Chapter II · Obligations of Data Fiduciary
Section 7: Certain legitimate uses
Section 7 lists the situations where a Data Fiduciary may process personal data without fresh consent, from data a person voluntarily provides, to medical emergencies, legal duties and certain employment purposes.
- Chapter
- Chapter II · Obligations of Data Fiduciary
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027
- Applies to
- Data Fiduciaries
- Official citation
- DPDP Act, 2023, s.7
- Reading time
- 5 min
- Updated
- August 2026
At a glance
Section 7 sets out a closed list of legitimate uses that let a Data Fiduciary process personal data without consent. These include data the person voluntarily provided for a specified purpose, certain State functions and subsidy or service delivery, legal obligations and court orders, medical emergencies and public-health measures, disaster and public-order response, and specified employment purposes. It is a fixed list, not an open balancing test.
Key takeaways
- Legitimate uses are an alternative to consent, a closed, listed set of situations.
- The most common one for business: data a person voluntarily provided for a specified purpose and has not objected to.
- Covers medical emergencies and public-health measures during epidemics or outbreaks.
- Covers disaster and breakdown of public order response.
- Covers specified employment purposes and safeguarding the employer from loss or liability.
- There is no open "legitimate interests" test, if your use is not on the list, you need consent.
Who should read this
Read this if you want to process data without asking for consent, it tells you the only situations where that is allowed, and how narrow they are.
In plain language
Section 7 is the counterweight to consent. It recognises that some processing should not need a consent click, and lists the situations where a Data Fiduciary may process without consent. The catch: it is a closed list. If your use is not on it, consent is your route.
For ordinary businesses, the workhorse is the first item: where a person has voluntarily provided their data for a specified purpose and has not indicated they object, you may use it for that purpose. Think of someone handing over an email to get an invoice.
The rest of the list is about necessity and public interest: medical emergencies, public-health measures during outbreaks, disaster and public-order response, legal obligations, court orders, certain State functions, and defined employment purposes such as protecting the employer from loss or liability.
The text of the law
Section 7: Certain legitimate uses (summary of the listed uses)
Voluntary provision Where the Data Principal has voluntarily provided her personal data for a specified purpose and has not indicated that she objects to its use.
State functions and benefits For the State and its instrumentalities to provide or issue a subsidy, benefit, service, certificate, licence or permit, subject to conditions; and for performance of functions under law or in the interest of the sovereignty, integrity and security of India.
Legal obligations and orders For fulfilling any legal obligation to disclose information to the State, and for compliance with any judgment, decree or order under law.
Medical and public health For responding to a medical emergency involving a threat to life or health, and for measures during an epidemic, outbreak of disease or other threat to public health.
Disaster and public order For measures to ensure safety of, or provide assistance or services to, individuals during a disaster or any breakdown of public order.
Employment For employment purposes, including safeguarding the employer from loss or liability (such as protecting confidentiality of trade secrets or classified information) or providing a service or benefit to an employee.
This is a plain-language summary of the legitimate uses listed in Section 7. Always confirm against the official Gazette text for authoritative language.
What this means for you
- Prefer the voluntary provision use for straightforward, expected processing, but honour any objection.
- Do not stretch a legitimate use to cover marketing or profiling, those generally need consent.
- For each legitimate use you rely on, document why it fits the listed category.
- Remember the security, breach and erasure duties in Section 8 still apply.
Frequently asked questions
What are the legitimate uses under the DPDP Act?
Can I use legitimate uses instead of consent for marketing?
Is there a legitimate interests balancing test?
Do other duties still apply if I rely on a legitimate use?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.