DPDP Wiki Talk to us

/The Act · Chapter II · Obligations of Data Fiduciary

Section 4: Grounds for processing personal data

DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) G.S.R. 843(E)Chapter II: Obligations of Data Fiduciary
Provision
Section 4 of The Digital Personal Data Protection Act, 2023
Status
Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
Rules made under it
None identified
Source
Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF

Section 4. Grounds for processing personal data

Verbatim from the Gazette of India
(1)

A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,—

(a)

for which the Data Principal has given her consent; or

(2)

For the purposes of this section, the expression “lawful purpose” means any purpose which is not expressly forbidden by law.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data PrincipalData Fiduciary

Section 4 establishes the fundamental rules for when any person or organization can process personal data under the Act. It states that the personal data of a Data Principal, which is the individual to whom the data relates, can only be processed if the processing complies with the provisions of the Act. Furthermore, the processing must always be for a lawful purpose. The section limits the processing of personal data to two specific grounds. First, data can be processed if the Data Principal has explicitly given their consent for that processing. Second, data can be processed for certain legitimate uses. These legitimate uses are specific scenarios recognized by the Act where obtaining consent is not necessary. Finally, the section provides a clear definition of what constitutes a lawful purpose. It states that a lawful purpose is any purpose that is not expressly forbidden by law. This means that as long as the reason for collecting and using the personal data is not illegal or prohibited by other legislation, it meets this requirement.

Key points

  • Personal data can only be processed in accordance with the Act and for a lawful purpose [(1)].
  • Processing is permitted if the Data Principal has given their consent [(1)(a)].
  • Processing is also permitted for certain legitimate uses [(1)(b)].
  • A lawful purpose is defined as any purpose that is not expressly forbidden by law [(2)].

Common misreadings

  • One might think a lawful purpose requires a specific law authorizing the processing, but the Act clarifies it simply means the purpose must not be expressly forbidden by law.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.