A Data Fiduciary may process personal data only for a lawful purpose, and only either with the Data Principal's consent, or for a legitimate use listed in s. 7.
"Lawful purpose" means a purpose not expressly forbidden by law. Note the structure: lawfulness of purpose and lawfulness of basis are two separate tests, and both must be met. A purpose can be entirely lawful and still require consent you don't have.
There is no legitimate-interest basis. If your processing does not fall within one of the specific legitimate uses in section 7, you need consent. This is the single most consequential structural difference from GDPR, and it is where most European-designed compliance programmes break when ported to India.
Every consent request must be accompanied or preceded by a notice. Under s. 5, that notice must inform the Data Principal of:
Where consent was obtained before the Act commenced, notice must still be given as soon as reasonably practicable, and processing may continue until the Data Principal withdraws consent.
The notice must be available in English or any language in the Eighth Schedule to the Constitution, at the Data Principal's option. Twenty-two languages, at the individual's choice — not the organisation's convenience.
Consent must be:
and it must signify agreement to processing for the specified purpose, limited to the personal data necessary for that purpose.
s. 6(1) contains an illustration worth reading closely: where a person consents to processing for one purpose, consent is limited to the data necessary for that purpose, and a request bundling unnecessary data is not valid consent to that surplus.
Any part of a consent request that infringes the Act is invalid to that extent.
Withdrawal. s. 6(4) requires that the Data Principal have the right to withdraw consent at any time, with ease of doing so comparable to the ease with which it was given. A one-click accept and a four-step withdrawal buried in settings does not satisfy this. On withdrawal, the Fiduciary must cease processing within a reasonable time unless another lawful ground applies.
Consequences of withdrawal fall on the Data Principal, and processing already carried out lawfully is not invalidated.
Through a Consent Manager. s. 6(7) allows consent to be given, managed, reviewed and withdrawn through a Consent Manager, who is accountable to the Data Principal.
Demonstrating consent. Where a question arises, the Data Fiduciary must be able to prove that notice was given and consent obtained in accordance with the Act. The burden sits with you.
s. 7 lists the situations in which personal data may be processed without consent. These are exhaustive — there is no residual category.
They include processing where the Data Principal has voluntarily provided her personal data for a specified purpose and has not indicated that she objects; processing by the State for the provision of a subsidy, benefit, service, certificate, licence or permit; performance of a legal function or compliance with a judgment or order; responding to a medical emergency or threat to life; measures during an epidemic or outbreak; measures during a disaster or breakdown of public order; and processing for purposes of employment or to safeguard the employer from loss or liability.
The voluntary-provision limb is the one most often over-read. It covers the purpose the person actually provided the data for, and no more. A customer giving an address for delivery has not voluntarily provided it for marketing.
Before processing the personal data of a child, a Data Fiduciary must obtain verifiable consent of the parent — which includes a lawful guardian where applicable. A child, under the Act's definitions, is an individual under eighteen years of age.
In addition, a Data Fiduciary must not:
s. 9(4) allows sub-sections (1) and (3) to be disapplied for prescribed classes of Fiduciaries, purposes and conditions — and Rule 12 with the Fourth Schedule does exactly that for specified healthcare classes. s. 9(5) allows the Central Government to notify a lower age threshold for a Fiduciary that has demonstrated verifiably safe processing.
The eighteen-year threshold is the operative fact for education and consumer platforms: most of a school's or coaching centre's student body are children under this Act.
s. 8 is where the accountability architecture sits.
8(1) — Accountability regardless of agreement. The Data Fiduciary is responsible for complying with the Act in respect of any processing undertaken by it or on its behalf by a Data Processor, notwithstanding any agreement to the contrary and notwithstanding any failure by the Data Principal to perform her duties.
8(2) — Processors under contract. A Data Fiduciary may engage a Data Processor only under a valid contract.
8(3) — Accuracy where decisions are made. Where personal data is likely to be used to make a decision affecting the Data Principal, or to be disclosed to another Data Fiduciary, the Fiduciary must ensure it is complete, accurate and consistent.
8(4) — Appropriate measures. Implement appropriate technical and organisational measures to ensure effective observance of the Act.
8(5) — Reasonable security safeguards. Protect personal data in your possession or under your control, including in respect of processing by a Processor on your behalf, by taking reasonable security safeguards to prevent a personal data breach. This is the obligation carrying the highest penalty in the Schedule.
8(6) — Breach intimation. In the event of a personal data breach, give the Board and each affected Data Principal intimation in the prescribed form and manner.
8(7) — Erasure. Erase personal data on withdrawal of consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier — unless retention is necessary for compliance with any law. The Fiduciary must also cause its Processor to erase.
8(9) — Grievance redressal. Publish the business contact information of a Data Protection Officer, if applicable, or of a person able to answer questions about processing on the Fiduciary's behalf, and establish an effective mechanism to redress Data Principal grievances.
The erasure obligation in s. 8(7) collides with mandatory retention in ways that catch most organisations out, and the Rules make the collision explicit rather than resolving it. → Retention and Erasure
s. 8(6) requires intimation of a personal data breach to the Board and each affected Data Principal. Rule 7(2) sets the timing, and it is routinely misdescribed as "72 hours to notify."
On becoming aware of a personal data breach, a Data Fiduciary must intimate the Board:
CERT-In's Directions of April 2022 require a body corporate to report a cybersecurity incident within 6 hours of detection. That obligation applies now — it does not wait for 13 May 2027 — and it is wholly independent of DPDP.
| Clock | Starts on | Deadline | In force |
|---|---|---|---|
| CERT-In | Detection of a cybersecurity incident | 6 hours | Now |
| DPDP initial intimation — Rule 7(2)(a) | Awareness of a personal data breach | Without delay | 13 May 2027 |
| DPDP detailed report — Rule 7(2)(b) | Awareness of the breach | 72 hours | 13 May 2027 |
One detection event, two regulators, three deadlines. An incident process built for one of them will fail the others.
| Obligation | Provision | What it requires of your systems |
|---|---|---|
| Lawful purpose and basis | s. 4 | A purpose register, with a recorded basis per purpose |
| Notice | s. 5 | Versioned notices, 22-language support, retrievable per consent event |
| Valid consent | s. 6 | Purpose-level capture, affirmative action, no bundling |
| Easy withdrawal | s. 6(4) | Withdrawal route with parity to the consent route, and propagation |
| Legitimate uses | s. 7 | Basis recorded per purpose, and defensible |
| Children's data | s. 9 | Age assurance, verifiable parental consent, no tracking or targeted ads |
| Accountability | s. 8(1)–(2) | Processor contracts, and oversight you can evidence |
| Accuracy | s. 8(3) | Correction workflows feeding decision systems |
| Security | s. 8(5) | Safeguards, access control, logging — the highest-penalty duty |
| Breach intimation | s. 8(6) | Detection, assessment, Board and Data Principal notification |
| Erasure | s. 8(7) | Purpose-served detection, retention conflict handling, processor cascade |
| Grievance | s. 8(9) | Published contact, intake channel, response record |
No. Processing requires either consent or one of the specific legitimate uses listed in s. 7. There is no open-ended balancing test, so processing justified under GDPR legitimate interest will often need consent in India.
Processing may continue, but notice complying with s. 5 must be given as soon as reasonably practicable, and the Data Principal may withdraw. In practice, consent gathered without purpose specificity will need to be refreshed — which is a programme with a long tail.
The notice must be available in English or any of the twenty-two languages in the Eighth Schedule to the Constitution, at the Data Principal's option. The choice belongs to the individual.
An individual who has not completed eighteen years of age. Processing a child's personal data requires verifiable parental consent, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited.
Breach of the s. 8(5) obligation to take reasonable security safeguards attracts a penalty that may extend to ₹250 crore — the highest single figure in the Schedule. → Penalties and Enforcement
Sections 4 to 10 commence on 13 May 2027, together with the penalty provisions. The obligations are not enforceable before that date, but the work of building consent architecture, inventories and rights workflows plainly takes longer than the time remaining.
Consiva.ai maps every obligation above to a workflow, dashboard, or automated job — so your team focuses on decisions, not tracking.
Start Free — No Credit Card →Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 4–10; DPDP Rules, 2025, Rules 3, 10, 12. Reference material about the law, not legal advice — see /disclaimer.