Consent Under the DPDP Act · Part 3
Processing Under the Legitimate Uses
What circumstances the Act defines, and how to record which one applies to each purpose

Abstract
This article is the third and last in a three part series called Consent Under the DPDP Act. The first two articles dealt with consent itself, first as it arrives from a registered intermediary and then in its hardest form, where the data principal is a child. This article deals with the boundary of the requirement. Section 7 of the Digital Personal Data Protection Act 2023 sets out circumstances in which a data fiduciary may process personal data without consent, and the section is called certain legitimate uses.
The list is exhaustive and it is narrow. That combination matters more than either feature alone, because teams arriving from the General Data Protection Regulation expect something the Act does not contain. There is no ground equivalent to legitimate interests, under which a controller identifies an interest of its own, tests whether the processing is necessary, and weighs that interest against the rights of the individual. The Act instead names specific situations, and processing either falls inside one of them or it needs consent.
This article works through the grounds in the order a business will meet them. Employment, the ground carrying most of the practical weight for a private organisation. Data voluntarily provided by the individual for a specified purpose. Compliance with law and with orders of a court. The emergency and public interest grounds covering medical emergencies, public health situations, and disasters. In each case the article sets out what the ground permits and where its edge falls, because a ground read too widely offers no protection at all.
The article then covers what does not change when a legitimate use applies. Removing the consent requirement removes one obligation and leaves the rest in place, including purpose limitation, retention limits, security safeguards, and the duties owed to data principals. It closes on the record an organisation needs, a basis set against each purpose and not a general statement of position, and then draws the three articles in the series together.
1. Why the Act Has No General Alternative
1.1 An exhaustive list and not a test
Section 7 lists the circumstances in which processing may proceed without consent, and the list is closed. An organisation cannot add to it by argument, however reasonable the argument. This design choice separates the Act from frameworks that provide a general ground resting on the controller’s own assessment, and understanding the difference prevents a category of error that appears regularly in Indian compliance work.
Under the General Data Protection Regulation, a controller relying on legitimate interests performs an assessment. It identifies the interest, considers whether the processing is necessary to serve it, and balances the interest against the rights and freedoms of the data subject. Where the balance favours the controller, the processing is lawful without consent. The assessment is documented and can be challenged, and the flexibility of the ground is what makes it useful across a wide range of ordinary business activity.
Nothing of that shape appears in the Act. Its grounds are categorical, meaning that processing either matches a described situation or it does not, and no weighing exercise converts a situation outside the list into one inside it. A team that has produced a legitimate interests assessment for a European product and files it as the basis for the same processing in India has documented a test the Act does not recognise. The practical consequence is that a great deal of ordinary commercial processing, including marketing, analytics, profiling, advertising, and reuse of data for purposes unrelated to the original one, requires consent in India.
1.2 Reading a ground honestly
Because the grounds are narrow, the temptation is to read one widely enough to cover processing an organisation wants to continue. That reading is the most expensive mistake available in this part of the Act, because a ground stretched past its terms provides no protection while creating a record that the organisation considered the question and answered it wrongly. An organisation processing without consent on a basis that does not apply is processing without a basis.
A discipline that helps is to ask three questions in order before relying on any ground. Does the processing match the situation the ground describes, in its own words and not in a paraphrase. Is the processing necessary for that situation, or merely convenient alongside it. Would the organisation be comfortable stating this basis to the individual concerned and to the Board. Where any answer is uncertain, consent is the safer route, and the effort of obtaining it is smaller than the exposure of relying on a ground that does not hold.
The remaining sections describe each ground with its edge marked, because the edge is where the useful information sits. An organisation reading only what a ground permits will over apply it. An organisation that also knows where it stops can place its processing correctly, and that is the object of the exercise.
2. The Grounds a Business Will Use
2.1 Employment
The employment ground carries most of the practical weight for a private organisation. It permits processing for the purposes of employment, and for purposes related to safeguarding the employer from loss or liability. The Act names examples, including the prevention of corporate espionage, the maintenance of confidentiality of trade secrets and intellectual property, and the provision of any service or benefit sought by an employee. Payroll, performance management, workplace safety, and the administration of benefits an employee has asked for sit comfortably inside it.
The value of this ground is that it removes an awkward problem. Consent obtained from an employee is difficult to treat as freely given, because the person is in a relationship of dependence with the party asking. A framework requiring employee consent for routine employment processing would rest that processing on a weak footing. The Act avoids the difficulty by placing employment processing on a ground of its own, and an organisation should use that ground instead of collecting employee consent it would then have to defend.
Two limits mark the edge of this ground. Processing has to relate to the employment or to protecting the employer from loss or liability, so an employer using employee personal data for something unconnected to either, such as promoting an unrelated commercial venture to staff, sits outside it. And the ground covers the employment relationship and not everything an employer holds, so data about a job applicant who was never employed, or about a former employee retained past any purpose, needs its own analysis. Monitoring deserves particular care, since surveillance of employees can be within the ground where it genuinely protects against loss and outside it where it does not, and the distinction rests on what is actually being protected.
2.2 Data the individual provided voluntarily
The Act permits processing where a data principal has voluntarily provided their personal data for a specified purpose and has not indicated an objection to its use for that purpose. The ground fits situations where a person supplies information in order to receive something, and requiring a separate consent transaction would add ceremony without adding protection. A customer who gives a delivery address in order to receive a delivery has provided it voluntarily for that purpose.
The limits are strict and they follow from the words. Purpose is fixed by what the data was provided for, so an address given for a delivery is available for the delivery and not for a marketing campaign. The provision has to be voluntary, so data extracted as a condition of a service the individual could not otherwise obtain is doing something other than volunteering. And an objection ends the reliance, which means the organisation needs a route through which an objection can be made and a system that acts on one.
This ground is easier to misapply than any other, because almost all customer data was in some sense provided by the customer. The question the ground asks is narrower, being whether the specific processing now contemplated matches the purpose for which the data was given at the time. An organisation using this ground should record the purpose for which each item was provided. The first article in this series described that same register. Each new use is then tested against it instead of being treated as covered by the original provision.
2.3 Compliance with law and with orders
Two related grounds cover legal obligation. Processing is permitted for compliance with any judgment, decree, or order issued in India, and for compliance with obligations under law to disclose information to the State or its instrumentalities, subject to what the law in question provides. An organisation retaining transaction records because tax legislation requires it, or producing documents under a court order, is on solid ground and does not need consent for either.
The edge here is that the obligation has to exist. A practice the organisation regards as prudent, an industry norm, or a requirement of a contract with a commercial counterparty is not an obligation under law, and processing justified by any of those needs a different basis. Where a sectoral regulator imposes a requirement, the position is usually clear, and organisations in regulated industries should map their regulatory retention and reporting obligations explicitly, since these are the cases where this ground does the work.
A practical point concerns retention. Where law requires records to be kept for a period, that requirement stands alongside the Act and not in conflict with it, and the retention rule for those records follows the longer statutory period. Organisations frequently apply a single retention rule across a data set containing both statutory records and material with no such requirement, which either destroys records they were obliged to keep or holds data past the point its purpose was served. Separating the two inside the retention schedule is the correct treatment.
3. The Emergency and Public Interest Grounds
3.1 Medical emergency and public health
The Act permits processing for responding to a medical emergency involving a threat to the life of, or an immediate threat to the health of, the data principal or any other individual. A hospital receiving an unconscious patient can access records held elsewhere without pausing for a consent transaction, and the reason the ground exists is that the alternative would cause harm. A related ground covers measures to provide medical treatment or health services during an epidemic, an outbreak of disease, or any other threat to public health.
Both grounds are tied to the situation they describe and neither creates a general permission for health data. Routine patient engagement, appointment marketing, wellness programme promotion, and analytics performed on clinical data for commercial purposes are ordinary processing requiring an ordinary basis. The emergency ground requires an emergency, meaning something real and time bound, not a category of activity an organisation has labelled urgent.
For organisations in healthcare the practical implication is that a single system will hold data processed on several different bases. The emergency access path operates on this ground. The ongoing treatment relationship operates on its own footing. A marketing list needs consent. Retention differs across the three. Building a system that records which basis applied to which processing event, instead of treating all clinical data as one category, is what allows an organisation to answer a question about any particular record later.
3.2 Disaster and public order
A further ground permits processing for taking measures to ensure the safety of, or to provide assistance or services to, individuals during a disaster or a breakdown of public order. The situations it addresses are unpredictable and the processing it permits is bounded by the situation, which gives this ground a characteristic that organisations should build for deliberately.
That characteristic is a time limit on reliance. Processing permitted during a disaster is permitted for as long as the disaster and the measures responding to it continue. Once the situation ends, continued use of the data collected during it requires a fresh basis, and data no longer needed for the response falls under the ordinary erasure obligations. An organisation that stood up an emergency data flow during a crisis and left it running afterward is processing on a ground that has expired.
This suggests a specific practice for any organisation likely to invoke this ground, whether in logistics, utilities, telecommunications, healthcare, or public facing services. Emergency processing should be established as a defined mode with a recorded start, a named person accountable for it, and a review that closes it. Doing that in advance costs a short procedure. Doing it afterward means reconstructing what was processed, when, and on what footing, at a point when the people involved have moved on to other things.
4. What Does Not Change
4.1 The obligations that continue regardless of basis
A legitimate use removes the requirement for consent and removes nothing else. That sentence is the most useful one in this article for an organisation planning its work, because a common misreading treats a legitimate use as an exemption from the Act. Processing on any basis under the Act carries the duties of purpose limitation, so the data is used for the purpose relied on and not beyond it. It carries retention limits, so the data goes when the purpose is served or when law requires it to be kept no longer. It carries the obligation to maintain reasonable security safeguards, which sits at the highest penalty tier in the Act.
It carries the breach reporting duties, which apply to personal data regardless of the basis on which it was being processed. It carries the obligation to have a grievance redressal mechanism the data principal can use. Where the organisation engages processors, it carries the duty to bind them and to cause them to erase data when required. And the record of processing an organisation maintains has to describe processing on legitimate uses alongside processing on consent, because the record describes what the organisation does and not only the part that rests on consent.
The practical instruction is that an organisation should not organise its compliance programme around the consent boundary. A programme built to handle consent well, with legitimate use processing treated as outside its scope, will leave the retention, security, and reporting obligations unaddressed for a substantial share of the organisation’s processing. Employment data in particular can represent a large holding of personal data resting on a legitimate use, and an organisation that excluded it from scope has excluded a considerable amount of what it holds.
4.2 Rights and notice
The rights of data principals interact with basis in ways worth setting out. The right to access a summary of personal data being processed, and the right to correction, operate whatever the basis. An organisation processing employment data on a legitimate use still has to answer a request from an employee about what it holds. The grievance mechanism is available in the same way. Nomination operates independently of basis.
Erasure works differently across bases and the difference is where teams go wrong. Withdrawal of consent triggers erasure of data held for the withdrawn purpose, and there is no withdrawal to make where consent was never the basis. Data held on a legitimate use is erased when the purpose is served or when law no longer requires its retention, and an individual cannot end the processing by withdrawing something they never gave. An organisation should be able to explain that distinction clearly, since a data principal who asks for erasure of employment records and receives a refusal deserves a reason they can understand.
Notice deserves a word because the position is easy to get wrong in the other direction. The detailed notice obligation in the Rules attaches to requests for consent, and an organisation processing on a legitimate use is not making such a request. Transparency remains valuable and in some situations is expected, so the practical approach is to describe legitimate use processing in the organisation’s general privacy information even where a consent notice is not required. An employee handbook that explains what the employer processes and why is good practice and it also answers questions that would otherwise arrive as grievances.
5. Recording the Basis
5.1 A basis for each purpose
The requirement that follows from everything above is a record connecting each purpose to the basis relied on for it. A general statement that the organisation relies on consent where required and on legitimate uses where available describes an approach and not a position. What the record needs is an entry for each purpose naming the basis, and for a legitimate use naming which one.
The reason this granularity matters is that a single data set commonly supports several purposes on different bases. Employee personal data supports payroll on the employment ground, tax reporting on the legal obligation ground, an emergency contact process on the medical emergency ground, and an internal social event invitation that needs consent. Recording one basis for the data set answers none of these correctly. Recording a basis for each purpose produces a position an organisation can defend and, more usefully, a position its own engineers can implement, since retention and access rules follow the purpose and not the table.
This record is the same purpose register described in the first article of this series, extended with a basis column. An organisation that built it for the consent work has most of what this article requires, and that is one reason the register is the first piece of work to commission. An organisation that has not built it will find that questions about basis cannot be answered at all, because there is no list of purposes against which to answer them.
5.2 What the record needs to contain
Each entry needs the purpose stated in plain terms and the categories of personal data used for it. It needs the basis relied on, with the specific ground identified where that basis is a legitimate use. It needs the retention period and what determines it, the systems that perform the processing, and any processors involved. Where the basis is a legitimate use, a short note on why the ground applies is worth including, because the reasoning fades and the person who reasoned it moves on.
Two habits keep the record honest. It should be reviewed when the organisation changes what it does, through the same release checkpoint that keeps notices and data flows current, since a new purpose introduced without an entry is processing without a recorded basis. And it should be tested occasionally by picking a purpose and following it into the systems to confirm that the processing described is the processing occurring. A register that has drifted from the systems is a document and not a control.
The register also settles a question that arises repeatedly in practice. What to do when a purpose could rest on either consent or a legitimate use. The answer is to choose one, record it, and build accordingly, because the two lead to different behaviour. Processing on consent has to stop on withdrawal, and processing on a legitimate use does not, so a system built for one and documented as the other will behave incorrectly in exactly the situation a regulator examines. Making the choice explicitly, at the point the purpose is recorded, prevents that.
6. Bringing the Series Together
6.1 The three articles in sequence
This series took consent as its subject because the Act rests on it more heavily than comparable frameworks do. The first article dealt with consent arriving from outside the organisation, through the registered intermediary framework whose registration window opens in November 2026, and set out what a data fiduciary has to build in order to participate. That build has five parts. A purpose register. An authoritative consent store holding the lifecycle with its notice versions and languages. Processing systems that consult that store as they act rather than working from periodic copies. Identity resolution reliable enough to match an incoming record to the right person. A documented mapping between an intermediary’s purposes and the organisation’s own.
The second article dealt with the hardest form of consent, where the data principal is a child under eighteen. Establishing age, which no method resolves completely. Obtaining a parent whose identity is verified and not merely declared, with Rule 10 pointing toward government backed credentials. The prohibitions on tracking, behavioural monitoring, and advertising directed at children, which consent does not cure and which reach into how many products are built. And the exemptions available to defined classes for defined purposes, which are narrower than they appear and which should be documented against their conditions before they are relied on.
This third article dealt with the boundary, where the Act permits processing without consent. An exhaustive and narrow list, with no general ground resting on the organisation’s own balancing exercise. Employment as the ground carrying most weight for a private business, alongside voluntarily provided data, legal obligation, and the emergency and public interest grounds. The obligations that continue regardless of basis, which are most of them. And a record connecting each purpose to the basis relied on for it, the artefact all three articles converge on.
6.2 What the series points to
A theme runs through the three articles and it is worth naming at the end. Each of these obligations resolves into the same small set of underlying capabilities. Knowing what purposes the organisation processes for. Knowing which basis supports each one. Holding a record of consent with its lifecycle where consent is the basis. Being able to identify an individual across systems. Having processing systems that consult that state as they act. Keeping evidence of what the systems did. An organisation with those capabilities can meet the intermediary framework, the children’s obligations, and the legitimate use record keeping without treating each as a separate programme.
That is the practical reason to build in this order instead of obligation by obligation. The purpose register serves the consent work, the children’s work, and the basis record. One consent store serves both the intermediary interface and the parental consent flow. The architecture that checks state as processing occurs serves consent withdrawal and the prohibition on monitoring children. An organisation working through the Act clause by clause will build the same things several times. An organisation that builds the capabilities once will find the clauses already answered, and that is the position worth reaching before May 2027.
Conclusion
Section 7 permits processing without consent in a closed and narrow set of circumstances, and the Act contains no general ground resting on a balancing exercise of the kind the General Data Protection Regulation provides. For a private business the employment ground carries most of the weight, covering employment purposes and the protection of the employer from loss or liability, and it removes the awkwardness of relying on consent from a person in a relationship of dependence. Data voluntarily provided for a specified purpose is available for that purpose and no other. Legal obligation covers what law actually requires and not what an organisation regards as prudent. The emergency, public health, and disaster grounds are tied to their situations and reliance on them is time bound.
A legitimate use removes the consent requirement and removes nothing else, so purpose limitation, retention limits, security safeguards, breach reporting, grievance handling, processor obligations, and the record of processing all continue to apply. Rights operate whatever the basis, with erasure working differently because there is no consent to withdraw. What all of this requires is a record connecting each purpose to the basis relied on for it, with the specific ground named, the retention rule stated, and the systems identified. The record is reviewed when the organisation changes what it does, and tested against the systems occasionally. That record is the same purpose register the first article of this series described, and it is the artefact on which the whole of consent under this Act finally rests.
Continue on TrustOS: product overview · DPDPA gap assessment · documentation

