Sections 4, 6 and 7
Purpose Under DPDP
Under DPDP, personal data may be processed only for a lawful purpose. Where consent is the basis, that consent is tied to a specified purpose. Section 7 separately lists certain legitimate uses for which processing may proceed without consent under Section 4.
What the Act says about purpose
Section 4 provides that a person may process personal data of a Data Principal only in accordance with the Act and for a lawful purpose — for which the Data Principal has given consent, or for certain legitimate uses. A lawful purpose is a purpose that is not expressly forbidden by law.
Section 6 ties consent to purpose. Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action signifying agreement to process personal data for the specified purpose. Consent that is bundled without purpose specificity, or that cannot be understood in relation to particular processing, sits poorly against that statutory design. Notice under Section 5 (and Rule 3 once commenced for operational detail) must inform the Data Principal of personal data and purpose in connection with a consent request.
Section 7 sets out certain legitimate uses — specific situations listed in the Act for which personal data may be processed without consent under Section 4. This page does not reproduce or invent that list. Organisations should read Section 7 against their facts: legitimate use is a statutory category of listed situations, not a general open-ended “business interest” test borrowed from other regimes.
What it means in practice
Start with an inventory of processing activities and state, for each, the purpose in business language that can also appear in notices. Then decide whether the applicable basis is consent under Sections 4 and 6, or a certain legitimate use under Section 7. Do not default every activity to consent, and do not stretch Section 7 beyond the situations the Act actually lists.
Where consent applies, design notices and consent captures so each affirmative action maps to specified purpose(s). Withdrawal and later processing limits should respect that purpose-linking: new purposes generally need a fresh lawful basis, not silent expansion of an old consent. Retention and erasure (Section 8; Rule 8) also connect to whether the specified purpose continues to be served.
Cross-functional teams — product, marketing, analytics, legal and engineering — should share the same purpose catalogue so systems do not collect “just in case.” Purpose clarity is both a legal and an operational control.
Common mistakes
- Treating purpose as a privacy-policy paragraph while consent UIs remain generic (“I agree”).
- Importing GDPR-style legitimate interest analysis and labelling it a DPDP “legitimate use.” Section 7 is a list of certain uses in the Act.
- Expanding processing to new purposes without revisiting consent or another applicable basis.
- Assuming every processing activity requires consent when Section 4 also contemplates Section 7.
Official source
ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.
Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.