DPDP Wiki Talk to us

/Glossary · Defined term

specified purpose

Defined in section 2(za) of the Act.

Official definition

Official definition

Verbatim

Act, section 2(za)

(za) “specified purpose” means the purpose mentioned in the notice given by the Data Fiduciary to the Data Principal in accordance with the provisions of this Act and the rules made thereunder; and

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData Principal

The Digital Personal Data Protection Act defines "specified purpose" as the exact reason a Data Fiduciary (the entity deciding how and why data is processed) collects and uses a Data Principal's (the individual to whom the data relates) personal data. This reason must be clearly stated in the notice that the Data Fiduciary gives to the Data Principal.\n\nThe definition ties the purpose directly to the formal notice required by the Act and its accompanying rules. This means a purpose is only considered a "specified purpose" if it is actually written down and presented to the individual in that notice, following the procedures set out in the law.\n\nBy defining it this way, the Act ensures that the reasons for processing personal data are transparent and formally communicated. A Data Fiduciary cannot rely on vague or unstated reasons; the purpose must be explicitly mentioned in the notice provided to the Data Principal.

Key points

  • The term refers to the specific reason for processing personal data that is mentioned in the formal notice. (2(za))
  • The notice containing this purpose must be given by the Data Fiduciary to the Data Principal. (2(za))
  • The notice and the purpose mentioned within it must comply with the provisions of the Act and any rules made under it. (2(za))

Common misreadings

  • A Data Fiduciary might assume any internal business reason counts as a specified purpose, but it only counts if it is actually mentioned in the notice given to the Data Principal.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.