DPDP Insights › Questions › When do we need consent, and when can we rely on a legitimat
Question
When do we need consent, and when can we rely on a legitimate use?
Short answer: It depends on the use; most organisations need both
For every use of personal data you need one basis: consent, or one of the legitimate uses in Section 7, such as a legal duty, employment, a medical emergency, or data a person gave voluntarily for a specific purpose. Anything beyond what the person expects, such as marketing, profiling or sharing with partners, usually needs consent.
What the law says
Section 4 allows processing only with consent or for a legitimate use. Section 6 sets what valid consent looks like. Section 7 lists the uses that need no consent.
Section 4: Personal data may be processed only for a lawful purpose, either with the person's consent or for one of the legitimate uses listed in Section 7.
Section 6: Consent must be free, specific, informed, unconditional and unambiguous, given by a clear action, limited to the data needed for the purpose, and as easy to withdraw as it was to give.
Section 7: Some uses need no consent: data a person gave voluntarily for a specified purpose, duties under law, medical emergencies involving a threat to life, health services during an epidemic, safety during a disaster, and purposes of employment.
Steps
List each purpose for which you use personal data.
Against each purpose, write the basis: consent or the exact clause of Section 7.
Where the basis is consent, check that it was asked separately, with a clear action and no pre-ticked box.
Stop or re-paper any purpose with no basis.
Review the list whenever a new product, campaign or system starts.
Evidence to keep
Purpose and basis register
Consent records with date, version and channel
Legal sign-off on each legitimate use relied on
Common mistakes
Treating account terms as consent for marketing
Bundling several purposes in one tick-box
Relying on 'legitimate interest', which the Indian Act does not have
How it plays out by sector
Banking, financial services and insurance: KYC is a legal duty. Loan servicing uses data the customer gave for the loan. Cross-selling insurance needs separate consent.
IT, ITeS, BPO and GCC: Payroll and background checks are employment purposes. Newsletters to prospects need consent.
DPO / Privacy lead: Build the purpose-and-basis register yourself, even if each team fills its own rows. When someone asks why their data was used, this register is your answer.
Legal & compliance: Write the basis for each purpose and keep it with the register. Where you rely on Section 7, cite the exact clause.
Branch / business head: Know which uses in your area need consent and which do not, so staff can answer simply.
Marketing department: Ask marketing consent separately and keep the record with the date and version.
Legal department: Record the legal basis for each purpose with the exact clause.
What a good answer from management sounds like
“Every purpose has a written basis. Marketing and partner sharing run only on separate consent, and we can produce the record for any customer in a few minutes.” Effort and time: Medium · 6 to 10 weeks.