Chapter II — Obligations of Data Fiduciary
Section 4 — Grounds for processing personal data
4. (1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,—
(a) for which the Data Principal has given her consent; or
(b) for certain legitimate uses.
(2) For the purposes of this section, the expression “lawful purpose” means any purpose which is not expressly forbidden by law.
Source: The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Act No. 22 of 2023, Gazette of India Extraordinary, 11 August 2023; SHA-256 4deb23981d30… — verified copy
Plain-language note
Plain-language note pending
Questions people ask about this provision
- How long can companies store personal data under the DPDP Act?
- What are the requirements for cookie consent under the DPDP Act?
- What are the compliance requirements under the DPDP Act?
- When can a Data Fiduciary process personal data under the DPDP Act?
- What is a lawful purpose for processing personal data under the DPDP Act?
- What happens if consent is misclassified or cannot be proven under the DPDP Act?
- Does the DPDP Act require consent for all data processing activities?
- What are the obligations under the DPDP Act when a user withdraws consent for data processing?
Taught in Core Rules