Buyer Questions • 7 min read
Is there deemed consent under DPDP?
The DPDP Act 2023 replaced the concept of deemed consent with certain legitimate uses. Discover how Sections 4 and 7 affect your legal defensibility, consent operations, and compliance obligations.
Last updated:
Direct Answer: No Deemed Consent
Under the Digital Personal Data Protection Act, 2023, the concept of deemed consent does not exist. Earlier legislative drafts included this phrasing, but the final Act replaced it with the concept of certain legitimate uses. Section 4 clearly states that a person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose. The statute explicitly defines a "lawful purpose" as any purpose which is not expressly forbidden by law. Crucially, Section 4 mandates that processing must be based either on the consent given by the Data Principal or for certain legitimate uses. For General Counsels and Legal Heads evaluating compliance, this statutory shift means you cannot simply assume consent because a Data Principal interacts with your service or platform.
Section 7 and Voluntary Provision
The closest mechanism to the previous deemed consent model is found under Section 7 of the Act. Section 7(a) permits a Data Fiduciary to process personal data for a specified purpose if the Data Principal voluntarily provides it and has not indicated a refusal to consent to such use. The Act provides clear statutory illustrations of how this operates in practice. In the first illustration, an individual (X) makes a purchase at a pharmacy (Y). She voluntarily provides her mobile number to receive a payment receipt. The pharmacy may lawfully process this data for the sole purpose of sending that receipt. In a second illustration, an individual electronically messages a real estate broker requesting help to identify a suitable rented accommodation. The broker can process this data to provide the requested service. In these narrow scenarios, processing qualifies as a legitimate use without requiring explicit consent.
Limitations of Legitimate Use
While legitimate uses provide operational flexibility, they are strictly bounded. Relying on Section 7(a) cannot act as a catch-all loophole to bypass your enterprise consent management systems. If a customer provides an email address to receive a shipping confirmation, using that same email for cross-selling, newsletters, or marketing campaigns falls completely outside the specified purpose for which it was voluntarily provided. Diverting personal data to secondary purposes requires an explicit shift to affirmative consent, accompanied by an itemised notice. Enterprises must precisely map exactly where voluntary provision begins and ends to avoid illegal processing.
Special Considerations for Children and Persons with Disability
Furthermore, legal teams must reconcile legitimate uses with the stringent obligations under Section 9 concerning minors and persons with disabilities. Section 9(1) mandates that a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian before processing any personal data of a child or a person with a disability who has a lawful guardian. This creates a critical legal intersection: even if a minor voluntarily provides personal data in a manner that might otherwise look like a legitimate use under Section 7(a), the strict verifiable consent requirements of Section 9 take precedence. Additionally, Section 9(2) and Section 9(3) strictly prohibit processing that is likely to cause any detrimental effect on the well-being of a child, as well as tracking, behavioural monitoring, or targeted advertising directed at children.
Impact on Defensibility and Liability
For enterprise legal teams, relying heavily on legitimate uses introduces severe compliance risks if not tightly governed by internal policies. Regulator engagement and defensibility require clear internal documentation proving that the data was provided voluntarily and used solely for the immediate, specified purpose. If product teams or marketing departments stretch Section 7 to cover secondary processing without legal oversight, they expose the enterprise to maximum penalties of up to 250 crore rupees for breaching Section 4 processing obligations. Outside counsel spend often balloons when defending ambiguous, poorly documented data collection practices during a Data Protection Board inquiry.
Alignment with DPDP Rules 2025
The impending DPDP Rules, 2025 impose strict operational mechanics for privacy notices, consent management, and data breach reporting. Because the Rules enforce stringent requirements for verifiable consent, your organisation must definitively distinguish between consent and legitimate use at the exact point of data capture. Falsely classifying a processing activity as a legitimate use merely to avoid the itemised notice requirements mandated by the Rules creates an easily identifiable, systemic compliance failure. Your privacy architecture must hardcode these distinctions into the user journey to ensure sustainable compliance.
Breach Notification and Legitimate Use
Regardless of whether personal data is processed under affirmative consent or a legitimate use, your breach notification obligations remain absolutely identical. The Rules, 2025 require intimation to affected Data Principals without delay, alongside a detailed report to the Data Protection Board within 72 hours. Managing these incredibly tight response windows requires a comprehensive, up-to-date data map. Limitation of liability during a breach investigation depends heavily on proving that you understood exactly which legal basis applied to the compromised data and that the data was secured appropriately.
Systematic Oversight and Audit Trails
A robust compliance posture requires mapping all enterprise data flows to their specific legal bases. The legal review burden decreases significantly when software platforms automatically enforce the boundaries of legitimate use versus affirmative consent. Your systems must maintain comprehensive audit logs showing exactly why data was collected, when it was voluntarily provided, and under which provision it is processed. If a Data Principal questions your processing, your ability to provide privileged review materials and legally defend your actions depends entirely on the accuracy and immutability of these operational logs.
What To Do Next
With exactly 278 days remaining until the DPDP compliance deadline of 13 May 2027, General Counsels and compliance officers must act swiftly to formalise their processing grounds.
1. Audit all customer intake forms, mobile applications, and web portals to classify the data collection strictly under affirmative consent or a Section 7 legitimate use.
2. Revise privacy policies, terms of service, and vendor contract clauses to reflect legitimate uses accurately, stripping out any outdated language claiming deemed consent.
3. Implement automated consent management systems that generate defensible audit trails to protect your organisation against unlawful processing claims.
To evaluate your current readiness and identify gaps in how your organisation tracks legitimate uses versus consent, request an assessment at freescan.complydp.com.
Sources
Frequently asked questions
Did the DPDP Act replace deemed consent entirely?
Yes. The term deemed consent was removed in the final Digital Personal Data Protection Act, 2023. It was replaced by specific grounds for processing known as certain legitimate uses under Section 7.
Can we use Section 7 legitimate use for marketing emails?
No. Section 7(a) requires the data to be provided voluntarily for a specific, immediate purpose. Using an email provided for a shipping receipt to send promotional material exceeds the specified purpose and requires separate affirmative consent.
How do the DPDP Rules 2025 impact legitimate uses?
The DPDP Rules, 2025 detail how itemised notices must be presented when relying on consent. Legal teams must ensure any data collected without an itemised notice strictly meets the narrow voluntary criteria of Section 7 to avoid severe compliance penalties.
What is the penalty for misclassifying data collection as a legitimate use?
Processing personal data without a valid legal basis violates Section 4 of the Act. Stretching a legitimate use beyond its specified purpose is a breach of processing obligations, which can result in penalties up to 250 crore rupees.
Do we need consent for processing employee data?
Under Section 7(i), processing personal data for the purposes of employment or related to safeguarding the employer from loss or liability is considered a legitimate use. This provides a legal basis for routine HR processing without requiring continuous consent.
How does legitimate use apply to children's data under Section 9?
Section 9 strictly limits general legitimate use flexibility. Even if a child voluntarily provides data, Section 9(1) mandates verifiable consent of the parent or lawful guardian. Furthermore, tracking, behavioural monitoring, or targeted advertising directed at children is expressly prohibited.
ComplyDP