. Ask a legal adviser about hard cases and record who approved.
Watch for
Using To confirm as a permanent state. Give each one an owner and a date.
Output
A ground, a reason and an approver on every row.

5Attach the evidence and the stop route

What to do
Add the notice version, the consent record where the ground is consent, a child-data flag, the owner, the systems and vendors, and the route by which a withdrawal or objection reaches the activity.
Output
Evidence and a stop route on every row.

6Review the gaps and set review triggers

What to do
Read the gap flags and the summary. Assign each gap. Re-open a row when a purpose, notice, vendor or law changes, and link it to the retention register so each purpose ends on its own trigger.
Watch for
A map that is complete once and never touched again.
Output
A gap list with owners and a review date.

Build and use it

7 common mistakes when mapping consent, purpose and legitimate uses

Most weak maps use one ground for everything, borrow terms from other laws or leave out the evidence. These seven are the usual causes.

Common mistakes and fixes
MistakeWhy it hurtsFix
1. Setting every row to consentConsent can be withdrawn and must be provable. It is not the only ground, and a weak consent is a weak ground.Decide each row on its facts, and record the reason.
2. Treating 7(a) as a catch-allIt covers data the person provided for the specified purpose, not every use of any data.Check the source and the purpose before using it.
3. Importing GDPR termsLawful basis and legitimate interest are not Act terms, and the reasoning does not carry over.Use consent and the named Section 7 clauses.
4. Bundling purposesOne ground cannot cover two different purposes.One purpose per row.
5. Choosing a ground with no reason or approverNobody can review or defend it.Write one sentence and name the approver.
6. Mapping the ground but not the stop routeA withdrawal or objection does not reach every system.Record the route and the vendors it must reach.
7. Skipping child dataSection 9 sets separate rules.Flag the row and read Section 9 first.

Questions

Frequently asked questions: consent, purpose and legitimate uses under the DPDP Act

What is purpose mapping under the DPDP Act?

It means recording, for each processing activity, the specified purpose, the Section 4 ground you rely on (consent or a Section 7 use), the evidence and the owner. We found no provision that requires it. It is a practical way to show why you hold each set of data.

Does every processing activity need consent under the DPDP Act?

No. Section 4 allows processing for a lawful purpose with the Data Principal's consent or for certain legitimate uses. Section 7 lists nine such uses. Which ground applies depends on the facts. Where no Section 7 clause fits, consent is the route.

Is legitimate interest a ground under the DPDP Act?

We found no ground called legitimate interest. The Act speaks of certain legitimate uses and lists nine of them in Section 7. They are named and narrow, and they are not a general business-interest test. Do not carry over reasoning from other laws.

What is the difference between Section 4 and Section 7?

Section 4 sets the two grounds for processing: consent, or certain legitimate uses. Section 7 lists what those legitimate uses are. Section 7 therefore sits inside the framework of Section 4 and does not stand beside it.

Can I rely on Section 7(a) for any data a customer gives me?

No. Section 7(a) covers the specified purpose for which the person voluntarily provided her data, where she has not indicated that she does not consent to that use. The Act's own illustration is a pharmacy using a phone number given for a receipt to send the receipt. A different purpose, such as marketing, or data that came from someone else, is outside that wording and needs a separate look.

Is there a contract ground under the DPDP Act?

We found no separate ground for performing a contract. For a service activity, the question is whether consent or a Section 7 clause fits the facts. Many service activities are examined under Section 7(a). Whether it fits is a legal judgment, so take advice and record who approved the call.

Do I need a notice if I rely on a Section 7 use?

Section 5 ties notice to requests for consent, and Rule 3 describes notice content for specific and informed consent. The Act also defines the specified purpose by reference to a notice. We found no provision that settles whether every Section 7 use needs one. Many advisers suggest giving a notice anyway, so take legal advice for your case.

Does the Act require a record of processing activities or a consent register?

We found no express duty to keep a record of processing activities. Section 6(10) does place the burden of proving notice and consent on the Data Fiduciary, which is a practical reason to keep records. See data mapping vs data inventory vs RoPA for the comparison.

What happens to the map when the purpose changes?

Add a new row. Consent is specific to a purpose under Section 6(1), so on a plain reading consent for the old purpose does not stretch to the new one. The new purpose needs its own notice wording and ground.

How does the map connect to consent withdrawal and erasure?

The stop route column shows how a withdrawal reaches each activity and vendor. Under Section 6(6), after withdrawal you must cease processing within a reasonable time and cause processors to cease, unless the law requires or authorises otherwise. Erasure is a separate step under Section 8(7). See consent withdrawal and retention and erasure mapping.

Related

Continue the data mapping collection

Go to the full method, the legal text and the practical tools. When you are ready to move from records to working controls, see the DPDP implementation framework.

Sources

Primary sources and regulatory references

  1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India, 11 August 2023. Sections 2, 4, 5, 6, 7, 8, 9 and 17 are cited here.
  2. The Digital Personal Data Protection Rules, 2025, notified 13 November 2025 (G.S.R. 846(E)). Rules 3 and 5, and the Second Schedule, are cited here.
  3. Our complete data mapping guide and section-by-section Act pages.
About this article. Prepared by the DPDPActIndia editorial team under our editorial policy. It explains the Act and Rules in general terms and is not legal advice (disclaimer).