The DPDPA gives you exactly two lawful bases for processing personal data: consent under Section 6, and legitimate uses under Section 7. There is no third option. Every processing activity in your data map must be classified under one of these two categories, and the classification determines whether you need to collect, manage, and honour consent for that activity.
The most common mistake is assuming that Section 7 legitimate uses work like GDPR legitimate interest. They do not. Section 7 is a closed list of specific categories, not a general-purpose balancing test. If your processing activity does not fit within one of the enumerated categories, you need consent.
Per-Activity Decision Grid
| Processing Activity | Lawful Basis | Section | Notes |
|---|---|---|---|
| Employee payroll processing | Legitimate Use | Section 7(e) — Employment | Processing necessary for employment purposes including payroll, benefits, and statutory compliance |
| Customer marketing emails | Consent | Section 6 | Marketing is not an enumerated legitimate use. Requires specific consent with opt-out mechanism. |
| Fraud detection analytics | Consent | Section 6 | No general legitimate interest equivalent. May argue Section 7(a) if data was voluntarily provided, but safer to obtain consent. |
| Compliance with tax filings | Legitimate Use | Section 7(c) — Legal obligation | Processing required for compliance with any law, judgment, or order of court/tribunal |
| Medical emergency treatment | Legitimate Use | Section 7(d) — Medical emergency | Processing to respond to medical emergency involving threat to life or health |
| Customer support tickets | Consent (or Voluntary) | Section 6 or 7(a) | If customer voluntarily provides data for support, Section 7(a) may apply. Best practice: obtain consent. |
| Credit scoring | Consent | Section 6 | Not an enumerated legitimate use. Requires specific consent for the credit assessment purpose. |
| Merger due diligence | Legitimate Use | Section 7(g) — Corporate transaction | Processing for merger, demerger, amalgamation, rehabilitation, or similar corporate transaction |
| Website analytics | Consent | Section 6 | Behavioural analytics and tracking are not legitimate uses. Consent required. |
| Public records research | Legitimate Use | Section 7(g) — Publicly available | Processing of data made publicly available by the Data Principal or under any law |
Related Reading
Frequently Asked Questions
What is consent under Section 6 of the DPDPA?
Section 6 requires consent that is free, specific, informed, unconditional, unambiguous, and given through a clear affirmative action. Consent must be preceded by a notice in clear and plain language describing the purpose and categories of data. Consent is purpose-limited and item-specific — bundled consent for multiple purposes is not valid.
What are the legitimate uses under Section 7?
Section 7 lists an exhaustive set of legitimate uses: (a) processing for which the Data Principal has voluntarily provided data and has not indicated she does not consent, (b) State functions, (c) compliance with court or tribunal orders, (d) medical emergencies, (e) employment purposes, (f) safety or assistance during disasters, (g) reasonable purposes including corporate transactions and publicly available data.
Can legitimate use be used for marketing?
Generally, no. Marketing does not fall within the enumerated legitimate uses under Section 7. Direct marketing, advertising, and promotional activities typically require consent under Section 6. The exception is limited — if the Data Principal has voluntarily provided contact details and has not refused consent, some limited communication may be permissible, but this is a narrow interpretation.
How does legitimate use differ from GDPR legitimate interest?
GDPR legitimate interest (Article 6(1)(f)) is a broad, general-purpose lawful basis that requires a balancing test between the controller's interests and the data subject's rights. DPDPA legitimate use is a closed, enumerated list with no general balancing test. Many activities that qualify as legitimate interest under the GDPR — analytics, fraud prevention, existing customer marketing — require consent under the DPDPA.
Lawful Basis Mapping
We map every processing activity in your data register to the correct lawful basis — consent or legitimate use — and build the consent architecture for activities that require it.
Schedule a Consultation