Back to Key Provisions
Lawful Bases: Legitimate Uses
Analysis of the DPDPA's legitimate uses - the lawful bases for processing personal data without consent, including employment, State functions, and public interest.
9 min read
Legitimate Uses Under Section 7
While consent is the primary basis for processing under the DPDPA, Section 7 recognises "Certain Legitimate Uses" where personal data may be processed without the Data Principal's consent. These legitimate uses provide operational flexibility while maintaining safeguards for individual rights.
The legitimate use provisions are narrower than the GDPR's six lawful bases but broader than a consent-only framework. They reflect practical necessities - employment relationships, government functions, and emergency situations - where requiring individual consent would be impractical or impossible.
Voluntary Provision for a Specified Purpose (Section 7(a))
Where a Data Principal voluntarily provides personal data to a Data Fiduciary, and it is reasonable that the Data Principal would have expected the processing, the data may be processed for the specified purpose.
This provision covers scenarios such as:
• Providing a phone number to a delivery service for logistics coordination
• Sharing an email address for transaction confirmation
• Providing contact details at a reception desk for visitor management
The key test is the reasonable expectation of the Data Principal - would they expect their data to be used in this manner given the context of their voluntary provision?
State Functions (Section 7(b))
Personal data may be processed for the State to provide subsidies, benefits, services, certificates, licenses, or permits. This covers the vast apparatus of government-to-citizen services, including:
• Aadhaar-linked benefit transfers
• Government portal registrations
• License and permit applications
• Digital public infrastructure services
This exemption recognises the practical reality that requiring individual consent for every government data processing activity would be administratively unfeasible and could impede service delivery.
Sovereignty and Security of State (Section 7(c))
Processing is permitted in the interest of the sovereignty and integrity of India, or the security of the State. This covers:
• Intelligence and national security processing
• Defence-related data handling
• Processing by agencies responsible for State security
This ground allows critical government functions to operate without the constraint of individual consent requirements, while remaining subject to constitutional safeguards.
Compliance with Law (Section 7(d))
Processing is permitted for compliance with any law in force in India. This covers:
• Regulatory reporting requirements (RBI, SEBI, IRDAI)
• Tax compliance and filings
• Anti-money laundering obligations
• Statutory record-keeping mandates
This ground ensures that Data Fiduciaries can fulfil their obligations under other laws without needing separate consent for each compliance activity.
Court Orders and Judgments (Section 7(e))
Processing is permitted for compliance with any judgment, decree, or order issued under any law by a court, tribunal, or other body. This includes:
• Court-directed disclosures
• Tribunal orders requiring data submission
• Regulatory directions from statutory bodies
The obligation to comply with judicial and quasi-judicial orders takes precedence over consent requirements.
Medical Emergencies (Section 7(f))
Processing is permitted for responding to medical emergencies involving a threat to the life or health of the Data Principal or any other individual. This covers:
• Emergency room admissions where the patient cannot provide consent
• Sharing medical information with emergency responders
• Processing necessary for immediate medical intervention
The exemption is limited to genuine emergencies and does not extend to routine healthcare processing, which requires consent.
Epidemic and Public Health (Section 7(g))
Processing is permitted for measures to be taken during an epidemic, outbreak of disease, or any other threat to public health. This covers:
• Contact tracing during health emergencies
• Disease surveillance and monitoring
• Public health reporting and response coordination
This ground was particularly relevant given India's experience during the COVID-19 pandemic, where large-scale data processing was necessary for public health response.
Disaster and Public Order (Section 7(h))
Processing is permitted for measures to ensure safety of, or provide assistance or services to, any individual during any disaster, or any breakdown of public order. This covers:
• Natural disaster relief coordination
• Emergency evacuation data processing
• Maintaining essential services during breakdowns of public order
This ground enables rapid data processing for humanitarian purposes without the delay of obtaining individual consent.
Employment-Related Processing (Section 7(i))
Personal data may be processed for purposes related to employment, including:
• Recruitment and onboarding
• Payroll and benefits administration
• Performance management
• Compliance with employment law obligations
• Health and safety requirements
This legitimate use recognises the power imbalance in employment relationships, where consent from employees may not be truly "free." By providing a separate basis, the Act avoids the fiction of voluntary employee consent for mandatory processing activities.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
