Chapter II — Obligations of Data Fiduciary

Section 4 — Grounds for processing personal data

4. (1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,—

(a) for which the Data Principal has given her consent; or

(b) for certain legitimate uses.

(2) For the purposes of this section, the expression “lawful purpose” means any purpose which is not expressly forbidden by law.

Source: The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Act No. 22 of 2023, Gazette of India Extraordinary, 11 August 2023; SHA-256 4deb23981d30… — verified copy

Plain-language note

Plain-language note pending

Questions people ask about this provision

  • How long can companies store personal data under the DPDP Act?
  • What are the requirements for cookie consent under the DPDP Act?
  • What are the compliance requirements under the DPDP Act?
  • When can a Data Fiduciary process personal data under the DPDP Act?
  • What is a lawful purpose for processing personal data under the DPDP Act?
  • What happens if consent is misclassified or cannot be proven under the DPDP Act?
  • Does the DPDP Act require consent for all data processing activities?
  • What are the obligations under the DPDP Act when a user withdraws consent for data processing?

Taught in Core Rules