What Counts as Lawful Processing

Before an organisation can touch your personal data at all, the Act asks one question: on what legal basis? There are exactly two acceptable answers.

THE ONLY TWO DOORS IN

DOOR ONE

Consent

You say YES, clearly and specifically, to a stated purpose

DOOR TWO

Lawful purpose

A person may process the personal data for which the Data Principal has given her consent and legitimate uses.

NO DOOR THREE ​

There is no general exception

Unlike some other countries’ laws, there’s no open-ended “because it’s reasonable for our business” basis.

This is one of the more consequential design choices in the whole Act. It means a business can’t process personal data just because doing so seems sensible or low-risk — every use has to trace back to one of these two doors, with nothing in between.

Common misconception — That if consent feels impractical to obtain, there’s probably some general business-justification basis to fall back on. There isn’t. If neither door applies, the processing isn’t lawful.

Two doors, no side entrance — that’s the entire lawful basis for processing personal data in India.

SOURCES  The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf

Ready to get compliant?

Talk to our team or register your organisation to get started with ConveyGrid.