What is legitimate use under DPDP?
“Legitimate use” is a defined set of situations under Section 7 of India’s Digital Personal Data Protection Act, 2023 (DPDP Act) where a business may process personal data without consent. It’s a closed list — not a general exception.
Educational resource only — not legal advice.
It names nine grounds, including data a person has voluntarily provided for a purpose, certain employment purposes, medical emergencies, and specific State functions. Outside these defined cases, consent remains the rule. Legitimate use replaced the older idea of “deemed consent,” which was dropped in the 2023 Act — a common point of confusion.
Why it matters to you. For a business, legitimate use tells you the narrow set of cases where a consent box isn’t required (for example, running payroll for your staff). For an individual, it explains why some processing can lawfully happen without you actively agreeing.
What it is not. Legitimate use is not a catch-all exemption, and it’s not the old “deemed consent.” It also doesn’t switch off your other duties — even when you rely on it, you must still keep the data secure, use it only for that purpose, and honour people’s rights over it. It removes the consent requirement, nothing more.
Collecting personal data from your own customers?
These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.
Run the compliance self-check →