Readiness assessment

DPDP Guide · Consent

Consent vs Certain Legitimate Uses Under the DPDP Act (Section 7)

When can an Indian business process personal data without consent? The answer is Section 7, a closed list of legitimate uses, and it is far narrower than teams migrating from GDPR expect.

In short

Under the DPDP Act a Data Fiduciary needs a lawful purpose plus either consent (Section 6) or one of the certain legitimate uses in Section 7. Section 7 is a closed statutory list, not an open "legitimate interest" test like the GDPR. It covers narrow situations such as data the individual voluntarily provided, certain State functions, legal obligations and court orders, medical emergencies, public health and disasters, and employment purposes. If your processing does not fit one of those grounds, you need valid consent.

Two grounds, not one

Section 4 sets the rule: a Data Fiduciary may process personal data only for a lawful purpose, and only where it has either the individual's consent or a legitimate use listed in Section 7. Everything flows from those two grounds. Consent is the default most businesses will rely on; Section 7 is the tightly-drawn set of exceptions.

The law

Section 7 is a closed list. Unlike the GDPR's Article 6(1)(f) "legitimate interests", there is no balancing test you can run to invent your own ground. Either your processing fits a listed use or it does not.

What Section 7 actually covers

The practically important legitimate uses for most organisations are:

  • Voluntary provision (7a). Data the individual provided on their own initiative for a specified purpose, where they have not indicated they do not consent. This is narrow: the moment you prompt, ask or provide a form, the data is no longer "voluntarily provided" and you need consent.
  • State functions and benefits. Processing by the State or its instrumentalities to provide subsidies, benefits, services, certificates, licences or permits, subject to the standards in the Second Schedule, including an intimation to the individual.
  • Legal obligation and court orders. Processing needed to comply with a law or a judgment.
  • Medical emergency. Where processing is needed to respond to a threat to life or health.
  • Public health and disasters. Epidemics, threats to public health, and breakdown of public order or disaster situations.
  • Employment. Purposes related to employment, such as safeguarding the employer from loss, providing a benefit to the employee, and protecting confidentiality or trade secrets.
Practice

The most common business mistake is stretching 7(a) "voluntary provision" to cover data your own form collected. If your website, app or staff prompted for it, that is a consent scenario, not a legitimate use.

What Section 7 does not switch off

A legitimate use removes the need for consent. It does not remove the rest of the DPDP framework. Even when you rely on Section 7 you still owe:

  • Purpose limitation, so the data is used only for the legitimate use you relied on.
  • Reasonable security safeguards.
  • Retention limits and erasure when the purpose is served.
  • Processor contracts, breach response, and the ability to explain the decision later.
Risk

Most marketing, analytics, profiling, advertising and unrelated reuse of data still needs consent. Section 7 is not a business-convenience clause, and treating it as one is the fastest route to an invalid processing claim.

How to decide: consent or legitimate use

Work through it in order, and default to consent whenever the answer is unclear.

  • Did the individual provide the data entirely on their own initiative, unprompted? If not, 7(a) does not apply.
  • Does the processing fit one of the other listed uses exactly, on its plain wording? If it only "sort of" fits, it does not.
  • Is the purpose the same one the legitimate use permits, with no unrelated reuse? If you want to reuse the data, you likely need consent.
  • If any step is vague, use consent under Section 6 instead.

Consent vs legitimate uses: frequently asked questions

What are legitimate uses under the DPDP Act?

They are the specific situations in Section 7 where a Data Fiduciary may process personal data without consent, including voluntary provision, certain State functions and benefits, legal obligations and court orders, medical emergencies, public health and disasters, and employment purposes. It is a closed list.

Is Section 7 the same as GDPR legitimate interests?

No. GDPR legitimate interests is an open-ended basis you justify with a balancing test. Section 7 is a closed statutory list with no balancing test. A GDPR legitimate interests assessment does not translate into a valid DPDP ground.

Can a business always skip consent using Section 7?

No. You can only skip consent when your processing clearly fits a listed use. Most marketing, analytics, profiling and unrelated reuse still requires consent under Section 6.

Does "voluntarily provided" cover data my form collects?

Generally no. Data is voluntarily provided only when the individual initiates the transfer unprompted. Once you ask, prompt or provide an input field, collecting that data is a consent scenario.

If I rely on a legitimate use, do the other DPDP rules still apply?

Yes. Section 7 removes the need for consent only. Purpose limitation, security safeguards, retention limits, processor contracts and breach response all still apply.

Sources

  • Digital Personal Data Protection Act, 2023, Sections 4 and 7.
  • Digital Personal Data Protection Rules, 2025, Second Schedule (standards for State processing under Section 7).

General information about the DPDP Act and Rules, not legal advice, and not affiliated with any government body.