DPDP Guide · Consent
When can an Indian business process personal data without consent? The answer is Section 7, a closed list of legitimate uses, and it is far narrower than teams migrating from GDPR expect.
In short
Under the DPDP Act a Data Fiduciary needs a lawful purpose plus either consent (Section 6) or one of the certain legitimate uses in Section 7. Section 7 is a closed statutory list, not an open "legitimate interest" test like the GDPR. It covers narrow situations such as data the individual voluntarily provided, certain State functions, legal obligations and court orders, medical emergencies, public health and disasters, and employment purposes. If your processing does not fit one of those grounds, you need valid consent.
Section 4 sets the rule: a Data Fiduciary may process personal data only for a lawful purpose, and only where it has either the individual's consent or a legitimate use listed in Section 7. Everything flows from those two grounds. Consent is the default most businesses will rely on; Section 7 is the tightly-drawn set of exceptions.
Section 7 is a closed list. Unlike the GDPR's Article 6(1)(f) "legitimate interests", there is no balancing test you can run to invent your own ground. Either your processing fits a listed use or it does not.
The practically important legitimate uses for most organisations are:
The most common business mistake is stretching 7(a) "voluntary provision" to cover data your own form collected. If your website, app or staff prompted for it, that is a consent scenario, not a legitimate use.
A legitimate use removes the need for consent. It does not remove the rest of the DPDP framework. Even when you rely on Section 7 you still owe:
Most marketing, analytics, profiling, advertising and unrelated reuse of data still needs consent. Section 7 is not a business-convenience clause, and treating it as one is the fastest route to an invalid processing claim.
Work through it in order, and default to consent whenever the answer is unclear.
They are the specific situations in Section 7 where a Data Fiduciary may process personal data without consent, including voluntary provision, certain State functions and benefits, legal obligations and court orders, medical emergencies, public health and disasters, and employment purposes. It is a closed list.
No. GDPR legitimate interests is an open-ended basis you justify with a balancing test. Section 7 is a closed statutory list with no balancing test. A GDPR legitimate interests assessment does not translate into a valid DPDP ground.
No. You can only skip consent when your processing clearly fits a listed use. Most marketing, analytics, profiling and unrelated reuse still requires consent under Section 6.
Generally no. Data is voluntarily provided only when the individual initiates the transfer unprompted. Once you ask, prompt or provide an input field, collecting that data is a consent scenario.
Yes. Section 7 removes the need for consent only. Purpose limitation, security safeguards, retention limits, processor contracts and breach response all still apply.
General information about the DPDP Act and Rules, not legal advice, and not affiliated with any government body.