Glossary · Legitimate Use

What Is Legitimate Use Under DPDPA?

Consent is not the only lawful basis under DPDPA, but the alternative is not a GDPR-style balancing test. Section 7 is a closed list of nine legitimate uses. If your processing does not sit in one of them, you need Section 6 consent. Map the basis before 13 May 2027.

Last reviewed: 13 August 2026

Definition

A legitimate use is one of nine specific situations in Section 7 of the DPDP Act, 2023 where you may process someone's personal data without asking for consent and without serving a Section 5 notice. The list is closed — you cannot invent your own justification the way "legitimate interests" works under GDPR. It covers data a person voluntarily gave you for an evident purpose, employment purposes, medical emergencies, epidemics, disasters, court orders, and several State functions. Your other duties — security safeguards, accuracy, breach reporting, grievance redressal — apply exactly as they would for consent-based processing, and each use must stay inside the situation that justified it.

How this matters in practice

Most SMBs over-collect consent — asking staff to tick a box for payroll data that Section 7(i) already permits, which weakens the consent record everywhere else. Privigo maps each collection point to its lawful basis, flags consent theatre, and keeps legitimate-use processing out of the consent ledger while still logging purpose, retention and access for audit.

Frequently asked questions

Is legitimate use the same as GDPR's legitimate interests?

No, and this is the most common mistake Indian SMBs make when adapting a GDPR-era policy. GDPR lets you run a balancing test and argue your own commercial interest outweighs the individual's rights. DPDPA does not. Section 7 is a closed list of nine defined situations — if your processing doesn't fall squarely into one of them, you need consent under Section 6. There is no "we assessed it and decided it was reasonable" route.

Can I rely on legitimate use for my employees' data?

Largely yes. Section 7(i) covers processing for employment purposes, for safeguarding the employer from loss or liability (think prevention of corporate espionage, protecting trade secrets and IP), and for providing a service or benefit the employee has asked for. So payroll, attendance, PF and appraisals don't need a consent tick-box. But it doesn't stretch to unrelated uses — pushing employee data to a marketing tool, or sharing it with a partner for cross-selling, sits outside the clause and falls back to consent.

If I don't need consent, do I have no obligations at all?

You still have most of them. Reasonable security safeguards under Section 8(5) apply regardless of lawful basis, and failure there carries a penalty of up to ₹250 crore. Breach notification under Section 8(6) applies too, with its own slab of up to ₹200 crore. Four lanes run in parallel: CERT-In within 6 hours of noticing; Rule 7(1) intimation to affected Data Principals without delay; Rule 7(2)(a) initial Board intimation without delay; and Rule 7(2)(b) the detailed report to the Board within 72 hours. Accuracy, retention limits and a published Section 8(9) contact and Section 8(10) grievance channel also continue to apply. Build backwards from 13 May 2027.

Official sources

Map each collection point to its lawful basis

Book a 30-minute call. We walk one employee flow and one customer flow, mark which sit on Section 7 and which need Section 6 consent, and flag the consent theatre that weakens the rest of your record.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.