Section 4 – Grounds for Processing Personal Data
Digital Personal Data Protection Act, 2023 | A Practical Executive Guide

Every Processing Activity Needs a Lawful Basis
Before an organisation collects, uses, stores, shares, or processes personal data, it must have a legally valid ground under the DPDP Act, 2023. Organisations cannot process personal data simply because it is convenient, useful, or available. Section 4 is the legal gateway — it establishes the foundational rule that governs every data processing activity carried out by a Data Fiduciary.
🚫 Without Lawful Basis
Processing may be non-compliant, exposing the organisation to legal risk and regulatory action.
✅ With Lawful Basis
Processing is permitted, transparent, and defensible under the Act.
The Two Lawful Grounds Under Section 4
Section 4 of the DPDP Act recognises exactly two lawful grounds for processing personal data. If an organisation cannot rely on either, it should generally refrain from processing that data.
Ground 1 — Consent
The Data Principal gives free, specific, informed, and unambiguous consent for a specific purpose. Governed by Section 6.
Ground 2 — Certain Legitimate Uses
Processing is permitted without explicit consent in specific situations defined by law. Governed by Section 7.

Section 4 as the Legal Gateway
Section 4 is not just a standalone provision — it is the entry point to the entire compliance framework of the DPDP Act. Every obligation that follows — Notice, Consent, Legitimate Use, Data Fiduciary obligations — flows from this fundamental question: "Do we have a lawful ground to process this personal data?"
This flow represents the logical sequence every organisation must follow before initiating any data processing activity under the Act.
The First Question Every Organisation Must Ask
Before You Ask...
- What data should we collect?
- How should we secure it?
- What rights do individuals have?
- How long should we retain it?
You Must First Answer:
“Do we have a lawful ground to process this personal data?”
This single question is the starting point of data protection compliance under the DPDP Act. Getting it right protects the organisation, builds trust, and prevents costly remediation later.
Consent vs. Certain Legitimate Uses — At a Glance
While both are valid lawful grounds, they operate very differently. Understanding which ground applies to which activity is essential for compliance.
| Dimension | Consent (Section 6) | Legitimate Use (Section 7) |
|---|---|---|
| Who decides? | The Data Principal (individual) | The law defines the situations |
| Can it be withdrawn? | Yes, at any time | Not applicable |
| Typical use | Marketing, optional services | Statutory obligations, safety |
| Notice required? | Yes (Section 5) | May still apply |
Real-World Processing Activities Across Sectors

🏥 Hospital
Patient registration and treatment → Consent. Insurance processing and lab testing may fall under Legitimate Use depending on statutory obligations.

🏦 Bank
KYC and loan processing → likely Legitimate Use (regulatory mandate). Internet banking sign-up → Consent.

🏢 Employer
Payroll, statutory compliance, attendance → Legitimate Use. Optional employee surveys or photo for internal branding → Consent.

🛒 E-Commerce
Customer registration and delivery → Consent. Promotional emails → Consent (separate, specific). Customer support → contextual.
Sector Deep Dive — Healthcare & Banking
🏥 Hospital Processing Activities
| Activity | Likely Ground |
|---|---|
| Patient registration | Consent |
| Medical treatment | Consent / Legitimate Use |
| Lab testing | Consent |
| Insurance processing | Legitimate Use |
🏦 Bank Processing Activities
| Activity | Likely Ground |
|---|---|
| Opening a bank account | Consent |
| KYC verification | Legitimate Use |
| Loan processing | Legitimate Use |
| Internet banking | Consent |
Sector Deep Dive — HR & E-Commerce
🏢 Employer Processing Activities
| Activity | Likely Ground |
|---|---|
| Recruitment | Consent |
| Payroll processing | Legitimate Use |
| Attendance tracking | Legitimate Use |
| Statutory compliance | Legitimate Use |
| Employee ID cards | Consent / Legitimate Use |
🛒 E-Commerce Processing Activities
| Activity | Likely Ground |
|---|---|
| Customer registration | Consent |
| Product delivery | Consent |
| Promotional communications | Consent (specific) |
| Customer support | Consent / Legitimate Use |
Can We Process This Personal Data?
Use this practical decision tree before initiating any data processing activity. Every organisation — large or small — should embed this logic into its operations and governance processes.
Personal Data?
Is personal data being processed?
DPDP Apply?
Does the DPDP Act cover this?
Purpose?
What is the processing purpose?
Valid Consent?
Is valid consent obtained?
If neither Consent nor Legitimate Use applies at Step 5, the organisation should reconsider whether the processing should proceed at all before taking any further action.
How Section 4 Connects to the Rest of the Act
Section 4 is the foundation upon which every other obligation under the DPDP Act is built. Understanding this flow helps organisations sequence their compliance activities correctly and avoid gaps in their data protection programmes.

Each stage in this flow is interdependent. A gap at Stage 1 — failing to establish a lawful ground — invalidates all subsequent steps and renders the entire processing activity potentially non-compliant.
Common Business Mistakes to Avoid
Many organisations inadvertently fall into these traps when managing personal data. Awareness is the first step to correction.
❌ No Lawful Basis Identified
Collecting personal data without first identifying a lawful ground — the most common and serious compliance gap.
❌ Consent for Everything
Assuming consent is always required, even when a legitimate use already covers the activity — creating unnecessary consent fatigue.
❌ Never Seeking Consent
Assuming consent is never required and relying solely on legitimate use, even for clearly discretionary processing activities.
❌ One Basis for Multiple Purposes
Using a single lawful basis to justify several unrelated processing activities — each purpose must be evaluated individually.
❌ Speculative Data Collection
Processing personal data "just in case it may be useful later" — purpose limitation is a core principle of the Act.
Why Documenting the Lawful Basis Is Good Business
Maintain a Record of Processing Activities (ROPA)
Every organisation should maintain an internal record — a ROPA or equivalent — that documents, for each processing activity:
- The purpose of processing
- The lawful ground relied upon
- The categories of personal data involved
- The retention period and review schedule
Business Benefits of Documentation
Better Compliance
Structured records demonstrate accountability to regulators and auditors.
Stronger Customer Trust
Transparency about data use builds long-term loyalty and brand equity.
Reduced Legal Risk
Clear documentation reduces exposure to penalties and disputes.
Real-Life Scenarios — Identify the Lawful Ground
Test your understanding. For each scenario below, consider which lawful ground should apply before reviewing the explanation.
1. Educational Institution
Scenario: A university collects student biometric data for attendance. Analysis: May fall under Legitimate Use if mandated by institutional regulation, or Consent if optional.
2. Government Service
Scenario: A government department processes Aadhaar-linked data for a welfare scheme. Analysis: Likely Legitimate Use under a statutory function of the State.
3. E-Commerce Platform
Scenario: A platform wishes to send personalised promotional offers via SMS. Analysis: Requires specific, separate Consent — this is discretionary and not covered by legitimate use.
4. Employer
Scenario: An employer processes salary data for income tax filing. Analysis: Clearly Legitimate Use — statutory obligation under applicable tax law.
Key Takeaways — Section 4 in Summary
01. Legal Foundation
Section 4 is the legal foundation of all personal data processing under the DPDP Act, 2023.
02. Lawful Basis Always Required
Every processing activity — collection, storage, use, sharing — must have a lawful ground before it begins.
03. Two Principal Grounds
The Act recognises Consent (Section 6) and Certain Legitimate Uses (Section 7) as the only two valid grounds.
04. Identify and Document
Organisations should identify, assign, and document the lawful basis for every processing activity in their ROPA.
05. Start with "Why"
Good privacy governance begins with understanding why personal data is being processed — not just how.
Section 5 — Notice: Informing Individuals Before Collecting Their Personal Data
Once a lawful ground for processing is established, the DPDP Act requires that individuals be informed about the collection and use of their personal data. Section 5 sets out the obligations of a Data Fiduciary to provide clear, accessible, and meaningful notice — before or at the time of collecting personal data.
📋 What is Notice?
The obligation to inform Data Principals about the purpose, basis, and nature of data processing.
🔗 Why It Follows Section 4
Notice is the next step after establishing a lawful ground — it makes the processing transparent and meaningful.
📌 Who Must Give Notice?
Every Data Fiduciary collecting personal data directly or through a Data Processor must fulfil this obligation.
Follow this series for a complete, section-by-section breakdown of the DPDP Act, 2023 — in plain language, with real-world context.
Disclaimer
This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.
