
DPDPA Section 4: Grounds for Processing Personal Data and the Meaning of Lawful Purpose
Master DPDPA Section 4 to ensure your data processing is legal. Discover the exact rules for lawful purpose, consent, and compliance under India’s privacy law.
Written by
Sahil Pugalia
Date
Read time
5 min

You can have military-grade encryption, an airtight perimeter, and the most beautifully designed privacy notice in the industry. But if you fail DPDPA Section 4, none of it matters. You are just securely hoarding illegal data.
Section 4 of the Digital Personal Data Protection Act sets the gateway rule for any personal data processing in India. You can process personal data only if two conditions are met: the purpose is lawful, and the activity fits one of exactly two legal grounds.
If your processing does not fit one of these grounds, and your purpose is not lawful, you are out of bounds. There is no loophole.
What Section 4 Says
Let’s strip away the legalese. The rule is a positive obligation framework. Processing is prohibited by default unless it satisfies the lawful purpose test and sits on one of two grounds:
- Consent from the Data Principal.
- Certain legitimate uses.

That is the entire list. There is no third option. There is no “implied consent,” no “industry practice” carve-out, and no “general business necessity” exception.
Lawful Purpose: What It Is and What It Is Not
Section 4 defines a DPDPA lawful purpose negatively. If a purpose is not expressly forbidden by law, it is lawful. This creates a presumption of lawfulness,until a statute or judgment says otherwise.
But remember this distinction: a lawful purpose is necessary, but it is not sufficient. You still need a lawful ground.
Purposes expressly forbidden by law include:
- Criminal activity, fraud, identity theft, money laundering, and terrorism.
- Prohibited discrimination based on protected characteristics.
- Violations of statutory prohibitions (under laws like the IT Act or sector regulations).
- Child protection violations.
- Constitutional violations where no lawful justification applies.
The contrast in practice:
- Lawful purposes: Sending marketing emails with valid consent, credit scoring for lending, product personalization, or research with anonymized data and safeguards.
- Unlawful purposes: Phishing, illegal surveillance, discriminatory profiling, or creating non-consensual deepfakes.
Ground 1: Consent
Consent is the primary ground for most private-sector data use. But under the Act, meeting DPDP consent requirements means clearing a high bar. Valid consent must be:
- Free: No coercion. You cannot tie non-essential processing to service access.
- Informed: Provided only after clear notice of the data and the purpose.
- Specific: Purpose-bound. Blanket consent is a myth.
- Unambiguous: A clear affirmative action. Silence is not consent.
- Withdrawable: Exactly as easy to withdraw as it was to give.
When to use consent:
Marketing and promotions, optional personalization, sharing with third parties for non-essential purposes, behavioral tracking, and secondary uses beyond core service delivery.
When to stop asking for it:
Do not rely on consent where a genuine choice does not exist. If processing is mandatory by law, necessary for core service delivery, employment essentials, medical emergencies, or fraud prevention, consent is the wrong tool. For those, you look to legitimate uses.
Rely on invalid consent, and the processing becomes unlawful. You stop processing, face penalties, and manage the reputational fallout.
Ground 2: Certain Legitimate Uses
Do not confuse this with the GDPR’s broad “legitimate interests” test. Legitimate uses under the DPDPA are a closed list defined in Section 7. It is a specific set of situations where consent is not required because necessity and public or institutional interest justify the processing.
The categories include:
- State functions for services, benefits, licenses, permits, or certificates.
- Compliance with law and legal claims.
- Compliance with court or tribunal orders.
- Medical emergencies and health services during emergencies.
- Disaster response and public order breakdown.
- Employment essentials (recruitment, payroll, attendance, performance, and termination).
- Safety and security (preventing unlawful activity and network security).
- Business transfers (mergers, acquisitions, and reorganizations).
- Processing of personal data made publicly available by the Data Principal or under law.
- Other prescribed uses that may be notified by the government.
The guardrails:
You cannot just claim a legitimate use and walk away. The processing must be genuinely necessary for that specific use, not merely convenient. You must practice proportionality (collect only what is needed) and purpose limitation (do not repurpose the data without a fresh ground). You still need transparency, security, and documentation to prove your rationale remains valid.
Choosing the Right Ground: A Simple Decision Path

- Is the purpose expressly forbidden by law?
If yes, stop. It is unlawful.
- Does the activity fit a Section 7 legitimate use?
If yes, and it is necessary, use legitimate use. If it is not necessary, move to consent.
- Can you obtain valid consent?
If yes, use consent and meet the Section 6 attributes. If no, the processing is not permissible.
Avoid ground switching. If you choose consent and the user withdraws it, you cannot retroactively claim legitimate use for the exact same activity. That is not compliance. That is a cover-up.
Common Pitfalls to Avoid
- Implied or deemed consent: Using a service is not consent for non-essential processing.
- Overreach on legitimate use: Do not stretch “safety and security” to cover marketing analytics.
- Bundled or coerced consent: Do not hold service access hostage for optional processing.
- Purpose creep: Do not reuse data collected for one purpose for another without a fresh ground or anonymization.
- Backup ground thinking: Do not cite both consent and legitimate use for the same activity. Pick one.
Practical Examples
Hospital emergency processing:
Processing data to identify a patient, access medical records, verify insurance, and administer treatment during an emergency fits legitimate use for medical emergencies. No consent is required in the moment. But for non-essential follow-on uses,like research or marketing,you must obtain consent once the emergency passes.
Retail CCTV boundary:
Continuous in-store CCTV to prevent theft and ensure safety relies on legitimate use for safety and security. You use signage and time-bound retention. But if you want to use that same footage to build customer demographics for marketing? That requires consent, or anonymization that truly removes identification.
Implementation Checklist
- Data mapping: Inventory all processing activities, data elements, sources, and recipients.
- Purpose classification: Define the specific purpose for each activity and confirm it is not forbidden by law.
- Ground determination: Select consent or legitimate use per activity and document the rationale.
- Mechanism design: Build consent flows with clear notices and withdrawal, or record legitimate use necessity and controls.
- Documentation: Maintain records of processing, legal grounds, consent logs, and assessments.
- Ongoing review: Revisit grounds, purposes, and safeguards as operations change.
The Bottom Line
Section 4 is the entry gate. Every processing activity needs a lawful purpose and one lawful ground. Legitimate uses are closed and necessity-bound. Consent must be real, specific, and easy to withdraw. Get this assessment wrong, and the rest of your compliance program is just theatre.
Most teams do not struggle with the theory. They struggle with the execution details: mapping every purpose, separating essential from optional processing, keeping evidence of necessity, and designing clear consent journeys.
At Regodit, we did not build a tool just to store policies. We built a platform to help teams operationalize these exact requirements with structure, traceability, and discipline. We help you map processing, assign the right legal grounds, and keep the evidence ready for audits. If you want a straight path to Section 4 compliance at scale, schedule a brief discussion with our team.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
