Before an organisation can touch your personal data at all, the Act asks one question: on what legal basis? There are exactly two acceptable answers.
THE ONLY TWO DOORS IN
DOOR ONE
Consent
You say YES, clearly and specifically, to a stated purpose
DOOR TWO
Lawful purpose
A person may process the personal data for which the Data Principal has given her consent and legitimate uses.
NO DOOR THREE
There is no general exception
Unlike some other countries’ laws, there’s no open-ended “because it’s reasonable for our business” basis.
This is one of the more consequential design choices in the whole Act. It means a business can’t process personal data just because doing so seems sensible or low-risk — every use has to trace back to one of these two doors, with nothing in between.
Common misconception — That if consent feels impractical to obtain, there’s probably some general business-justification basis to fall back on. There isn’t. If neither door applies, the processing isn’t lawful.
Two doors, no side entrance — that’s the entire lawful basis for processing personal data in India.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf