Consent Under DPDP vs GDPR: Why "Legitimate Interest" Doesn't Travel to India
Ask any GDPR-trained privacy professional what keeps consent
pop-ups from appearing on every single data-processing activity, and the answer
is almost always the same: legitimate interest. It's the quiet workhorse of
European privacy compliance — the lawful basis that lets a company run fraud
detection, do routine analytics, and send certain marketing communications
without asking for explicit consent each time, as long as a documented
balancing test shows the organisation's interest doesn't override the individual's
rights.
India's DPDP Act doesn't have this option, and understanding
exactly why matters more than just noting that it's absent.
GDPR's Article 6 sets out six lawful bases for processing,
with legitimate interest functioning as an intentionally flexible,
judgment-based category — a controller weighs its own interest in processing
against the impact on the individual, documents that reasoning, and proceeds
without needing a consent mechanism at all. It's flexible by design, precisely
because the drafters wanted a workable basis for the enormous range of ordinary
commercial activity that doesn't cleanly fit under contract performance or
legal obligation.
The DPDP Act takes a fundamentally different position.
Section 4 establishes consent as the default lawful basis for processing, full
stop. Section 7 then lists "certain legitimate uses" — but as a
closed, specific list rather than an open judgment call: voluntary provision of
data by the individual for a stated purpose, compliance with a court judgment
or order, medical emergencies, disaster response and public health situations,
and a small number of employment-related purposes such as protecting the employer
from loss or liability. There's no equivalent to GDPR's flexible balancing test
anywhere in this list. If a processing activity doesn't fall inside one of
these specific categories, the only lawful basis available is consent —
obtained properly, tracked, and capable of being withdrawn as easily as it was
given.
This has a direct, practical consequence for any
organisation that built its data practices around GDPR's flexibility. Routine
fraud-pattern analytics across a customer base, for instance, would typically
run under legitimate interest in the EU. In India, unless that specific
analytics use case happens to fall within Section 7's narrow list — and most
such activities don't — the same processing needs actual, purpose-specific
consent from each Indian user whose data is analysed. The same applies to a wide
range of ordinary commercial processing: cross-selling based on purchase
history, certain categories of behavioural personalisation, and various forms
of internal business analytics that EU teams rarely think twice about from a
lawful-basis perspective.
The lesson for compliance teams building or buying tooling
isn't just "add a consent checkbox." It's that any inventory of
processing activities needs to be re-evaluated activity by activity against
Section 7's specific list, rather than assumed to carry over from whatever
lawful basis applied under GDPR. Where an activity doesn't fit the list, the
only route to compliance is capturing real, purpose-specific consent — not a
broader, GDPR-style justification that simply has no equivalent under Indian
law.
About the Author: Nitin Ray is a Compliance Manager at
RuleExpert, helping organisations build DPDP-compliant consent frameworks from
the ground up. Learn more at ruleexpert.com.
Comments
Post a Comment