Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Privacy Principles

Lawful Basis for Processing

Also known as: Legal Basis for Processing, Lawful Basis, Legal Basis
Simply put

A lawful basis for processing is the legal justification an organisation must have before it collects or uses people's personal data under EU and UK data protection law. Rather than relying on a single rule, the law sets out a defined list of permitted reasons, and an organisation must identify which one applies to its activity. Simply wanting to use data is not enough; the processing must fit one of these recognised bases.

Formal definition

Under the GDPR (Regulation (EU) 2016/679) and the UK GDPR, a lawful basis is one of the enumerated grounds that must apply for the processing of personal data to be lawful, supporting the 'lawfulness, fairness and transparency' principle. The core bases for general personal data are set out in Article 6(1): consent, contract, legal obligation, vital interests, public task, and legitimate interests. The ICO's guidance for the UK GDPR describes these as seven reasons, reflecting the treatment of legitimate interests (including, in the UK regime, a category of 'recognised legitimate interest') as distinct grounds; practitioners should confirm the current enumeration against the applicable text, as the EU and UK regimes have diverged. Where consent is used, it must generally be freely given, specific, informed, and unambiguous. Note that this concept concerns the lawful basis under Article 6 and is distinct from the additional conditions required for special category data (Article 9) or criminal offence data; the appropriate basis is fact-specific and depends on the purpose, context, and category of data. This entry is informational and does not address the extra conditions, documentation, or transparency obligations attaching to each basis; verify against the current official regulation and regulator guidance.

Why it matters

Identifying a valid lawful basis is a threshold requirement under the GDPR and the UK GDPR: without one, the processing of personal data is unlawful, regardless of how carefully it is otherwise handled. The requirement flows directly from the 'lawfulness, fairness and transparency' principle, which sits at the heart of both regimes. For compliance teams, the lawful basis is not a box-ticking afterthought but a foundational decision that shapes downstream obligations, including the transparency information an organisation must provide, the individual rights that apply, and how the processing may lawfully continue or be challenged.

The choice of basis is consequential and fact-specific. Different bases attract different individual rights and different constraints; for example, where consent is relied on, it must generally be freely given, specific, informed, and unambiguous, and it can typically be withdrawn. Selecting an inappropriate basis, or switching bases after the fact, can expose an organisation to regulatory scrutiny and undermine the fairness of its processing. Because the EU and UK regimes have diverged, and because the ICO frames the position as seven reasons while the core Article 6(1) grounds are commonly described as six, organisations operating across both jurisdictions should confirm which enumeration and interpretation applies to them.

This entry addresses only the lawful basis under Article 6 for general personal data. It does not cover the separate and additional conditions that apply to special category data or criminal offence data, nor the specific documentation and transparency obligations attaching to each basis. Application to any particular processing activity requires professional judgement and verification against the current official regulation and regulator guidance.

Who it's relevant to

Data protection officers and privacy teams
Those responsible for privacy compliance must map each processing activity to an appropriate Article 6 basis and ensure the choice is consistent with the transparency information provided to individuals. Because the basis shapes which individual rights apply, this mapping is a core part of building and maintaining a defensible processing record.
Legal counsel and compliance officers
Counsel advising on data processing need to assess which basis fits a given purpose and context, particularly where organisations operate across both the EU and UK regimes, which have diverged in how the bases are framed and enumerated. The analysis is fact-specific and should be checked against the current official text rather than assumed from a single regime.
Product, marketing, and engineering teams
Teams designing data-driven products or campaigns should engage privacy specialists early, because the lawful basis must be identified before processing begins and directly affects design choices, especially where consent is relied on and must be freely given, specific, informed, and unambiguous.
Auditors and assessors
Those reviewing an organisation's data protection posture will examine whether a valid lawful basis has been identified and documented for each processing activity, and whether the basis aligns with the stated purpose and the rights afforded to individuals. This review is distinct from certifying compliance and turns on the specific facts of each activity.

Inside Lawful Basis for Processing

Legal grounds enumerated in the GDPR
Under the EU General Data Protection Regulation, processing of personal data is lawful only where at least one specified legal ground applies. These generally include consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest or in the exercise of official authority, and legitimate interests. The precise wording and conditions should be verified against the current text of the Regulation.
Consent
A legal basis requiring that agreement to processing be freely given, specific, informed, and unambiguous. Consent must generally be as easy to withdraw as to give, and reliance on it carries recordkeeping and demonstrability expectations. It is one option among several and is not inherently superior to other bases.
Contractual necessity
Processing that is necessary for the performance of a contract to which the data subject is a party, or to take steps at the data subject's request prior to entering a contract. The processing must be genuinely necessary for the contract, not merely useful or convenient.
Legal obligation
Processing necessary for compliance with a legal obligation to which the controller is subject. This generally refers to obligations arising under applicable law rather than contractual commitments, and the specific obligation should be identifiable.
Vital interests
Processing necessary to protect the vital interests of the data subject or another natural person. This basis is generally reserved for situations involving life-or-death or comparable emergencies and is narrowly applied.
Public task / official authority
Processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This basis is most relevant to public bodies and to organizations exercising functions grounded in law.
Legitimate interests
Processing necessary for the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Reliance typically involves a balancing exercise and its outcome is fact-specific. Availability of this basis may be restricted for certain actors and processing types.
Additional conditions for special category and other sensitive data
Where processing involves special categories of personal data or other data attracting heightened protection, an ordinary lawful basis alone is generally insufficient; a further specific condition must also be satisfied. Practitioners should consult the applicable provisions for the relevant category.

Common questions

Answers to the questions practitioners most commonly ask about Lawful Basis for Processing.

Is consent the only lawful basis for processing personal data under the GDPR?
No. Consent is only one of several lawful bases available under the GDPR. The Regulation sets out a number of alternative bases, which generally include the performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest, and legitimate interests. Consent is frequently over-relied upon; in many cases another basis fits the processing more appropriately and is more robust, since consent can be withdrawn. Which basis applies is fact-specific and should be assessed against the current official text and applicable guidance.
Does relying on legitimate interests mean an organisation can process data however it wants?
No. Legitimate interests is not an open-ended permission. It generally requires a balancing exercise weighing the interests pursued against the rights, freedoms, and reasonable expectations of the individuals concerned, and it may not override those interests where the impact on individuals is significant. It is also typically less suitable for certain processing, such as processing that individuals would not reasonably expect. This entry does not address the specific conditions attaching to special category data, which are handled separately under the Regulation. Application to particular circumstances requires professional judgment.
When during a project should the lawful basis be identified?
As a matter of good practice, the lawful basis is generally identified before processing begins, since it informs what information must be provided to individuals and which rights apply. Retrospectively selecting or switching a basis is generally discouraged and, in the case of consent, may not be permissible after the fact. Documenting the basis at the design stage also supports accountability. Organisations should verify sequencing expectations against current authoritative guidance for their jurisdiction.
Can an organisation switch from one lawful basis to another after processing has started?
Changing the lawful basis after processing has begun is generally difficult and often discouraged, because the original basis affects the information given to individuals and the rights they can exercise. In particular, moving away from consent to another basis to avoid honouring a withdrawal is generally not acceptable. Where a change is contemplated, organisations typically need to consider transparency obligations and whether the new basis genuinely applies. The precise position is fact-specific and should be checked against current guidance.
How should the chosen lawful basis be documented?
As part of accountability, organisations generally record which lawful basis applies to each processing activity, and this is often reflected in records of processing activities and in privacy notices provided to individuals. Where legitimate interests is relied upon, documenting the balancing assessment is commonly expected. This entry describes the practice qualitatively; the specific documentation format is not prescribed here, and organisations should confirm expectations against the current official text and supervisory authority guidance.
Does the lawful basis affect which individual rights apply?
Yes. The applicable lawful basis can influence which rights individuals may exercise. For example, certain rights such as data portability or the right to erasure may be available or constrained depending on the basis relied upon. Because the interaction between basis and rights is detailed and fact-specific, organisations should map each basis to the corresponding rights carefully and verify against the current authoritative source rather than assuming a uniform outcome.

Common misconceptions

Consent is always required to process personal data.
Consent is only one of several possible lawful bases under the GDPR. In many cases another basis, such as contractual necessity, legal obligation, or legitimate interests, is more appropriate, and relying on consent where another basis fits better can create unnecessary operational and compliance burdens.
A single lawful basis satisfies all requirements for any kind of personal data.
For special categories of personal data and certain other sensitive data, an ordinary lawful basis generally is not enough on its own; an additional specific condition must also apply. The basis and the additional condition are distinct requirements.
The concept of lawful basis for processing applies uniformly across all jurisdictions.
The enumerated legal grounds described here derive from the EU GDPR and govern processing within its scope, including its extraterritorial reach in defined circumstances. Other jurisdictions, such as the United States or the United Kingdom, may frame the lawfulness of processing differently, and their requirements should be assessed separately against the applicable law.

Best practices

Identify and document the specific lawful basis for each processing activity before processing begins, rather than assigning one retrospectively.
Where legitimate interests is relied upon, carry out and record a balancing assessment weighing the interest against the data subject's rights and freedoms.
Avoid defaulting to consent; assess whether contractual necessity, legal obligation, or another basis more accurately reflects the processing and its context.
For special category or otherwise sensitive data, confirm both an ordinary lawful basis and an applicable additional condition, and record both.
Maintain records that demonstrate how each basis was selected, as accountability expectations generally require the ability to justify the choice.
Verify the enumerated grounds, conditions, and any restrictions against the current official text of the Regulation and relevant regulator guidance, since interpretations evolve and provisions are periodically amended; apply to specific circumstances only with appropriate professional judgment.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.