Consent Under DPDP vs GDPR: Why "Legitimate Interest" Doesn't Travel to India

Ask any GDPR-trained privacy professional what keeps consent pop-ups from appearing on every single data-processing activity, and the answer is almost always the same: legitimate interest. It's the quiet workhorse of European privacy compliance — the lawful basis that lets a company run fraud detection, do routine analytics, and send certain marketing communications without asking for explicit consent each time, as long as a documented balancing test shows the organisation's interest doesn't override the individual's rights.

India's DPDP Act doesn't have this option, and understanding exactly why matters more than just noting that it's absent.

GDPR's Article 6 sets out six lawful bases for processing, with legitimate interest functioning as an intentionally flexible, judgment-based category — a controller weighs its own interest in processing against the impact on the individual, documents that reasoning, and proceeds without needing a consent mechanism at all. It's flexible by design, precisely because the drafters wanted a workable basis for the enormous range of ordinary commercial activity that doesn't cleanly fit under contract performance or legal obligation.

The DPDP Act takes a fundamentally different position. Section 4 establishes consent as the default lawful basis for processing, full stop. Section 7 then lists "certain legitimate uses" — but as a closed, specific list rather than an open judgment call: voluntary provision of data by the individual for a stated purpose, compliance with a court judgment or order, medical emergencies, disaster response and public health situations, and a small number of employment-related purposes such as protecting the employer from loss or liability. There's no equivalent to GDPR's flexible balancing test anywhere in this list. If a processing activity doesn't fall inside one of these specific categories, the only lawful basis available is consent — obtained properly, tracked, and capable of being withdrawn as easily as it was given.

This has a direct, practical consequence for any organisation that built its data practices around GDPR's flexibility. Routine fraud-pattern analytics across a customer base, for instance, would typically run under legitimate interest in the EU. In India, unless that specific analytics use case happens to fall within Section 7's narrow list — and most such activities don't — the same processing needs actual, purpose-specific consent from each Indian user whose data is analysed. The same applies to a wide range of ordinary commercial processing: cross-selling based on purchase history, certain categories of behavioural personalisation, and various forms of internal business analytics that EU teams rarely think twice about from a lawful-basis perspective.

The lesson for compliance teams building or buying tooling isn't just "add a consent checkbox." It's that any inventory of processing activities needs to be re-evaluated activity by activity against Section 7's specific list, rather than assumed to carry over from whatever lawful basis applied under GDPR. Where an activity doesn't fit the list, the only route to compliance is capturing real, purpose-specific consent — not a broader, GDPR-style justification that simply has no equivalent under Indian law.

About the Author: Nitin Ray is a Compliance Manager at RuleExpert, helping organisations build DPDP-compliant consent frameworks from the ground up. Learn more at ruleexpert.com.

 

  

Comments

Popular posts from this blog

Data Deletion in 2026: Why Your Business Needs a Compliance Workflow Now

The Future of Data Protection in India

Empowering the Indian Consumer: Navigating Your Rights as a Data Principal