DPDPA Section 7 explained: the limited legitimate uses that need no separate consent, and why most commercial processing still requires it.
The legitimate uses include personal data a person has voluntarily provided for a specified purpose and not objected to, processing by the State or its instrumentalities to provide benefits, subsidies, services, certificates, licences or permits, compliance with a law or judgment, medical emergencies and threats to public health, disaster and public-order situations, and certain employment-related purposes.
Each use is purpose-bound. It permits the processing that fits the listed situation, not a general licence to use the data for anything.
Unlike the GDPR, which offers a broad legitimate-interests basis subject to a balancing test, the DPDP Act enumerates a closed list of legitimate uses. There is no open-ended legitimate-interests basis for marketing, analytics or profiling.
That is why, for most websites and apps, consent under Section 6 remains the route for cookies, analytics, advertising and personalization, and getting the consent flow right is central to compliance.
This page is a plain-English summary of the Digital Personal Data Protection Act, 2023 for general information and is not legal advice. Confirm your obligations with qualified counsel.
DPDPA-native consent, Section 9 age-gate and verifiable receipts. Start free or take the DPDPA quiz.