DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

‹ General awareness

General awareness

Consent is not the default under the DPDP Act

Does DPDP require consent for every processing activity?
No. Consent is the main road, and Section 7 provides a small number of clearly marked exits, the legitimate uses that need no consent. There is no GDPR style balancing test, and no lane marked because it makes commercial sense.
Who this affects
Anyone deciding the lawful basis for a processing activity.
What to do about it
Match each activity to a specific Section 7 entry or obtain consent. The list is closed, so if it does not fit, consent is required.

A common assumption is that the DPDP Act requires consent for every act of processing. It does not.

Think of the Act as a road network. Consent is the main road. Section 7 provides a small number of clearly marked exits, the "certain legitimate uses" where a Data Fiduciary may process personal data without consent. What the Act does not provide is a lane marked "because it makes commercial sense."

The legitimate uses that matter to most organisations

So far this reads like relief. Here is where care is needed.

Section 7 is not a GDPR style legitimate interests clause. There is no general balancing test where a Data Fiduciary weighs its commercial interest against the interests of the individual and decides the matter for itself. The list is closed. If a processing activity does not fall within one of the enumerated legitimate uses, a Data Fiduciary cannot rely on Section 7.

Two practical consequences follow.

Before asking for consent, ask a different question.

Do I actually need consent for this processing activity, or am I relying on one of the specific legitimate uses recognised by Section 7?

Starting with that question often avoids both unnecessary consent notices and misplaced reliance on Section 7.

Where do you see the line being drawn in practice? Are organisations more likely to over rely on consent out of caution, or to over rely on "legitimate uses" by treating Section 7 as if it were a GDPR style balancing test?

#DPDP #DPDPAct2023 #DPDPRules2025 #DataProtection #PrivacyLaw #IndiaLegal #Compliance

Get DPDP ready in hours, not weeks

Take the readiness assessment and generate your compliance documents from your answers.

Assess My Readiness