/The Act · Chapter II · Obligations of Data Fiduciary
Section 7: Certain legitimate uses
DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.
- Provision
- Section 7 of The Digital Personal Data Protection Act, 2023
- Status
- Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
- Rules made under it
- Rule 5
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
A Data Fiduciary may process personal data of a Data Principal for any of following uses, namely:—
for the specified purpose for which the Data Principal has voluntarily provided her personal data to the Data Fiduciary, and in respect of which she has not indicated to the Data Fiduciary that she does not consent to the use of her personal data.
for the State and any of its instrumentalities to provide or issue to the Data Principal such subsidy, benefit, service, certificate, licence or permit as may be prescribed, where––
she has previously consented to the processing of her personal data by the State or any of its instrumentalities for any subsidy, benefit, service, certificate, licence or permit; or
such personal data is available in digital form in, or in non-digital form and digitised subsequently from, any database, register, book or other document which is maintained by the State or any of its instrumentalities and is notified by the Central Government,
subject to standards followed for processing being in accordance with the policy issued by the Central Government or any law for the time being in force for governance of personal data.
for the performance by the State or any of its instrumentalities of any function under any law for the time being in force in India or in the interest of sovereignty and integrity of India or security of the State;
for fulfilling any obligation under any law for the time being in force in India on any person to disclose any information to the State or any of its instrumentalities, subject to such processing being in accordance with the provisions regarding disclosure of such information in any other law for the time being in force;
for compliance with any judgment or decree or order issued under any law for the time being in force in India, or any judgment or order relating to claims of a contractual or civil nature under any law for the time being in force outside India;
for responding to a medical emergency involving a threat to the life or immediate threat to the health of the Data Principal or any other individual;
for taking measures to provide medical treatment or health services to any individual during an epidemic, outbreak of disease, or any other threat to public health;
for taking measures to ensure safety of, or provide assistance or services to, any individual during any disaster, or any breakdown of public order.
For the purposes of this clause, the expression “disaster” shall have the same meaning as assigned to it in clause (d) of section 2 of the Disaster Management Act, 2005; or
for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee.
Section 7 lists specific situations, called certain legitimate uses, where a Data Fiduciary (the entity determining the purpose of processing) can process a Data Principal's (the individual's) personal data without needing to get formal consent. One major use is when an individual voluntarily provides their data for a specific purpose and does not object to its use for that purpose. For example, if a person gives their phone number to a pharmacy to get a receipt, the pharmacy can use it to send that receipt.
The State and its instrumentalities have broad permissions under this section. They can process personal data to provide subsidies, benefits, services, certificates, licenses, or permits if the individual previously consented to processing for any such benefit, or if the data is in a government database notified by the Central Government. The State can also process data to perform its legal functions, protect national security, or maintain the sovereignty and integrity of India.
Other legitimate uses cover emergencies, legal obligations, and employment. Data can be processed to respond to medical emergencies, epidemics, disasters, or breakdowns of public order. It can also be processed to comply with court judgments or legal obligations to disclose information to the State. Finally, employers can process an employee's data for employment purposes, to provide benefits the employee asks for, or to protect the employer from loss or liability, such as preventing corporate espionage or protecting trade secrets.
Key points
- A Data Fiduciary may process personal data if the Data Principal voluntarily provides it for a specified purpose and does not indicate a lack of consent (a).
- The State may process data for prescribed subsidies, benefits, or services if the individual previously consented to any government benefit or if the data is in a notified government database (b).
- Processing is allowed for State functions under law, national security, or the sovereignty and integrity of India (c).
- Data may be processed to comply with Indian court orders, or foreign judgments related to civil or contractual claims (e).
- Processing is permitted for medical emergencies, epidemics, disasters, or breakdowns of public order (f, g, h).
- Employers may process employee data for employment purposes, providing requested benefits, or safeguarding against corporate espionage and loss (i).
Common misreadings
- One might assume that voluntarily providing data allows the Data Fiduciary to use it for anything, but the text restricts it to the specified purpose for which it was provided.
- One might think the State needs fresh consent for every new subsidy, but the text allows processing if the individual previously consented to any subsidy or benefit.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.