Section 4 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 4 is the gateway rule. A person may process the personal data of a Data Principal only in accordance with the Act and for a lawful purpose, and that purpose must rest on one of two grounds: the Data Principal's consent, or one of the "certain legitimate uses" in section 7. There is no third ground such as "legitimate interest" in the text. A legal consultation can help you assign a ground to each of your processing activities.
Personal data may be processed only in accordance with the Act and for a lawful purpose (section 4(1)). The purpose must be one for which the Data Principal has given consent, or for certain legitimate uses (section 7). A "lawful purpose" is any purpose not expressly forbidden by law (section 4(2)). Processing with neither ground is a breach; the general penalty in the Schedule is up to fifty crore rupees for a breach not covered by a specific entry.
The text at a glance
| Sub-section | Rule |
|---|---|
| 4(1) | A person may process the personal data of a Data Principal only (i) in accordance with the provisions of the Act, and (ii) for a lawful purpose |
| 4(1)(a) | ... for which the Data Principal has given her consent; or |
| 4(1)(b) | ... for certain legitimate uses |
| 4(2) | "Lawful purpose" means any purpose which is not expressly forbidden by law |
"A person" and "only"
Section 4(1) speaks of "a person", not only a Data Fiduciary. Since "person" in section 2(s) is wide, the rule is broad. The word "only" makes the two grounds exhaustive: if neither consent nor a section 7 use is available, the processing is not permitted under the Act.
This differs from regimes that list several legal bases. The Act has two: consent (section 6) and certain legitimate uses (section 7). A business that has been relying on contractual necessity or "business interest" must fit its processing into one of those two.
Lawful purpose: a low threshold
Section 4(2) defines lawful purpose as "any purpose which is not expressly forbidden by law". The word "expressly" matters. A purpose is not unlawful merely because no law permits it; it is unlawful only if a law expressly forbids it. This is a narrow filter, so the real limits come from the other parts of section 4(1): consent or legitimate use, and compliance with the rest of the Act.
It also means a purpose can be lawful and still fail section 4 because the ground is missing. For example, sending marketing messages is not expressly forbidden by the Act, but if there is no valid consent and no section 7 use, the processing has no ground.
Ground 1: consent
Consent under section 4(1)(a) must meet section 6: given without pressure, for a specified purpose, informed, unconditional and unambiguous, with a clear affirmative action, limited to the personal data necessary for that purpose. It must be preceded or accompanied by a notice under section 5. The Data Fiduciary bears the burden of proving notice and consent under section 6(10). See the articles on section 5 notice and section 6 consent.
Ground 2: certain legitimate uses
Section 4(1)(b) points to section 7, which lists the uses: voluntary provision for a specified purpose, State benefits, State functions and legal disclosure, court orders, medical emergencies, epidemics, disasters and employment-related purposes. No notice-and-consent step is needed for these uses in the way section 5 and 6 require, but the use must fit the wording of the clause. Section 7(a), for instance, lapses if the Data Principal has indicated that she does not consent. The three articles on section 7 in this cluster go through the clauses.
The words "in accordance with the provisions of this Act"
This phrase means the ground alone is not enough. Processing must also comply with the rest of the Act, including:
- security safeguards (section 8(5));
- accuracy where data is used for decisions or disclosed (section 8(3));
- erasure when consent is withdrawn or the purpose ends (section 8(7));
- special rules for children (section 9).
A business with valid consent that then keeps data indefinitely, or tracks children, still breaches the Act even though section 4(1)(a) was satisfied at the start.
What happens if there is no ground
The Act has no penalty entry specific to section 4. Section 33(1) lets the Board impose a monetary penalty specified in the Schedule where a breach is "significant", and entry 7 of the Schedule covers breach of any other provision of the Act or the rules, with a penalty that may extend to fifty crore rupees. Section 33(2) lists factors such as the nature, gravity and duration of the breach, and the type of data. These are covered in the article on section 33 and the article on the Schedule. The word "may extend" means fifty crore rupees is a ceiling, not a fixed amount.
Practical examples
Example 1: newsletter. A company adds customers to a marketing list because they bought once. The purchase does not amount to consent for marketing. Without a consent or a section 7 use, the marketing processing lacks a ground under section 4(1).
Example 2: receipt message. A shopper gives a phone number and asks for a receipt by message. The processing for sending the receipt is a legitimate use under section 7(a), because the purpose was voluntarily provided. Using the same number for a promotional campaign goes beyond that specified purpose.
Example 3: employer records. An employer processes payroll data of its employees. Section 7(i) allows processing for purposes of employment, so consent is not the only ground available, but the processing must still stay within that clause and the rest of the Act.
Common mistakes
- Treating "legitimate interest" or "contract" as a third ground. The text allows only consent and certain legitimate uses.
- Reading "lawful purpose" as permission. It is only a filter; a ground is still needed.
- Assuming that once consent is taken, all other duties fall away.
Need help with choosing a ground for processing?
If you handle customer, employee or vendor data and are unsure whether each activity rests on consent or a section 7 use, a mapping exercise can close the gaps before notices and forms are drafted. Reach out through our legal consultation service and we will go through your activities one by one.
Key takeaways
- Section 4(1) allows processing only in accordance with the Act and for a lawful purpose.
- The two grounds are consent (section 6) and certain legitimate uses (section 7).
- A lawful purpose is one not expressly forbidden by law.
- Compliance with the rest of the Act is part of section 4(1).
- A breach without a specific Schedule entry can attract a penalty up to fifty crore rupees.
Read next
- Section 5 of the DPDP Act, 2023: notice to Data Principal
- Section 6 of the DPDP Act, 2023: consent that is specific, informed and unambiguous
- Section 7 of the DPDP Act, 2023: voluntary provision and State benefits
- DPDP compliance checklist for businesses
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
