What is the legitimate use basis under DPDP — when consent is not needed

What is the legitimate use basis under DPDP — when consent is not needed
Lawful Basis

What is the legitimate use basis under DPDP — when consent is not needed

Consent is not the only lawful basis for processing personal data under DPDP. Here are the situations where consent is not required.

Quick Answer: The DPDP Act provides for 'legitimate uses' as an alternative lawful basis for processing personal data where consent is not required. Unlike GDPR's broad legitimate interests test, DPDP's legitimate uses are specific enumerated situations: processing by the State for welfare, benefits, subsidies, certificates, licences, and similar government functions; processing necessary to comply with a legal obligation or court order; processing to protect the vital interests of the data principal or another person in an emergency; employment-related processing covered by the contract of employment; and processing for certain public interest functions. These are narrow bases — companies cannot use 'legitimate use' as a catch-all to avoid consent for commercial data processing.

What processing by the State qualifies as legitimate use?

The government and its instrumentalities can process personal data without consent for: delivery of subsidies, benefits, and welfare services (Aadhaar-linked DBT transfers); issuance of certificates, licences, and permits; law enforcement and national security functions; and other government functions the government may prescribe. This recognises that requiring consent for welfare delivery would be administratively impractical and could exclude eligible beneficiaries. However, even under the State exemption, processing must be for the specified government purpose — it cannot be used to justify aggregating data across ministries for commercial or surveillance purposes.

Does compliance with a legal obligation qualify as legitimate use?

Yes. Processing personal data to comply with an obligation under Indian law — paying TDS, filing GST returns, maintaining EPF records, complying with SEBI reporting, responding to a court order — does not require consent from the individuals whose data is included. The legal obligation itself provides the lawful basis. This is important for businesses: your tax compliance data, regulatory filings, and legally mandated record-keeping are covered by this basis. You do not need to collect consent from employees to process their data for TDS or EPF compliance.

What processing in emergencies qualifies as legitimate use?

Processing necessary to protect the vital interests of the data principal or another person in a medical emergency qualifies as legitimate use. Example: sharing a patient's medical history with the emergency department when they arrive unconscious; sharing an employee's blood type with an ambulance when they collapse at work. This basis is strictly limited to genuine medical emergencies where the data principal cannot consent — it cannot be used to justify routine health data processing or wellness programme data collection.

What employment-related processing qualifies as legitimate use?

Processing personal data of employees and contractors necessary for employment functions qualifies as legitimate use without consent. This covers: payroll, attendance, performance management, leave management, benefit administration, and other data processing inherent in the employment relationship. However, 'necessary for employment purposes' is not a blanket exemption — using employee data for marketing campaigns, sharing it with third parties for non-HR purposes, or processing biometric data that could be done with a less intrusive method would require consent.

Can companies use legitimate use as a substitute for consent for marketing?

No. The legitimate use provisions are specific and do not include a general commercial interest exemption equivalent to GDPR's legitimate interests. Companies cannot use legitimate use as a basis for: marketing communications; third-party data sharing for advertising; profiling for personalised recommendations; or analytics beyond what is necessary for operational purposes. For commercial data processing beyond the statutory or employment bases, consent remains the required lawful basis. This is a significant difference from GDPR — Indian companies with GDPR-compliant legitimate interests programmes will need to revisit their lawful basis assessments.

What might the government add as additional legitimate uses?

The Act allows the government to prescribe additional legitimate uses by notification. Based on the consultation process, potential additions include: processing for research, archiving, and statistical purposes with appropriate anonymisation safeguards; processing by media entities for journalistic purposes; and processing in the public interest by civil society organisations. Monitor MeitY notifications closely — each new legitimate use basis changes the consent landscape for affected organisations.

Frequently asked questions

Is processing for fraud prevention a legitimate use under DPDP?

Fraud prevention is not listed among the specific legitimate uses in the Act. Unless the government adds it by notification, fraud prevention processing requires either consent from the data principal or falls under the contractual basis (fraud prevention is necessary to perform the contract with the customer in some financial services contexts). Building fraud detection systems on the contractual basis requires that the processing is genuinely necessary for the contract, not just useful. For broader fraud analytics across customer populations, consent is likely needed.

Does credit scoring for lending qualify as legitimate use?

Credit scoring for lending is not among the enumerated legitimate uses. For a bank or NBFC, processing existing customer transaction data for credit assessment may be justifiable under the contractual basis (assessing creditworthiness is part of the lending contract). But building credit profiles for marketing pre-approved offers, or using transaction data from one product to cross-sell another, is beyond the contractual necessity and requires consent. The line between operational credit assessment and commercial profiling is where consent becomes necessary.

Can schools process student data without parental consent?

Schools processing student data for the core educational function — academic records, attendance, communication with parents, statutory reporting to the education board — can rely on the employment/contractual basis and statutory obligations. However, schools using student data for third-party educational apps, sharing with vendors, or processing health or behavioural data beyond what is educationally necessary need parental consent. Students who are minors always require parental consent for data processing that goes beyond the essential educational relationship.

Map your lawful basis for every processing activity

Niti Bharat's DPDP Readiness Assessment includes a lawful basis mapping exercise — categorising every processing activity as consent, legitimate use, or statutory obligation, with gap identification.

Start Lawful Basis Review
Previous Post Next Post

Get Free DPDP Checklist