The Digital Personal Data Protection (DPDP) Act, 2023, has fundamentally rewired how Indian organizations collect and process personal information. For businesses, particularly those handling sensitive information like healthcare or financial data, understanding the legal basis for data processing is no longer a bureaucratic formality—it is a financial necessity. Under the Act, every data processing activity must fall into one of two buckets: Consent (Section 6) or Certain Legitimate Uses (Section 7). Relying on the wrong one can expose your organization to penalties of up to ₹250 crore.
Understanding Section 6: The Strict Standard of Consent
Historically, organizations relied on “blanket consent”—long, jargon-filled documents that users blindly accepted. Section 6 of the DPDP Act completely eliminates this practice. For consent to be legally valid, it must be Free and Unconditional, You cannot deny a core service simply because a user refuses to share unrelated data.
Specific and Informed: The Data Principal (the user) must know exactly what data is being collected and the exact purpose it serves. Accompanied by Notice: Consent must be preceded by an itemized notice, available in multiple languages.
The Revocation Rule: Section 6 also mandates that withdrawing consent must be as easy as giving it. If a patient withdraws their consent for their data to be stored on your cloud server, your organization must erase it within a reasonable time.
Understanding Section 7: Certain Legitimate Uses
What happens in an emergency? What if you need to process employee data to pay their salary? The DPDP Act recognizes that strict consent is not always practical. Section 7 outlines a strict, closed list of scenarios where organizations can process data without asking for explicit consent. Key legitimate uses include:
Medical Emergencies: Providing urgent medical treatment during a health threat.
Employment Purposes: Processing data to safeguard the employer from loss or liability, or to provide employee benefits.
Legal Obligations: Complying with court orders or state laws. (Note: Unlike the European GDPR, India’s DPDP Act does not have an open-ended “Legitimate Interest” clause. If your use case is not explicitly listed in Section 7, you must obtain Section 6 consent.
Practical Use Cases: Mapping the Law to Reality Use
Case 1: The Healthcare Emergency (Section 7)
Scenario: A patient is brought into the emergency room unconscious. The hospital accesses their electronic health records to check for drug allergies.
The Verdict: The hospital does not need consent. This falls perfectly under Section 7 (Medical Emergency). Waiting to obtain explicit consent would endanger the patient’s life, making this a lawful processing activity without notice or consent.
Case 2: The E-Pharmacy Marketing Trap (Section 6)
Scenario: A user buys medication from an online pharmacy app, consenting to provide their address for delivery. The pharmacy then uses that purchase history to send targeted SMS ads for supplements.
The Verdict: This is a violation. The consent given was specific to delivery, not marketing. Because marketing is not a Section 7 “Legitimate Use,” the pharmacy must issue a fresh notice and acquire specific, granular Section 6 consent before sending promotional messages.
Conclusion
Why Controls Testing Matters, Misclassifying data processing activities is the most common vulnerability organizations face under the DPDP Act. A robust cybersecurity and compliance strategy doesn’t just protect perimeters; it maps every single data workflow to its correct legal basis. Protect your organization from compliance blind spots.
Book a DPDP Health Check with Zorixx today.
