Section 7 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
The last four legitimate uses in section 7 deal with urgent or work-related situations. Clause (f) covers a medical emergency, clause (g) covers health services during an epidemic or public health threat, clause (h) covers safety and assistance during a disaster or breakdown of public order, and clause (i) covers employment and protecting the employer from loss or liability. Together they let a Data Fiduciary process personal data without a consent request.
Personal data may be processed without a consent request (f) to respond to a medical emergency involving a threat to life or immediate threat to health of the Data Principal or any other individual; (g) to provide medical treatment or health services during an epidemic, outbreak or other public health threat; (h) to ensure safety or provide assistance during a disaster or breakdown of public order; and (i) for purposes of employment or safeguarding the employer from loss or liability, including providing a service or benefit sought by an employee.
Clauses (f) to (i) at a glance
| Clause | Situation | Wording to note |
|---|---|---|
| 7(f) | Medical emergency | "threat to the life or immediate threat to the health of the Data Principal or any other individual" |
| 7(g) | Epidemic, outbreak of disease or any other threat to public health | "measures to provide medical treatment or health services to any individual" |
| 7(h) | Disaster or breakdown of public order | "measures to ensure safety of, or provide assistance or services to, any individual"; "disaster" as in section 2(d) of the Disaster Management Act, 2005 |
| 7(i) | Employment | "purposes of employment or those related to safeguarding the employer from loss or liability", with examples; includes services or benefits sought by an employee |
Clause (f): medical emergency
Clause (f) applies to "responding to a medical emergency involving a threat to the life or immediate threat to the health of the Data Principal or any other individual". Two features matter.
- The patient need not be the Data Principal. The clause covers a threat to the Data Principal "or any other individual". Personal data of one person may be processed to help another in an emergency, for example sharing a blood group to save someone else.
- The threat is acute. The text speaks of a threat to life or an immediate threat to health. Routine care does not fit; it would need consent or another clause.
The clause is about responding to the emergency. Once the emergency has passed, the legitimate use no longer supports continued processing for unrelated purposes. Section 8(7) then requires erasure once the purpose is no longer served, unless retention is necessary for compliance with law.
Clause (g): epidemics and public health
Clause (g) allows processing "for taking measures to provide medical treatment or health services to any individual during an epidemic, outbreak of disease, or any other threat to public health". It is wider in time than clause (f), because a public health threat can last a long time, but it is tied to measures for treatment or health services. The text does not authorise unrelated use of the data collected during such a period.
Clause (h): disaster and breakdown of public order
Clause (h) covers "taking measures to ensure safety of, or provide assistance or services to, any individual during any disaster, or any breakdown of public order". The Explanation says "disaster" has the meaning in section 2(d) of the Disaster Management Act, 2005. "Breakdown of public order" is not defined in the Act, so read it in its ordinary sense.
Note that the clause speaks of measures to ensure safety or provide assistance, so a relief agency or a business supporting evacuation may process contact details or location to do so. The clause is not limited to the State, so a private Data Fiduciary may also use it if it is taking such measures.
Clause (i): employment
Clause (i) is the one most businesses will rely on daily. It allows processing "for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee".
Three parts can be separated.
- Purposes of employment. Recruitment decisions, payroll, attendance, performance management and similar functions fit, because they are for the purposes of employment.
- Safeguarding the employer from loss or liability. The examples given are prevention of corporate espionage and maintenance of confidentiality of trade secrets, intellectual property and classified information. The word "such as" makes the list illustrative.
- Services or benefits sought by an employee. If an employee asks for a benefit, for example health insurance enrolment or a loan from the employer, processing her data for that purpose fits.
Limits of clause (i)
The clause says "for the purposes of employment or those related to safeguarding the employer". It does not say the employer may process any data about the employee for any reason. Processing that has nothing to do with employment or loss prevention, such as using employee data for marketing, is outside it. The use must also stay within the rest of the Act: section 8 duties on accuracy, security, breach intimation and erasure still apply to employee data, unless section 17 removes them.
The clause refers to "a Data Principal who is an employee". It does not define "employee", and does not address contractors, candidates who were not hired, or former employees. For those groups, check whether the purpose still fits "purposes of employment", or use consent. See our employment and labour law advisory work for how HR processes are typically mapped.
Practical examples
Example 1: road accident. An unconscious person is brought to a hospital. The hospital contacts her family using the number in her phone, and shares her medical history with the treating team. Clause (f) supports this.
Example 2: flood relief. A relief organisation collects names and locations of stranded residents to send boats and supplies. This fits clause (h), as the flood is a disaster under the Disaster Management Act, 2005.
Example 3: payroll and monitoring. A company uses employee bank details for salary and logs access to confidential design files to prevent leakage of trade secrets. Both fit clause (i). Using the same employee data for an unrelated promotion does not.
Common mistakes
- Using clause (f) for routine treatment rather than an emergency.
- Continuing to hold data collected in an emergency after the emergency has passed.
- Treating clause (i) as a general licence to process any employee data.
- Forgetting that section 8 still applies to employee data.
Need help with employee data and HR policies under the DPDP Act?
If your HR team processes recruitment, payroll, monitoring and benefits data, it helps to record which activities rest on section 7(i) and which still need consent. Our employment and labour law advisory team can help you align HR policies, employee notices and records with the Act.
Key takeaways
- Clause (f) allows processing to respond to a medical emergency threatening life or health of any individual.
- Clause (g) supports treatment and health services during an epidemic or public health threat.
- Clause (h) supports safety and assistance during a disaster or breakdown of public order.
- Clause (i) covers purposes of employment, safeguarding the employer from loss or liability, and benefits sought by an employee.
- Section 8 duties still apply to these uses.
Read next
- Section 7 of the DPDP Act, 2023: legal obligations, courts and State functions
- Section 7 of the DPDP Act, 2023: voluntary provision and State benefits
- Section 8 of the DPDP Act, 2023: erasure and retention of personal data
- DPDP Act for healthcare and pharma
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
