Deemed consent does not exist under the DPDP Act
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 7 min read
The short answer
No. The phrase deemed consent appears nowhere in the Digital Personal Data Protection Act, 2023, and neither does legitimate interest. Clause 8 of the November 2022 draft Bill was headed Deemed consent, but that draft was a consultation document and the enacted Act replaced it with section 7, headed Certain legitimate uses, which lists 9 clauses, (a) to (i). Section 4 makes those legitimate uses 1 of only 2 lawful grounds for processing, the other being consent. Several categories the 2022 draft would have covered, including credit scoring and a general fair and reasonable purpose weighed against the Data Fiduciary's legitimate interests, are not in the Act at all, while others, such as recovery of debt and publicly available personal data, survive only in a different shape in section 17(1)(f) and section 3(c)(ii). Section 7 is in the group of provisions due to come into force 18 months after publication, which computes to 13 May 2027, interpretation until officially confirmed.

There is no deemed consent in the Digital Personal Data Protection Act, 2023. The phrase appears nowhere in the Act. Neither does legitimate interest. Both are real drafting history, and both were dropped before enactment, which is why summaries built on them describe a law India does not have.
What section 4 actually allows
Section 4 gives a Data Fiduciary exactly 2 lawful grounds for processing personal data: consent, and
"(b) for certain legitimate uses."
That is the whole of the second ground, and section 4 admits no third. Two limits sit outside section 4 and are worth naming so the point is not overstated: section 3(c) means the Act does not apply at all to some processing, including personal data the Data Principal has made publicly available, and section 17 disapplies most of Chapter II in the situations it lists. Within the reach of the Act, though, section 4 offers consent or a legitimate use and nothing else. The second ground points at section 7, whose marginal heading is Certain legitimate uses, and which opens:
"A Data Fiduciary may process personal data of a Data Principal for any of following uses, namely:—"
The missing word before "following" is as printed in the Gazette. Section 7 then prints 9 clauses, (a) to (i), and section 8 begins immediately after clause (i). There is no clause (j), no residual category and no balancing test anywhere in the section.
The 9 legitimate uses
| Clause | What it covers |
|---|---|
| (a) | The specified purpose for which the Data Principal voluntarily provided her personal data to the Data Fiduciary, where she has not indicated to it that she does not consent to that use |
| (b) | The State and its instrumentalities providing a prescribed subsidy, benefit, service, certificate, licence or permit, and only where she has previously consented to such processing by the State or the data sits in a State maintained database notified by the Central Government |
| (c) | Performance by the State or any of its instrumentalities of a function under any law in force in India, or processing in the interest of sovereignty and integrity of India or security of the State |
| (d) | Fulfilling a legal obligation on any person to disclose information to the State or its instrumentalities, subject to the disclosure provisions of that other law |
| (e) | Compliance with an Indian judgment, decree or order, or with a foreign judgment or order relating to a claim of a contractual or civil nature |
| (f) | Responding to a medical emergency involving a threat to the life, or an immediate threat to the health, of the Data Principal or any other individual |
| (g) | Medical treatment or health services during an epidemic, outbreak of disease or other threat to public health |
| (h) | Safety, assistance or services during a disaster or breakdown of public order |
| (i) | Employment purposes, and safeguarding the employer from loss or liability |
For a private company the workhorse is clause (a), which reaches personal data the Data Principal hands over for a purpose she has not objected to. 2 further clauses are worth singling out, in opposite directions. Clause (b) is the one most often misread: it is available only "for the State and any of its instrumentalities", and both of its gateways turn on processing by the State, so a private business cannot process its own customers on the footing that it is delivering a service. Whether an agency delivering a State scheme could rely on it is not settled by the words of the clause. Clause (i) is the one most private employers will actually use, and it is written around employment and protecting the employer from loss or liability.
Where deemed consent comes from
The November 2022 draft Bill, published by MeitY for public consultation, had a clause 8 headed Deemed consent, whose opening words were: "A Data Principal is deemed to have given consent to the processing of her personal data if such processing is necessary:". Those words are quoted inline rather than as a block quotation on purpose. Block quotations on this site carry an official requirement label, and this text is a consultation draft that never became law.
That draft was a consultation document and was never introduced in Parliament. What Parliament enacted less than 9 months later replaced the deeming construction with the section 7 list. The difference is not cosmetic. Deemed consent framed the ground as consent that the law supplies on the Data Principal's behalf; a legitimate use is not framed as consent, which is why section 6, section 5 and the withdrawal machinery are written around consent and not around section 7. 1 trace of the older idea does survive: sections 11(1) and 12(1) give the access and correction rights against a Data Fiduciary to whom the Data Principal has previously given consent, including consent as referred to in clause (a) of section 7, so for those 2 rights the Act itself treats clause (a) as a species of consent.
What the draft had that the Act does not
This is the part that makes stale summaries dangerous rather than merely out of date. The 2022 draft's deemed consent clause reached these categories, none of which is a legitimate use in section 7 of the enacted Act:
- credit scoring
- recovery of debt
- operation of search engines for publicly available personal data
- processing of publicly available personal data
- network and information security
- and, widest of all, "any fair and reasonable purpose as may be prescribed", to be assessed by asking "whether the legitimate interests of the Data Fiduciary in processing for that purpose outweigh any adverse effect on the rights of the Data Principal"
Two of those categories reappear in the Act in a different shape rather than vanishing. Section 3(c)(ii) puts personal data that the Data Principal has made publicly available, or that another person is under a legal obligation to make publicly available, outside the Act altogether, which is wider than the draft's deemed consent route and narrower in what it covers. Section 17(1)(f) exempts processing to ascertain the financial information, assets and liabilities of a person who has defaulted on a loan or advance from a financial institution, which is the nearest the Act comes to recovery of debt. Neither is a section 7 legitimate use. That last bullet is the closest thing in Indian drafting history to the GDPR style legitimate interests ground, and it did not survive. A company that reads a 2022 vintage explainer and concludes it may process on a fair and reasonable purpose basis, or for credit scoring, is relying on a clause that was never enacted. Under the Act as passed, processing that fits none of the 9 clauses needs consent.
The count is a useful tell
The count is the fastest way to test any summary of section 7. The Gazette prints 9 clauses, lettered (a) to (i), section 8 begins immediately after clause (i), and clause (h) also carries an Explanation that borrows the meaning of disaster from clause (d) of section 2 of the Disaster Management Act, 2005. A summary that cannot hold the count steady, or that reports 8, is not reading the section.
What a legitimate use does not switch off
Relying on section 7 removes the need for consent for that processing. It does not remove the rest of the Act. Section 8 states the general obligations of a Data Fiduciary in its own terms, and its first sub-section makes the fiduciary responsible for compliance irrespective of any agreement to the contrary, so security safeguards, accuracy where a decision or a disclosure turns on the data, breach intimation and erasure obligations do not depend on which ground was used.
Notice is the one place where the answer is less clean than it looks. Section 5(1) expresses the notice duty as attaching to "Every request made to a Data Principal under section 6 for consent", and a legitimate use under section 7 involves no such request. The better reading, and this site treats it as a reading rather than as the law, is that no section 5 notice is owed for processing under section 7. It is interpretation and not text, and the Act pushes back in 1 place worth naming: clause (a) of section 7 permits processing for the specified purpose, and section 2(za) defines a specified purpose as the purpose mentioned in the notice given by the Data Fiduciary, so clause (a) processing presupposes a notice that states the purpose. Section 8(7)(a) then measures erasure by that same specified purpose. The Act nowhere says that no notice is owed for a legitimate use, and no Board guidance construes the point. As a practical recommendation and not as a requirement of the Act, publish what you process and why regardless, because the transparency costs little and it is a poor argument to have to run after the fact.
When this starts to apply
Section 7 is named in the 18 month commencement group of notification G.S.R. 843(E). Computed from the publication date printed on Gazette issue No. 757, that group is due on 13 May 2027, and that calendar date is interpretation until officially confirmed. Nothing in section 7 is in force as at 25 August 2026, which also means that no organisation is yet relying on it lawfully or unlawfully. The reason to get the ground right now is that the ground you choose determines what you will need to build: a consent flow and a notice, or a documented legitimate use with a record of which clause you are within.
Section 7, official text with sources →What DPDP consent must look like →Why the commencement date is disputed by 1 day →