Section 7 of the DPDP Act: When Can You Process Personal Data Without Consent?

    Section 7 of the DPDP Act lists nine legitimate uses for processing personal data without consent. See how each clause applies to your customer and employee workflows.

    OneConsentBlog
    11 min read
    Friday, 9 October 2026
    Brass scales of justice on stacked legal documents beside data record cards, under the title Section 7 of the DPDP Act

    A customer at a pharmacy shares a mobile number so that the payment receipt can arrive by SMS. The pharmacy is allowed to send that receipt without asking for a separate consent, and Section 7 of the DPDP Act is the reason. Section 7 lists nine "certain legitimate uses". These are specific situations in which a Data Fiduciary, which is the organisation that decides why and how personal data is processed, may process personal data without relying on consent under Section 6 of the DPDP Act.

    Legitimate uses appear across ordinary business activity. They cover customer transactions and employee records. Legal disclosures and emergency healthcare appear on the list too. Your compliance and business teams need to decide, workflow by workflow, which uses of personal data need consent and which ones Section 7 supports on another ground.

    Section 7 comes into force from 13 May 2027, under the phased commencement notice dated 13 November 2025. Below are set out the details of each category of legitimate uses. The article also describes the ongoing responsibilities and a five-step process to categorize one’s workflow as such.

    What Is Section 7 of the DPDP Act?

    Section 7 of the DPDP Act specifies nine different situations when the processing of personal data takes place without obtaining the Data Principal's consent. The framework comes from Section 4, which allows a Data Fiduciary to process personal data for a lawful purpose with the Data Principal’s consent or under one of the legitimate uses in Section 7. The Data Principal is a person whose data it concerns.

    The list is closed. Because the list is closed, a business cannot label an activity a legitimate business interest and place it under Section 7. Your team needs to identify the exact clause that applies and record why. Your team needs to be able to determine precisely what particular clause applies and why it applies to the case at hand.

    The teams that also have to comply with European legislation often make comparisons between Section 7 and legitimate interests of Article 6(1)(f) of the GDPR. The notion of the GDPR has a balancing test involved in it. Section 7 contains no such test, because Parliament has already defined the permitted uses. Multinational businesses should record the two separately.

    Which Activities Can Be Processed Without Consent Under Section 7?

    Section 7 contains nine clauses. Some relate directly to the private sector operations your business runs. Others apply mainly to government functions and emergencies.

    •       7(a): personal data a Data Principal voluntarily provides for a specified purpose

    •       7(b): State subsidies, benefits, services, certificates, licences and permits

    •       7(c): functions the State performs under law, including sovereignty, integrity and State security

    •       7(d): disclosures to the State that another Indian law obliges a person to make

    •       7(e): compliance with judgements, decrees and orders, including certain foreign civil and contractual orders

    •       7(f): medical emergencies involving a threat to life or an immediate threat to health

    •       7(g): medical treatment and health services during an epidemic, outbreak or other public health threat

    •       7(h): safety and assistance measures during a disaster or a breakdown of public order

    •       7(i): Employment and to protect the employer against loss or liability

     

    The most significant clauses for private business establishments are clauses 7(a) and 7(i). The legal disclosure clauses come next.

    Section 7(a): Using Personal Data a Customer Shares for a Stated Purpose

    Section 7(a) applies when three conditions hold together:

    1.    The Data Principal provides personal data voluntarily.

    2.    The data is provided for a specified purpose.

    3.    The Data Principal has given no indication that the data should not be used for that purpose.

    For a deeper look at this clause, read our full blog on Section 7(a) of the DPDP Act



    The Act gives two illustrations. The first example involves a customer of a pharmacy who gives his telephone number for receiving a payment slip. In the second scenario, a person sends a message to a real estate agent giving him his personal details for finding rented accommodation.

    Both illustrations show the individual starting the exchange. The DPDP Rules, 2025 do not define ‘voluntarily provided’, so a written note on why each workflow qualifies gives your legal team a defensible record. On their reading, 7(a) is most dependable when the person starts the sharing for a purpose they have stated. The DPDP Rules, 2025 do not provide any definition. An explanation as to why each process is applicable is stated in writing, and this gives the legal department a good ground.

    Take an online order. The customer gives an address for delivery, and the company uses it to dispatch the order. Months later, the marketing team wants the same purchase record for a festive campaign. The campaign is a new purpose, and promotional messages generally need consent under Section 6. After checkout, the same phone number can travel into several activities:

    •       customer support and order tracking

    •       loyalty programmes and CRM segmentation

    •       email and WhatsApp campaigns

    •       analytics and product research

    Each function performs a specific purpose. These types of enterprises in retail and finance see this happening on a daily basis. It is usually easier to obtain a clear answer when looking at purposes instead of analyzing fields individually.

    DPDP Act for Employers: Processing Employee Data Under Section 7(i)

    Section 7(i) allows processing for employment purposes. The section also allows processing where the employer is protected from loss or liability. The examples of these are as follows:

    •       confidentiality of trade secrets and intellectual property

    •       prevention of corporate espionage

    •       protection of classified information

    •       a service or benefit that an employee requests

    Payroll and attendance connect directly to employment. Benefits administration and office access management are close behind. Controls for cybersecurity and device management in companies generally apply to the second part of the clause, dealing with the protection of the employer.

    If your company plans to use productivity analytics or AI-based evaluation, your HR and legal teams can document five points before launch:

    1.    the employee data the tool will collect

    2.    the purpose each data point serves

    3.    the link between that purpose and employment or employer safeguarding

    4.    the people who will see the outputs

    5.    the retention period for the information

    A practical test for any new employee data initiative: can the organisation write down how the use connects to a recognised purpose under Section 7(i)

    Sharing Personal Data When the Law Requires It: Sections 7(d) and 7(e)

    Section 7(d) covers disclosures that any law in force in India requires a person to make to the State or its agencies. auTax reporting and regulator filings are common examples. Section 7(e) covers compliance with a judgement, decree or order under Indian law. It also covers foreign orders on contractual or civil claims.

    You will see these clauses in regulatory inspections and statutory filings. Litigation and court-ordered production of records bring them up too.

    For your disclosure team, traceability is the operational priority. As a recommended practice, the team can log four details for each event:

    1.    the data disclosed and its source system

    2.    the legal provision or order behind the disclosure

    3.    the recipient and the date

    4.    any retention period for the disclosed copy

    A fully maintained log will help the business to answer questions posed by the auditor or the Data Principal regarding a previous disclosure.

    Section 7 DPDP Act Provisions for Medical Emergencies, Epidemics and Disasters

    Medical emergencies which entail a threat to life or imminent threats to health are covered under section 7(f). Section 7(g) covers treatment and health care services during epidemics or outbreaks. Section 7(h) covers safety and assistance services during a disaster or breakdown of law and order. Definition of disaster as per this Act is as per Disaster Management Act, 2005.

    These provisions would be most useful for hospitals and emergency services organizations, but may even face insurance and health-tech providers at times. They are provisions concerning urgency and, therefore, separate consideration is needed for regular health care and wellness marketing. A short note recorded at the time helps show that the ground applied.

    Government Benefits and State Functions Under Sections 7(b) and 7(c)

    Section 7(b) permits the State to process personal data for the purpose of issuing subsidies, licenses, and other similar services. Rule 5 of the DPDP Rules, 2025, read with the Second Schedule, sets the standards for that processing. Section 7(c) covers State functions under law. It also covers processing in the interest of sovereignty and security.

    Private companies comply with these requirements as technology providers and contractors of the government. If your company is involved in the exchange of data within the public system, you should study the Act and its associated rules as a whole.

    Obligations That Continue to Apply Under Section 7

    Section 7 creates the foundation for eligible processing. The further responsibilities detailed in Section 8 of a Data Fiduciary are still responsible for how the data is processed. The security measures and processor agreements apply here too. Accuracy becomes important if the data affects a decision. The data should be deleted after the task is done if it’s not legally obligated to stay.

    Some Data Principal rights continue as well. Section 11 gives the right to access a summary of processing. Section 12 gives the rights to correction and erasure. Both extend to data processed under Section 7(a).

    Payroll shows how the pieces connect. Section 7(i) could justify the employment context. The database must retain proper access controls and proper retention too. An outsourced service needs to be managed properly. The justification is the explanation for why processing was allowed. The privacy governance is how the organization manages the data from start to finish.

    How to Decide Between Consent and Section 7 for Each Processing Activity

    The same record will help in completing the order and providing customer services. This customer record is the basis for promotions and customer loyalty. The fraud team and legal requirements use this record also. The data stay the same, but the purposes change; therefore, the systematic review process is used to differentiate between each purpose.

    1. State the Purpose

    Express the aim in a practical manner. "To improve customer experience" is an example of a vague goal that cannot be categorized. "To send delivery notifications for an ongoing order" gives the reviewer a clear-cut way of evaluating.

    2. Identify the Personal Data Involved

    Map the data fields and their source. Note where the data was collected and which systems and processors receive it.

    3. Check Whether a Section 7 Clause Applies

    Record the exact clause you are relying on and the reason the activity matches it. Attach supporting context, such as the legal provision behind a disclosure.

    4. Determine Whether Consent Is Required

    Activities outside Section 7 need consent under Section 6. Plan the Section 5 notice and the point at which consent is captured. Then decide how your team will store evidence and process withdrawal.

    5. Track Where the Data Moves

    Follow the data into your CRM and customer data platforms. Marketing tools and support desks often receive it too, along with HR systems.

    The review produces a processing record with six linked fields:

    1.    purpose

    2.    personal data

    3.    ground for processing

    4.    system

    5.    processor

    6.    retention period

    Section 7 DPDPA Readiness as a Data Governance Exercise

    Follow one phone number through a typical enterprise. The number enters at checkout. Within days it can reach the CRM and the loyalty engine. A campaign tool and the analytics team may draw on it later.

    At each stage, your teams need to see the purpose and its ground for processing. Consent status matters wherever consent applies. A downstream team rarely sees the context of the original collection, so the ground should travel with the purpose. Section 7 readiness combines two workstreams. Legal teams classify each use. Data and technology teams keep that classification connected to live systems.

    Keeping Purpose and Ground Visible Across Systems with OneConsent

    Legal personnel planning for May 2027 must get information about where the consent is required and what purpose it serves. Auditors need evidence to be available upon demand.

    OneConsent is a DPDPA consent management platform designed around those needs. Its Purpose and Processing Management module links purposes to personal data and processing activities. The Processing Activity Center gives a central view of purposes and data categories across systems. Evidence of Consent and Audit Trail tracks the timestamped logs. The Consent Sync Hub passes consent and preference changes to connected applications.

    Preparing for Section 7 Before May 2027

    Section 7 of the DPDP Act provides the conditions when consent under Section 6 does not apply. The readiness work will link those conditions to practical work processes. Three priorities carry most of the value. Map each purpose and identify its ground. Then keep the evidence behind each decision.

    Customer records and employee profiles pass through many systems over their lifecycle. The organisations best prepared for May 2027 will be able to explain why each use takes place and which ground supports it. They will also know where the evidence is held.

    Map Your Section 7 and Consent Decisions with OneConsent

    Classifying each activity under Section 7 forms one step in your wider DPDP compliance programme. OneConsent can help you connect each purpose to its ground for processing and its consent record. The platform also shows which connected systems use that data. You can explore the OneConsent platform to see how purpose and consent governance work across touchpoints, and book a personalised demo to review your own processing activities with the team.

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack