CHAPTER II - OBLIGATIONS OF DATA FIDUCIARY

Section 4 - Grounds for processing personal data

Official text

(1)A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,—

(a)for which the Data Principal has given her consent; or

(b)for certain legitimate uses.

(2)For the purposes of this section, the expression “lawful purpose” means any purpose which is not expressly forbidden by law.

Commentary

Clause-by-clause commentary on lawful purpose, consent and certain legitimate uses under the Digital Personal Data Protection Act, 2023

Statutory provision

4. Grounds for processing personal data. (1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,(a) for which the Data Principal has given her consent; or (b) for certain legitimate uses.

(2) For the purposes of this section, the expression “lawful purpose” means any purpose which is not expressly forbidden by law.

1. “A person may process”

The opening words of Section 4 are deliberately broad.

The provision does not say that only a company, government department or Data Fiduciary must have a ground for processing. It says that a person may process personal data only on the conditions stated in Section 4.

The statutory meaning of person is wide enough to include:

  • an individual;

  • a company;

  • a partnership or firm;

  • a Hindu undivided family;

  • an association of persons;

  • a body of individuals;

  • the State;

  • a local authority;

  • another juridical person.

Accordingly, Section 4 may apply to a multinational company, a sole proprietor, a hospital, a school, a recruitment consultant, a social-media marketing agency, a hotel, a neighbourhood retailer or a technology vendor.

The word “may” expresses conditional permission. It does not mean that a person is generally free to process personal data unless the Data Principal objects. It means that processing is permitted only where the requirements of Section 4 and the rest of the Act are satisfied.

The word “process” is equally important. Section 4 is not concerned only with the moment at which personal data is collected. Processing includes a broad range of operations, including collection, recording, organisation, structuring, storage, alteration, retrieval, use, indexing, sharing, disclosure, dissemination, restriction, erasure and destruction.

This means that a lawful ground must support each relevant processing operation.

A company may have a proper ground to collect an address for delivery but lack a ground to sell that address to an advertising company. An employer may lawfully maintain attendance records but lack a ground to use those records to train a commercial artificial-intelligence product. A hospital may process medical records for treatment but may not automatically use them to create a commercial health-profiling service.

Section 4 should therefore be applied at the level of the particular operation, purpose and dataset. It should not be assigned once to an organisation or database as a permanent label.

1.1 Illustration 1: Retail delivery

A customer gives an online retailer her address so that an order can be delivered.

The retailer may use the address for delivery. If it later supplies the address to a real-estate broker, the disclosure is a separate operation for a different purpose and requires its own Section 4 analysis.

1.2 Illustration 2: Employee payroll

An employer collects an employee’s bank details and processes them to pay salary.

The processing is connected with employment and may rely on Section 7(i). If the employer supplies the bank and salary information to a financial company for loan marketing, that is a new purpose that falls outside ordinary employment processing.

1.3 Illustration 3: Customer complaint

A customer sends account details and supporting documents to a telecommunications company to resolve a billing complaint.

The company may use those details to investigate and resolve the complaint. It may not automatically use the complaint, together with the customer’s identity, to train a vendor’s general-purpose commercial AI model.

2. “The personal data of a Data Principal”

Section 4 applies to personal data about a Data Principal. It is not restricted to personal data directly supplied by that person.

It may include:

  • information collected directly from an individual;

  • information obtained from another Data Fiduciary;

  • information observed through devices or cameras;

  • transaction and behavioural information;

  • workplace records;

  • information generated by a company;

  • internal notes;

  • inferred interests;

  • predicted behaviour;

  • ratings and scores;

  • profiles produced through artificial intelligence.

Example

For example, an employee does not supply her own performance rating, but the rating is personal data about her. A borrower does not directly supply a fraud-risk score, but the score relates to the borrower. A customer does not necessarily state her purchasing preferences, but a platform may infer them from transaction history.

The entity generating the inference still needs a Section 4 ground. It cannot avoid the provision by saying that the information was created rather than collected.

2.1 Illustration 1: Credit score

A lender combines income, repayment history and transaction information to produce a risk score.

The source data and the resulting score are personal data if they relate to an identifiable borrower. The purpose and ground for generating and using the score must be identified separately.

2.2 Illustration 2: Recruitment ranking

A recruitment platform assigns applicants a suitability score based on their CVs, assessment results and interview records.

The score is personal data even though it is generated by the platform. The applicants’ consent or voluntary provision of data for a specified recruitment purpose does not automatically authorise every later use of the score.

2.3 Illustration 3: Health inference

A food-delivery platform infers that a customer may have diabetes because the customer frequently purchases sugar-free food.

The inference is personal data about the customer. The fact that the customer never directly disclosed a medical condition does not remove the inference from Section 4.

3. “Only”

The word “only” makes the structure of Section 4 restrictive and exhaustive.

A person may process personal data only:

  1. in accordance with the Act;

  2. for a lawful purpose; and

  3. on the basis of consent or one of the legitimate uses listed in Section 7.

The following are not independent grounds for processing under the DPDPA:

  • commercial convenience;

  • business interest;

  • industry practice;

  • silence of the Data Principal;

  • absence of a complaint;

  • inclusion of processing in a privacy policy;

  • inclusion of processing in standard contractual terms;

  • technical capability;

  • usefulness of the data;

  • a GDPR legitimate-interest assessment;

  • a vague claim that processing is reasonable.

A privacy notice informs the individual. It does not, by itself, supply a ground.

A contract may describe a transaction. It is not a general lawful basis equivalent to Article 6(1)(b) of the GDPR.

A company’s commercial interest may explain why the company wants to process data. It is not equivalent to a “certain legitimate use” under Section 7.

This is one of the most important structural differences between the DPDPA and the GDPR.

3.1 DPDPA and GDPR structure

IssueDPDPAGDPR
Main groundsConsent or specified legitimate usesSix separate lawful bases
Contractual necessityNo general standalone equivalentArticle 6(1)(b)
Legal obligationAddressed through particular Section 7 provisionsArticle 6(1)(c)
Vital interestsAddressed through defined emergency usesArticle 6(1)(d)
Public taskAddressed through specified State-related usesArticle 6(1)(e)
General legitimate interestsNot availableArticle 6(1)(f)
Employment processingSpecifically addressed in Section 7(i)Usually contract, legal obligation or legitimate interests
Publicly available dataMay be outside the Act under Section 3(c)(ii)Remains regulated

GDPR Article 6 provides multiple lawful bases, including contract, legal obligation, vital interests, public task and legitimate interests. The DPDPA does not reproduce that general framework.

Consequently, an organisation cannot copy the lawful basis from its European processing register into its Indian processing register.

If its GDPR record says “legitimate interests,” the organisation must identify whether the Indian processing falls within a specific Section 7 clause. If it does not, consent may be required.

4. “In accordance with the provisions of this Act”

This expression establishes that having a ground is necessary but not sufficient.

Consent does not excuse a failure to protect personal data. A legitimate use does not permit indefinite retention. A statutory disclosure obligation does not authorise disclosure of the entire database where only a limited record is required.

Processing must comply with all other applicable requirements of the DPDPA.

Depending on the circumstances, these include:

  • the notice requirements in Section 5;

  • the validity requirements for consent in Section 6;

  • the limits of the relevant Section 7 use;

  • the general obligations in Section 8;

  • the requirements concerning children in Section 9;

  • the additional obligations of a Significant Data Fiduciary under Section 10;

  • Data Principal rights;

  • transfer restrictions;

  • applicable exemptions;

  • the final DPDP Rules, 2025.

4.1 Ground and compliance are different questions

QuestionExample
Is there a ground?Section 7(i) permits payroll processing
Is the data accurate?Incorrect account details must be corrected
Is the processor properly engaged?Payroll vendor must operate under a valid contract
Is access controlled?Every employee should not see salary information
Is retention justified?Payroll records should not be kept indefinitely without a continuing purpose
Is a breach managed?Unauthorised disclosure must be handled under the Act and Rules

4.2 Case study 1: Valid consent but poor security

A health application obtains valid consent to process medical information but stores it in an unrestricted cloud folder.

The collection may have a ground, but the processing is not in accordance with the Act because appropriate security safeguards are missing.

4.3 Case study 2: Legitimate employment use but unrelated disclosure

An employer processes salary information under Section 7(i). HR sends the entire payroll database to a marketing group company.

The initial processing may be lawful, but the disclosure is not an ordinary employment purpose.

4.4 Case study 3: Legal obligation but excessive disclosure

A regulator lawfully requires a bank to disclose records concerning five identified transactions. The bank supplies the customer’s complete historical account records.

The statutory ground applies only to processing necessary to satisfy the legal obligation. It does not automatically authorise excessive disclosure.

5. “For a lawful purpose”

A purpose is the objective for which personal data is processed. It answers the question:Why is the organisation doing this?

Terms such as “AI,” “CCTV,” “cloud storage,” “analytics” and “database management” do not, by themselves, describe a purpose. They describe a technology or method.

Similarly, “HR,” “customer service,” “business use” and “security” are usually too broad for a proper Section 4 analysis.

A meaningful purpose should be expressed concretely.

Vague descriptionProperly identified purpose
HRCalculate and pay employee salary
RecruitmentAssess the applicant for Vacancy A
SecurityPrevent unauthorised access to the server room
MarketingSend monthly promotional offers for hotel services
Customer serviceInvestigate and resolve a disputed invoice
AITrain a model to classify customer-support requests
CCTVRecord the cash counter to investigate theft
AnalyticsProduce aggregate monthly sales forecasts

Purpose identification is not merely a drafting exercise. It determines:

  • which statutory ground applies;

  • what personal data may be used;

  • which recipients require access;

  • whether a new use is compatible with the original ground;

  • when the purpose ends;

  • when the data should be erased.

A company that defines its purpose as “business use” has effectively defined no meaningful purpose at all.

6. Section 4(2): “Any purpose which is not expressly forbidden by law”

Section 4(2) defines lawful purpose negatively.

It does not say that the purpose must be expressly authorised by law. It says that the purpose must not be expressly forbidden by law.

This creates three categories:

CategoryPosition under Section 4(2)
Purpose expressly prohibited by lawUnlawful purpose
Purpose expressly required or authorised by lawLawful purpose, subject to the rest of Section 4
Purpose neither expressly prohibited nor expressly authorisedPotentially lawful, subject to consent or Section 7

The definition should not be misunderstood as meaning that every purpose not prohibited by criminal law is automatically permissible.

Section 4(2) answers only the purpose question. The person must still establish consent or a Section 7 use.

7. “Purpose”

The actual objective matters more than the label chosen by the organisation.

A loan application asking for information “for verification” may really support several purposes:

  • identity verification;

  • fraud detection;

  • credit assessment;

  • advertising;

  • customer profiling;

  • sale of leads.

Each purpose should be stated honestly and assessed independently.

8. “Expressly forbidden”

A purpose may be forbidden by:

  • an Act of Parliament;

  • State legislation;

  • statutory rules;

  • binding regulations;

  • a judicial order;

  • sector-specific restrictions;

  • professional confidentiality law;

  • labour or anti-discrimination law;

  • consumer-protection law;

  • criminal law.

A voluntary industry guideline is not automatically “law.” It may still be relevant to reasonableness, security or professional standards.

If the underlying purpose is prohibited, the Data Principal’s agreement does not make it lawful.

Example

For example, consent cannot legalise:

  • processing undertaken to carry out a prohibited activity;

  • disclosure that another binding law absolutely prohibits;

  • discriminatory processing prohibited under another law;

  • surveillance in a place where recording is legally forbidden.

9.1 Case study 1: Prohibited disclosure

A regulated professional is legally prohibited from disclosing specified client information. The client is asked to click a broad consent clause permitting sale of that information.

If the prohibition cannot legally be waived, the consent does not make the purpose lawful.

9.2 Case study 2: Product marketing

A retailer sends advertisements for lawful products.

The purpose is not ordinarily forbidden. However, the retailer still requires an appropriate processing ground and must comply with other applicable marketing and telecommunications requirements.

9.3 Case study 3: Statutory employee reporting

An employer processes specified employee information because labour or tax law requires its submission to a government authority.

The purpose is lawful. The appropriate route is the applicable Section 7 legitimate use, not employee consent.

Section 4(1)(a) permits processing for a lawful purpose for which the Data Principal has given consent.

The quality and validity of that consent are governed principally by Section 6. Consent must be:

  • free;

  • specific;

  • informed;

  • unconditional;

  • unambiguous;

  • expressed through clear affirmative action;

  • limited to personal data necessary for the specified purpose.

The Data Fiduciary bears the responsibility of showing that the required notice was given and valid consent was obtained.

Consent does not transfer ownership of personal data to the Data Fiduciary. It authorises processing for the specified purpose.

Consent to one activity does not mean consent to every related or commercially useful activity.

Consent givenNot automatically covered
Delivery of an orderSale of the address to advertisers
Assessment for a vacancyIndefinite talent-pool retention
Employee photograph for ID cardPublic advertising campaign
Hospital treatmentCommercial AI-model training
Electronic invoicePromotional messaging
Customer-support requestTraining a vendor’s general AI system
Loyalty pointsHealth or income profiling

12. “Free”

The Data Principal must have a genuine choice.

Consent is not free where:

  • refusal causes an unrelated disadvantage;

  • the person is threatened or pressured;

  • an unnecessary activity is made a condition of an essential service;

  • an employee reasonably fears adverse treatment;

  • withdrawal causes punishment;

  • the person has no meaningful alternative.

13. “Specific”

Separate purposes should not be hidden inside one broad consent.

Example

For example, an online retailer should not seek one consent for:

  • processing an order;

  • marketing;

  • sharing with affiliates;

  • creating advertising audiences;

  • AI-model training;

  • selling insights.

These activities have different objectives and should be assessed separately.

14. “Informed”

The person should understand at least:

  • who is processing the data;

  • what personal data is involved;

  • why it is processed;

  • what goods or services the processing enables;

  • how consent may be withdrawn;

  • how rights may be exercised;

  • how a complaint may be made.

Rule 3 of the final DPDP Rules requires the notice to be independently understandable and to contain an itemised description of personal data and the specified purpose, together with accessible means for withdrawal, rights and complaints.

15. “Unconditional”

Consent should not be bundled with conditions unrelated to the requested service.

A food-delivery company cannot ordinarily say:

“You can order food only if you agree that your transaction history may be sold to insurance companies.”

That secondary use is not necessary to deliver food.

16. “Unambiguous” and “clear affirmative action”

The following generally do not establish valid consent:

  • silence;

  • inactivity;

  • pre-ticked boxes;

  • continued browsing without a clear choice;

  • vague acceptance of general terms;

  • failure to object to an undisclosed activity.

The Data Principal should take a clear action showing agreement.

The EDPB’s Guidelines 05/2020 identify four cumulative elements of valid consent under the GDPR:

  1. freely given;

  2. specific;

  3. informed;

  4. unambiguous.

The guidance explains that genuine consent requires real choice and control, separate choices for separate purposes, freedom from detriment and a clear affirmative act. It also states that an imbalance of power may prevent consent from being freely given, with the employment relationship being a prominent example.

This guidance is not binding Indian law. It is nevertheless highly persuasive because the DPDPA uses similar concepts and adds that consent must be unconditional.

The EDPB’s approach should be used to clarify the meaning of consent, not to import the GDPR’s entire lawful-basis structure into India.

18. Section 4(1)(b): “Certain legitimate uses”

Section 4(1)(b) permits processing for “certain legitimate uses.” Those uses are contained in Section 7.

The word “certain” is critical. It means specified or identified. It prevents Section 7 from becoming a general business-interest provision.

A company cannot say:

“Fraud prevention, AI development or marketing is a legitimate business activity, so Section 4(1)(b) applies.”

It must identify the precise Section 7 clause.

Section 7 includes specific uses involving:

  • personal data voluntarily provided for a specified purpose;

  • defined State benefits and services;

  • State functions;

  • legal duties to disclose information to the State or its instrumentalities;

  • compliance with judgments and orders;

  • medical emergencies;

  • public-health threats;

  • disasters and breakdowns of public order;

  • employment and protection of employers.

The official statutory text confirms that Section 7 is framed as an enumerated list rather than a general balancing provision.

18.1 DPDPA legitimate uses versus GDPR legitimate interests

FeatureDPDPA Section 7GDPR Article 6(1)(f)
NatureClosed listOpen-ended ground
Business interest aloneInsufficientMay qualify
Necessity testAppears within or follows from particular clausesExpressly central
Balancing testNo general statutory test equivalent to GDPRRequired
Reasonable expectationsMay help interpret ambiguous clausesImportant part of balancing
EmploymentExpress provision in Section 7(i)Often analysed under contract, legal obligation or legitimate interests
New technologiesMust fit an existing clause or use consentMay sometimes rely on legitimate interests after assessment

19. Section 7(a): Voluntarily provided personal data

Section 7(a) permits processing for the specified purpose for which the Data Principal voluntarily provided personal data, provided she has not indicated that she does not consent to its use for that purpose.

The official illustrations concern:

  • a pharmacy customer providing a phone number to receive a payment receipt; and

  • an individual providing details to a real-estate broker to locate rented accommodation.

When the individual tells the broker that assistance is no longer required, the broker must stop processing for that purpose.

Section 7(a) has four elements:

  1. the Data Principal provides the personal data;

  2. the provision is voluntary;

  3. the purpose is specified;

  4. the Data Principal has not indicated non-consent.

20. Section 7(a) is not silence-based permission

The clause does not permit hidden collection merely because the individual did not object.

A website cannot secretly collect device fingerprints and later argue that visitors failed to object. The individual must have voluntarily provided the personal data for the specified purpose.

21. The specified purpose controls the use

If a customer gives a phone number for a receipt, the business may send the receipt. It may not automatically use the number for advertising.

If a client gives documents to an advocate for a case, the advocate may use them for that representation. The documents cannot automatically be used for a public AI-training dataset.

An individual may voluntarily supply data in circumstances where the Data Fiduciary also obtains formal consent.

Example

Examples include:

  • an applicant submitting a CV after accepting a recruitment notice;

  • a patient voluntarily enrolling in an optional programme;

  • an employee asking to join an optional benefit;

  • a customer submitting feedback for publication.

The Data Fiduciary should identify the most accurate ground rather than assuming that every voluntary interaction is consent or that every consent-based interaction is Section 7(a).

23. Applicants and potential candidates

A potential candidate or job applicant is ordinarily not an employee. Section 7(i) should therefore not automatically be treated as the lawful ground for all pre-employment processing.

The applicant stage requires a separate framework.

24. Direct application for a specified vacancy

An applicant submits a CV for Vacancy A.

The applicant has voluntarily provided personal data for the specified purpose of being considered for Vacancy A. Section 7(a) can support ordinary processing closely connected with that application, such as:

  • receiving and registering the application;

  • reviewing qualifications;

  • circulating the CV to the relevant hiring team;

  • scheduling interviews;

  • recording assessments;

  • communicating the result.

The organisation may also obtain consent under Section 6, particularly where it wishes to undertake processing going beyond straightforward assessment.

Specific consent should ordinarily be obtained for:

  • background verification;

  • contacting former employers;

  • criminal or credit checks where legally permissible;

  • psychometric assessment;

  • retaining the profile for future vacancies;

  • sharing the application across unrelated group entities;

  • adding the applicant to a general talent database;

  • using application data to train a recruitment model;

  • publishing applicant information;

  • using applicant details for marketing.

The consent must be separate and understandable. An applicant should not be required to agree to unrelated advertising merely to submit a job application.

26. Potential candidate who has not applied

A recruiter identifies a person through a professional platform and creates an internal profile before contacting her.

The person has not voluntarily provided data to the recruiter for that vacancy. Section 7(a) does not automatically apply.

If the relevant fields were genuinely made public by the Data Principal, Section 3(c)(ii) may affect whether the DPDPA applies to those fields. However, internal notes, inferred salary, suitability scores, hidden contact details and data obtained from other sources require separate analysis.

27. Employee referral

An employee sends another person’s CV to HR without that person’s knowledge.

The referred person has not voluntarily supplied the CV to the prospective employer. The employer should contact the person, provide relevant information and obtain consent or voluntary participation before substantive assessment.

27.1 Applicant case study 1: Immediate vacancy

An applicant uploads a CV, cover letter and portfolio for a graphic-design vacancy.

Section 7(a) can support assessment for that vacancy. If the company wishes to retain the application for three years for other roles, it should seek separate consent.

27.2 Applicant case study 2: Recruitment AI

An employer runs submitted CVs through an automated ranking tool.

The applicant should be informed about the processing, the data involved and the purpose. If the employer later uses the applications to train the vendor’s general recruitment model, fresh, specific consent should ordinarily be obtained.

27.3 Applicant case study 3: Background check

A successful applicant is asked to approve verification of education and previous employment.

The employer should obtain specific consent identifying the verification categories, sources, vendor and purpose. A broad line in the original application form is not sufficient for unlimited investigation.

28. Interns and trainees

An intern or trainee should not automatically be treated as an employee for Section 7(i).

The actual status may depend upon:

  • the contract;

  • applicable labour law;

  • an apprenticeship statute;

  • whether salary or stipend is paid;

  • the degree of employer control;

  • integration into ordinary operations;

  • whether the arrangement is primarily educational;

  • the duties performed;

  • legal entitlements.

Where the intern or trainee is not legally or factually an employee, the organisation should ordinarily use consent and, where applicable, Section 7(a).

A non-employee intern or trainee should receive a clear notice covering:

  • identity and eligibility documents;

  • academic information;

  • attendance;

  • stipend information;

  • bank details;

  • emergency contacts;

  • access-control records;

  • assessment;

  • certificate issuance;

  • programme administration;

  • retention after completion.

The consent should not automatically cover promotional photographs, public testimonials, AI training or sharing with unrelated businesses.

30. Section 7(a)

Section 7(a) may apply where the intern voluntarily provides information for a specific request, such as:

  • bank details to receive a stipend;

  • an address to receive a certificate;

  • documents to establish academic eligibility;

  • travel information for an approved training programme;

  • emergency details for a field visit.

30.1 Intern case study 1: Summer intern

A student undertakes a six-week summer internship and submits identity, academic and bank information.

The organisation should use an intern-specific notice and consent. Section 7(a) may support processing information voluntarily provided for stipend and programme administration.

30.2 Intern case study 2: Mislabelled trainee

A person called a “trainee” works full time, receives salary, performs regular productive work and is subject to ordinary employment control.

The label is not conclusive. If applicable law treats the person as an employee, Section 7(i) may apply.

30.3 Intern case study 3: Promotional photograph

An intern provides a photograph for an access card. Marketing later proposes to use the photograph on social media.

The access-card purpose does not cover publicity. Separate consent is required.

31. Employees and Section 7(i)

Section 7(i) permits processing:

  • for the purposes of employment;

  • for purposes relating to safeguarding the employer from loss or liability;

  • for purposes such as preventing corporate espionage;

  • for maintaining the confidentiality of trade secrets, intellectual property or classified information;

  • for providing a service or benefit sought by an employee.

This is the principal ground for core employment processing.

32. Core employment processing

Section 7(i) can ordinarily cover:

  • employee onboarding;

  • payroll;

  • salary administration;

  • attendance;

  • leave;

  • performance assessment;

  • training;

  • promotion;

  • transfer;

  • disciplinary administration;

  • internal investigations;

  • workplace access;

  • business travel;

  • employee records;

  • exit administration;

  • final settlement;

  • preservation of employment records for continuing claims or duties.

An employer should not seek artificial consent for processing that is essential to manage or perform the employment relationship.

Consent is unsuitable where the employee cannot realistically refuse.

Example

For example, an employee cannot meaningfully refuse processing of bank details if bank transfer is the established salary-payment method. The proper ground is Section 7(i), not a compulsory consent box.

33. Safeguarding the employer

Section 7(i) may support processing necessary to:

  • prevent theft;

  • detect expense fraud;

  • investigate data leakage;

  • maintain system-access logs;

  • protect source code;

  • prevent corporate espionage;

  • protect confidential business information;

  • investigate unauthorised downloads;

  • preserve evidence;

  • protect restricted premises;

  • respond to legal claims;

  • prevent misuse of company assets.

The words “such as” indicate that the listed examples illustrate the broader category of protecting the employer from loss or liability.

However, the clause is not unlimited. The employer must maintain a genuine connection between the processing and the employment or protective purpose.

34. Employee-requested services and benefits

Section 7(i) can apply when an employee seeks:

  • medical insurance;

  • dependent coverage;

  • transport;

  • accommodation;

  • relocation assistance;

  • an employment certificate;

  • a salary advance;

  • an employee-assistance service;

  • another workplace benefit.

The phrase “sought by” matters. The provision does not authorise the employer to disclose employee data for unsolicited commercial offers by calling them “benefits.”

35. Processing outside Section 7(i)

Consent should ordinarily be considered for:

  • promotional use of employee photographs;

  • public employee testimonials;

  • optional wellness research;

  • unrelated marketing;

  • sharing employee data with lenders for promotions;

  • alumni advertising;

  • use of employee data to train a general commercial AI model;

  • activities unrelated to employment or employer protection.

35.1 Employee case study 1: Payroll

The employer uses attendance, bank and salary information to calculate and pay salary.

This is core employment processing under Section 7(i). Separate consent is unnecessary.

35.2 Employee case study 2: Intellectual-property security

A software company records access to source-code repositories and investigates unusually large downloads.

Section 7(i) directly supports protection of intellectual property and prevention of corporate espionage.

35.3 Employee case study 3: Advertising campaign

The employer wants to use an employee’s personal story, family photograph and health journey in external advertising.

The processing is not necessary for employment. Specific, freely given consent is required, and refusal must have no adverse employment consequence.

36. Employees and Section 7(a)

An employee may also voluntarily provide personal data for a specified purpose under Section 7(a).

Example

Examples include:

  • requesting an employment certificate;

  • filing a reimbursement request;

  • updating an address;

  • submitting a grievance;

  • requesting work-related travel;

  • applying for an employee-requested benefit;

  • asking HR to support a visa application.

Section 7(a) and Section 7(i) may overlap. The organisation should identify the ground that best describes the actual processing.

36.1 Case study 1: Employment certificate

An employee asks HR to issue an employment certificate in a bank’s format.

The employee voluntarily provides the request and relevant information for a specified purpose. Section 7(a) can support preparation and transmission of the certificate.

36.2 Case study 2: Dependent insurance

An employee supplies spouse and child details to enrol them in medical insurance.

The processing may fall under Section 7(i) because it provides a benefit sought by the employee. Section 7(a) may also describe the employee’s voluntary submission. The spouse and child remain separate Data Principals and must be considered separately.

36.3 Case study 3: Workplace complaint

An employee submits a complaint and supporting evidence to the internal grievance team.

Section 7(a) can support use for the requested investigation, while Section 7(i) may support the employer’s management of workplace conduct and liability. The information cannot be used for retaliation or unrelated publicity.

37. CCTV only to the extent relevant to Section 4

CCTV is relevant to Section 4 because recording identifiable people constitutes processing that requires a ground unless the activity falls outside the Act.

The four potentially relevant routes are:

SituationSection 4 position
Purely personal or domestic CCTVSection 3(c)(i) may exclude the processing, so Section 4 does not apply
Commercial CCTV with clear advance notice and voluntary entrySection 7(a) may be arguable
CCTV monitoring employees to protect the employerSection 7(i)
CCTV required by law for preservation and disclosure to the StateSection 7(d)

38. Section 7(a) and public-facing CCTV

A commercial establishment may argue that a visitor who sees clear surveillance signage before entry and voluntarily enters has voluntarily provided the resulting image for the specified security purpose.

This is a plausible but unsettled interpretation.

The difficulty is that Section 7(a) contemplates personal data voluntarily provided by the Data Principal. A person may voluntarily enter a shop but may not necessarily be understood as actively supplying facial and movement data to the camera.

The argument is stronger where:

  • notice appears before recording begins;

  • entry is genuinely voluntary;

  • the purpose is specific;

  • recording is limited to ordinary security;

  • cameras are visible;

  • private areas are excluded;

  • no facial recognition or behavioural profiling occurs.

It is weaker where:

  • the person has no meaningful alternative;

  • the recording begins before notice;

  • the camera is hidden;

  • audio is captured;

  • facial recognition is used;

  • footage is used for advertising;

  • the person indicates non-consent.

Signage provides transparency. It should not casually be described as Section 6 consent.

39. Section 7(i) and employees

Workplace cameras may rely on Section 7(i) where they are genuinely used to protect the employer from loss or liability, protect confidential information, prevent theft or control access to restricted locations.

Section 7(i) does not automatically authorise unlimited productivity surveillance or surveillance of highly private spaces.

40. Section 7(d) and legally mandated CCTV

Section 7(d) applies where Indian law imposes an obligation on a person to disclose information to the State or its instrumentalities, and the processing complies with the provisions governing that disclosure.

Certain State public-safety laws require covered establishments to install CCTV, maintain footage and produce recordings to authorised police or State authorities. For example, the Karnataka Public Safety (Measures) Enforcement Act, 2017 contemplates public-surveillance measures and availability of recordings to designated police authorities. The Bihar Public Safety (Measures) Enforcement Act, 2024 similarly contemplates installation, maintenance and availability of recordings for at least the prescribed period. Tamil Nadu’s 2012 Rules make CCTV installation mandatory in specified public buildings and establishments through the municipal licensing framework.

Where such a law applies, Section 7(d) can support the recording, preservation and disclosure necessary to fulfil the statutory duty.

It does not support:

  • advertising analytics;

  • facial profiling;

  • employee scoring;

  • sale of footage;

  • indefinite retention;

  • disclosure to unauthorised private parties.

Each establishment must verify the exact State law, notification, coverage threshold, locations, retention requirement and authorised disclosure mechanism. The existence of a public-safety statute does not mean that every camera in the State automatically relies on Section 7(d).

41. Marketing

Section 4 requires marketing activities to be separated from the underlying customer transaction.

42. Transactional communication

A customer gives a phone number to receive an invoice, booking confirmation or delivery update.

Section 7(a) can support use for that specified purpose.

43. Promotional communication

Using the same number to send advertisements is a separate purpose. Consent should ordinarily be obtained.

44. Advertising audiences

Uploading customer email addresses or phone numbers to a social-media platform to create matched or lookalike audiences involves:

  • disclosure to the platform;

  • matching;

  • profiling;

  • advertising use.

The original transaction ground does not automatically cover these operations.

45. Loyalty programmes

A customer who voluntarily joins a loyalty programme may provide data for points, rewards and account administration.

Section 7(a) may support the mechanics of the programme. Extensive profiling, cross-brand sharing or use for unrelated product categories may require consent.

45.1 Marketing case study 1: Electronic receipt

A restaurant customer provides a number for a digital receipt.

The restaurant may send the receipt. It should not automatically add the number to a promotional broadcast list.

45.2 Marketing case study 2: Customer analytics

A hotel analyses booking dates and room preferences to provide a customer-requested service.

Using the same information to infer income, religion or health for unrelated advertising requires a separate ground.

45.3 Marketing case study 3: Social-media audience upload

A retailer uploads its entire customer database to an advertising platform.

This is not simply an internal marketing activity. It involves disclosure and profiling by another entity. Specific consent and a clear role assessment are required.

46. Ordinary customer-facing activities

Section 7(a) is particularly relevant to ordinary interactions initiated by customers.

Customer actionProcessing within the specified purpose
Provides delivery addressDelivering the order
Gives phone number for reservationConfirming the reservation
Submits complaintInvestigating the complaint
Provides email for invoiceSending the invoice
Sends documents to obtain professional adviceProviding the requested advice
Gives refund detailsProcessing the refund
Asks broker to find accommodationLocating suitable accommodation

The ground ends at the boundary of the specified purpose.

46.1 Case study 1: Hotel reservation

A guest gives her name, dates and contact details to reserve a room.

The hotel may process the information for the reservation. Using the information for unrelated promotional partnerships requires a separate ground.

46.2 Case study 2: Pharmacy receipt

A customer gives a phone number to receive a payment receipt.

Section 7(a) directly reflects this kind of situation. The pharmacy should not use the number for unrelated health-product marketing without consent.

46.3 Case study 3: Customer support

A customer submits account records to dispute a charge.

The business may use them to resolve the dispute. Retaining the records to develop a commercial profiling product is a new purpose.

47. Social media and scraping

Section 4 applies only after Section 3 establishes that the data remains within the Act.

Personal data genuinely made publicly available by the Data Principal may fall outside the DPDPA under Section 3(c)(ii). However, this does not mean that every item visible online is excluded.

The exclusion may not apply where information becomes public through:

  • hacking;

  • a data breach;

  • an unauthorised repost;

  • doxxing;

  • an accidental configuration;

  • disclosure by someone without authority.

48. Direct social-media interaction

A customer sends a direct message to a business seeking help and provides an order number.

Section 7(a) can support use of that information to answer the request. It does not automatically permit promotional targeting.

49. Public profile

A person publicly displays a name, employer and professional experience.

Those fields may be affected by the public-data exclusion. Internal recruiter notes, inferred salary, behavioural scores and information from non-public sources are separate personal data.

50. AI scraping

A company scrapes public photographs and generates facial templates.

The fact that the photograph was public does not necessarily establish that the generated biometric representation was made public by the Data Principal. The generated template should undergo a separate Section 3 and Section 4 assessment.

50.1 Scraping case study 1: Recruitment sourcing

A recruiter reviews public professional profiles and contacts potential candidates.

The public fields may be outside the Act, but Section 7(a) becomes relevant when the candidate responds and voluntarily supplies data for the vacancy.

50.2 Scraping case study 2: Leaked telephone numbers

A marketing company acquires numbers exposed through a cyberattack and claims they are public.

The individuals did not make the numbers public. The public-data exclusion should not apply. The company needs a Section 4 ground.

50.3 Scraping case study 3: Litigation profile

A company extracts names from public judgments and creates private risk scores.

Even if the source names fall within the public-data exclusion, the generated risk scores and combined profiles should be assessed separately.

51. Vendors and processors

A Data Fiduciary may engage a Data Processor under a valid contract, but outsourcing does not create a new legal ground.

The processor’s activity must remain within the Data Fiduciary’s authorised purpose and instructions.

52. Payroll processor

An employer supplies employee information to a payroll vendor.

Section 7(i) can support the underlying payroll processing. The vendor cannot use salary data to advertise loans or train its own commercial model unless a separate ground exists.

53. Customer-support vendor

A company supplies complaint information to a call-centre vendor to resolve customer issues.

The vendor may process the data for that purpose. It cannot add the information to an independent marketing database.

54. AI vendor

A business submits personal data to an AI provider for an authorised task.

If the provider uses the inputs to improve its own general model, it is pursuing an additional purpose. The original ground may not cover that use.

55. Role changes

A vendor may be:

  • a processor for one operation;

  • a Data Fiduciary for another;

  • a joint decision-maker in a third.

The role must be assessed operation by operation.

A payroll provider that calculates salary on instructions is a processor. The same provider may become a Data Fiduciary when it independently uses employee data to design and market financial products.

56. AI, only as relevant to the Section 4 ground

Artificial intelligence does not receive an independent processing ground under the DPDPA.

“AI development,” “model improvement” and “innovation” are purposes or descriptions of activity. They are not statutory grounds.

The organisation must identify:

  • consent;

  • Section 7(a);

  • Section 7(i);

  • another exact Section 7 use.

57. Customer data used for model training

Data collected to provide a service does not automatically become available for model training.

Example

For example, customer-support messages voluntarily supplied to resolve complaints may be processed for that purpose under Section 7(a). Training a general commercial language model is a different purpose.

58. Employee data

Section 7(i) may support an AI tool genuinely used for ordinary employment administration or employer protection.

It does not automatically support:

  • general commercial model training;

  • emotion recognition;

  • unrelated behavioural profiling;

  • monitoring private conduct;

  • sale of employment predictions.

59. Applicant data

Applicants are not employees. Section 7(i) should not automatically be used for recruitment AI.

Section 7(a) may support assessment for the vacancy for which the applicant submitted data. Training a reusable model on historical applications ordinarily requires specific consent.

59.1 AI case study 1: Payroll anomaly detection

An employer uses salary records to identify duplicate payments and payroll fraud.

This is closely connected with employment administration and protection from loss. Section 7(i) may apply.

59.2 AI case study 2: General HR model

An HR software vendor uses all customers’ employee records to train a commercial model sold to unrelated organisations.

The employer’s Section 7(i) ground does not automatically authorise the vendor’s independent purpose.

59.3 AI case study 3: Customer-health prediction

A food platform predicts customers’ health conditions and sells the predictions to insurers.

The original food-delivery purpose does not cover this processing. A separate Section 4 ground is required.

60. Change of purpose

A lawful ground does not permanently attach to the personal data.

Whenever the purpose changes, the Data Fiduciary should ask:

  1. What was the original purpose?

  2. What was the original ground?

  3. Is the proposed use genuinely part of that purpose?

  4. Does the existing consent specifically cover it?

  5. Does an exact Section 7 use independently apply?

  6. Is fresh consent required?

  7. Must the notice, security controls, recipients and retention period change?

The DPDPA does not contain a general compatibility test equivalent to the GDPR’s further-processing framework. An organisation should not assume that a new purpose is allowed merely because it seems related to the original one.

60.1 Case study 1: Applicant talent pool

An applicant submits a CV for one vacancy.

Assessment for that vacancy is the original purpose. Retaining the CV for all future vacancies is an additional purpose and should be supported by separate consent.

60.2 Case study 2: Employee analytics

Attendance data is collected for payroll. The employer later proposes to use it to train a general model predicting employee personality.

The new use is not automatically protected by Section 7(i).

60.3 Case study 3: Customer complaints

A company receives complaints to resolve service problems and later sells complaint trends linked to identifiable users.

The sale is a separate purpose requiring its own ground.

Where processing relies on consent, the Data Principal may withdraw consent with ease comparable to the manner in which consent was given.

Withdrawal generally affects future consent-based processing. It does not automatically make completed processing retrospectively unlawful.

After withdrawal, the Data Fiduciary must determine:

  • what processing must stop;

  • what processors must be instructed to stop;

  • what data should be erased;

  • whether some information must be retained under another law;

  • whether a separate Section 7 use genuinely applies.

A Data Fiduciary should not opportunistically switch from consent to another ground after withdrawal merely to continue the same activity.

Under Section 7(a), processing must also stop where the Data Principal indicates that she does not consent to the use for the specified purpose. The statutory broker illustration expressly requires cessation after the individual says that assistance is no longer required.

62. Multiple grounds within one relationship

An organisation should not assign one ground to an entire relationship.

62.1 Employee relationship

ActivityGround
PayrollSection 7(i)
Employee-requested certificateSection 7(a) or Section 7(i)
Tax disclosureApplicable legal-obligation use
Workplace securitySection 7(i)
Public testimonialConsent
Optional wellness researchConsent
Court-ordered disclosureRelevant Section 7 judgment or order provision

62.2 Customer relationship

ActivityGround
Customer gives address for deliverySection 7(a)
Promotional messagesConsent
Statutory identity disclosureApplicable Section 7 use
Medical emergencyRelevant emergency use
AI training unrelated to serviceSeparate consent, unless another exact ground applies

62.3 Applicant relationship

ActivityGround
Direct application for Vacancy ASection 7(a)
Background verificationConsent
Future talent poolConsent
Historical-data model trainingFresh consent
Court-directed disclosureRelevant Section 7 provision

63. Mapping Section 4 to the final DPDP Rules, 2025

The final Rules do not create a new lawful ground and do not contain a rule interpreting “lawful purpose” or “certain legitimate uses.”

Section 4 must therefore be read principally with Sections 5, 6 and 7 of the Act.

The Rules become relevant after the ground has been identified.

Section 4 issueRelevant final Rule
Consent noticeRule 3
Means of withdrawalRule 3
Consent ManagerRule 4
Security safeguardsRule 6
Breach notificationRule 7
Purpose completion and erasureRule 8
Contact and grievance informationRule 9
Verifiable consent involving childrenRules 10 and 11
Significant Data Fiduciary measuresRule 12
Exercise of Data Principal rightsRule 13
Overseas processing requirementsRule 14
Research, archiving and statistical purposesRule 15

Rule 3 is the closest operational connection to consent under Section 4(1)(a). It requires a clear and independently understandable notice containing an itemised description of personal data and the specified purpose, together with accessible means to withdraw consent, exercise rights and make complaints.

A compliant notice does not itself create consent. It enables an informed decision.

Similarly:

  • Rule 6 security does not create a ground;

  • Rule 7 breach reporting does not cure unlawful collection;

  • Rule 8 erasure does not authorise indefinite retention;

  • a processor contract does not independently authorise the processor’s own use.

64. Final interpretation

Section 4 establishes a disciplined, purpose-by-purpose system.

Its operation can be summarised in the following propositions.

First, the purpose must be identified accurately and must not be expressly forbidden by law.

Second, the person must identify either valid consent or an exact legitimate use in Section 7. Commercial interest, contract, notice, silence and GDPR legitimate interests are not independent Indian grounds.

Third, Section 7(a) applies where the Data Principal voluntarily provides personal data for a specified purpose and has not indicated non-consent. It is particularly relevant to ordinary customer requests, direct job applications and employee-initiated requests.

Fourth, applicants and potential candidates are not ordinarily employees. Direct application processing may rely on Section 7(a), while background checks, future talent-pool retention, broader sharing and recruitment-model training should ordinarily be supported by specific consent.

Fifth, interns and trainees should not automatically be treated as employees. Unless their actual legal relationship constitutes employment, consent and Section 7(a) provide the safer framework.

Sixth, Section 7(i) is the principal ground for core employee processing. Payroll, attendance, performance management, workplace administration, protection from loss, prevention of espionage and protection of confidential information do not require repetitive employee consent where they genuinely fall within that clause.

Seventh, optional, promotional or unrelated uses of employee data remain outside the core Section 7(i) ground and ordinarily require freely given consent.

Eighth, commercial CCTV under Section 7(a) remains an arguable but unsettled interpretation because voluntary entry after clear notice is not necessarily the same thing as voluntarily providing facial and movement data. Workplace security CCTV may rely on Section 7(i), while legally mandated CCTV may rely on Section 7(d) to the extent required to record, preserve and disclose footage under the applicable law.

Ninth, AI is not a lawful basis. Model training, profiling and prediction must independently fit consent or a specific Section 7 use. The original ground for customer service, recruitment or employment does not automatically authorise a new AI purpose.

Tenth, personal data processed through a vendor remains tied to the original ground. A processor cannot create an independent marketing, profiling or model-training purpose from data received under a service arrangement.

The practical rule is simple:

Key point

Identify the real purpose, select the exact statutory ground, confine every operation to that purpose, and reassess the ground whenever the data, technology, recipient or use changes.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.