Consent is the DPDP Act's default basis for processing — but not its only one. The Act carves out a closed list of legitimate uses where personal data may be processed without consent. Understanding this list precisely matters in both directions: relying on it wrongly makes your processing unlawful, while ignoring it means chasing consent you never needed.
If you come from GDPR, resist the instinct to reason by analogy. GDPR's "legitimate interests" is an open-ended balancing test — you weigh your interest against the individual's rights and document the assessment. The DPDP Act has no such general basis. Its legitimate uses are enumerated. If your processing doesn't fit a listed item, you need consent. Full stop.
Where the data principal has voluntarily provided their data for a specific purpose and has not indicated objection to its use for that purpose. A customer who hands over a phone number to receive a delivery update has voluntarily provided it for that purpose.
The trap: this covers the purpose for which data was volunteered — nothing more. A number given for delivery does not become a marketing list. The moment you extend the purpose, you leave the legitimate use and need consent.
Processing by the State or its instrumentalities to provide or issue a subsidy, benefit, service, certificate, licence or permit — where the individual has previously consented for any State service, or the data is already held by the State. Also covered: processing for the performance of State functions authorised by law, and in the interests of sovereignty, integrity and security of India.
This is the broadest carve-out in the Act and the reason government departments have different compliance dynamics — though the security-safeguard and breach obligations still apply to them.
Processing necessary to comply with any law in force in India, or for compliance with a judgment, decree or order — Indian, or foreign where it concerns contractual or civil claims. This covers tax records, statutory registers, KYC obligations, court-ordered disclosures and regulatory filings.
Processing necessary to respond to a medical emergency involving a threat to life or immediate health threat; for providing medical treatment or health services during an epidemic or outbreak; or for safety and assistance during a disaster or breakdown of public order.
Processing for purposes of employment, or to safeguard the employer from loss or liability — including prevention of corporate espionage, maintaining confidentiality of trade secrets and intellectual property, or providing a service or benefit sought by an employee.
This is the workhorse for HR. Payroll, attendance, performance management, IT-asset monitoring for security purposes, and background verification generally sit here — meaning employers do not need employee consent for core HR processing (a good thing, since employer-employee consent could rarely be considered "free"). But the boundaries hold: wellness-app data sharing, or using HR data for marketing, falls outside employment purposes.
Processing for a scheme of merger, demerger, amalgamation or reconstruction approved by a competent authority, and for ascertaining the financial position of a person who has defaulted on payment of a loan or advance.
This is the most misunderstood point. Processing under a legitimate use exempts you from obtaining consent — and from serving a consent notice. It does not exempt you from:
For every processing activity in your data inventory, record the basis explicitly: consent, or the specific legitimate use with a one-line justification. This mapping is the backbone of your Record of Processing Activities and the first thing an auditor or the Board will ask for.
Two audit findings recur in practice: organisations claiming legitimate use for marketing (almost never valid — marketing needs consent), and organisations collecting fresh consent for employment processing they were already entitled to perform. Both are fixed by an accurate basis mapping across a complete data inventory.
Privonta Shield helps Companies, Government, SMEs and Education Institutes meet every DPDP obligation — data discovery, consent management, rights workflows and audit trails, deployed inside your own boundary. Book a free DPDP assessment →
Get a personalised compliance assessment — free, no obligation.
Book a Free Assessment →