DPDP Act 2023 Series · #13 · Module 3 · Lawful Processing · DPDP #13

Section 4 – Grounds for Processing Personal Data

Digital Personal Data Protection Act, 2023 | A Practical Executive Guide

Grounds for processing personal data illustration
Why This Section Matters

Every Processing Activity Needs a Lawful Basis

Before an organisation collects, uses, stores, shares, or processes personal data, it must have a legally valid ground under the DPDP Act, 2023. Organisations cannot process personal data simply because it is convenient, useful, or available. Section 4 is the legal gateway — it establishes the foundational rule that governs every data processing activity carried out by a Data Fiduciary.

🚫 Without Lawful Basis

Processing may be non-compliant, exposing the organisation to legal risk and regulatory action.

✅ With Lawful Basis

Processing is permitted, transparent, and defensible under the Act.

The Two Lawful Grounds Under Section 4

Section 4 of the DPDP Act recognises exactly two lawful grounds for processing personal data. If an organisation cannot rely on either, it should generally refrain from processing that data.

Ground 1 — Consent

The Data Principal gives free, specific, informed, and unambiguous consent for a specific purpose. Governed by Section 6.

Ground 2 — Certain Legitimate Uses

Processing is permitted without explicit consent in specific situations defined by law. Governed by Section 7.

Two lawful grounds illustration
The Foundation

Section 4 as the Legal Gateway

Section 4 is not just a standalone provision — it is the entry point to the entire compliance framework of the DPDP Act. Every obligation that follows — Notice, Consent, Legitimate Use, Data Fiduciary obligations — flows from this fundamental question: "Do we have a lawful ground to process this personal data?"

Identify Activity → Lawful Ground → Fulfil Obligations → Remain Compliant

This flow represents the logical sequence every organisation must follow before initiating any data processing activity under the Act.

The First Question Every Organisation Must Ask

Before You Ask...

  • What data should we collect?
  • How should we secure it?
  • What rights do individuals have?
  • How long should we retain it?

You Must First Answer:

“Do we have a lawful ground to process this personal data?”

This single question is the starting point of data protection compliance under the DPDP Act. Getting it right protects the organisation, builds trust, and prevents costly remediation later.

Consent vs. Certain Legitimate Uses — At a Glance

While both are valid lawful grounds, they operate very differently. Understanding which ground applies to which activity is essential for compliance.

DimensionConsent (Section 6)Legitimate Use (Section 7)
Who decides?The Data Principal (individual)The law defines the situations
Can it be withdrawn?Yes, at any timeNot applicable
Typical useMarketing, optional servicesStatutory obligations, safety
Notice required?Yes (Section 5)May still apply
Practical Examples

Real-World Processing Activities Across Sectors

🏥 Hospital

🏥 Hospital

Patient registration and treatment → Consent. Insurance processing and lab testing may fall under Legitimate Use depending on statutory obligations.

🏦 Bank

🏦 Bank

KYC and loan processing → likely Legitimate Use (regulatory mandate). Internet banking sign-up → Consent.

🏢 Employer

🏢 Employer

Payroll, statutory compliance, attendance → Legitimate Use. Optional employee surveys or photo for internal branding → Consent.

🛒 E-Commerce

🛒 E-Commerce

Customer registration and delivery → Consent. Promotional emails → Consent (separate, specific). Customer support → contextual.

Sector Deep Dive — Healthcare & Banking

🏥 Hospital Processing Activities

ActivityLikely Ground
Patient registrationConsent
Medical treatmentConsent / Legitimate Use
Lab testingConsent
Insurance processingLegitimate Use

🏦 Bank Processing Activities

ActivityLikely Ground
Opening a bank accountConsent
KYC verificationLegitimate Use
Loan processingLegitimate Use
Internet bankingConsent

Sector Deep Dive — HR & E-Commerce

🏢 Employer Processing Activities

ActivityLikely Ground
RecruitmentConsent
Payroll processingLegitimate Use
Attendance trackingLegitimate Use
Statutory complianceLegitimate Use
Employee ID cardsConsent / Legitimate Use

🛒 E-Commerce Processing Activities

ActivityLikely Ground
Customer registrationConsent
Product deliveryConsent
Promotional communicationsConsent (specific)
Customer supportConsent / Legitimate Use
Decision Framework

Can We Process This Personal Data?

Use this practical decision tree before initiating any data processing activity. Every organisation — large or small — should embed this logic into its operations and governance processes.

Personal Data?

Is personal data being processed?

DPDP Apply?

Does the DPDP Act cover this?

Purpose?

What is the processing purpose?

Valid Consent?

Is valid consent obtained?

If neither Consent nor Legitimate Use applies at Step 5, the organisation should reconsider whether the processing should proceed at all before taking any further action.

How Section 4 Connects to the Rest of the Act

Section 4 is the foundation upon which every other obligation under the DPDP Act is built. Understanding this flow helps organisations sequence their compliance activities correctly and avoid gaps in their data protection programmes.

How Section 4 connects to other DPDP Act obligations

Each stage in this flow is interdependent. A gap at Stage 1 — failing to establish a lawful ground — invalidates all subsequent steps and renders the entire processing activity potentially non-compliant.

Common Business Mistakes to Avoid

Many organisations inadvertently fall into these traps when managing personal data. Awareness is the first step to correction.

❌ No Lawful Basis Identified

Collecting personal data without first identifying a lawful ground — the most common and serious compliance gap.

❌ Consent for Everything

Assuming consent is always required, even when a legitimate use already covers the activity — creating unnecessary consent fatigue.

❌ Never Seeking Consent

Assuming consent is never required and relying solely on legitimate use, even for clearly discretionary processing activities.

❌ One Basis for Multiple Purposes

Using a single lawful basis to justify several unrelated processing activities — each purpose must be evaluated individually.

❌ Speculative Data Collection

Processing personal data "just in case it may be useful later" — purpose limitation is a core principle of the Act.

Business Governance

Why Documenting the Lawful Basis Is Good Business

Maintain a Record of Processing Activities (ROPA)

Every organisation should maintain an internal record — a ROPA or equivalent — that documents, for each processing activity:

  • The purpose of processing
  • The lawful ground relied upon
  • The categories of personal data involved
  • The retention period and review schedule

Business Benefits of Documentation

Better Compliance

Structured records demonstrate accountability to regulators and auditors.

Stronger Customer Trust

Transparency about data use builds long-term loyalty and brand equity.

Reduced Legal Risk

Clear documentation reduces exposure to penalties and disputes.

Real-Life Scenarios — Identify the Lawful Ground

Test your understanding. For each scenario below, consider which lawful ground should apply before reviewing the explanation.

1. Educational Institution

Scenario: A university collects student biometric data for attendance. Analysis: May fall under Legitimate Use if mandated by institutional regulation, or Consent if optional.

2. Government Service

Scenario: A government department processes Aadhaar-linked data for a welfare scheme. Analysis: Likely Legitimate Use under a statutory function of the State.

3. E-Commerce Platform

Scenario: A platform wishes to send personalised promotional offers via SMS. Analysis: Requires specific, separate Consent — this is discretionary and not covered by legitimate use.

4. Employer

Scenario: An employer processes salary data for income tax filing. Analysis: Clearly Legitimate Use — statutory obligation under applicable tax law.

Key Takeaways — Section 4 in Summary

01. Legal Foundation

Section 4 is the legal foundation of all personal data processing under the DPDP Act, 2023.

02. Lawful Basis Always Required

Every processing activity — collection, storage, use, sharing — must have a lawful ground before it begins.

03. Two Principal Grounds

The Act recognises Consent (Section 6) and Certain Legitimate Uses (Section 7) as the only two valid grounds.

04. Identify and Document

Organisations should identify, assign, and document the lawful basis for every processing activity in their ROPA.

05. Start with "Why"

Good privacy governance begins with understanding why personal data is being processed — not just how.

Coming Next in This Series

Section 5 — Notice: Informing Individuals Before Collecting Their Personal Data

Once a lawful ground for processing is established, the DPDP Act requires that individuals be informed about the collection and use of their personal data. Section 5 sets out the obligations of a Data Fiduciary to provide clear, accessible, and meaningful notice — before or at the time of collecting personal data.

📋 What is Notice?

The obligation to inform Data Principals about the purpose, basis, and nature of data processing.

🔗 Why It Follows Section 4

Notice is the next step after establishing a lawful ground — it makes the processing transparent and meaningful.

📌 Who Must Give Notice?

Every Data Fiduciary collecting personal data directly or through a Data Processor must fulfil this obligation.

Follow this series for a complete, section-by-section breakdown of the DPDP Act, 2023 — in plain language, with real-world context.

⚠️ Important Notice

Disclaimer

This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.

Disclaimer artwork