Glossary | GDPR & Data Privacy

Lawful Basis for Processing

What is a Lawful Basis for Processing?

A lawful basis for processing is the legal justification that permits an organisation to collect and use personal data under Regulation (EU) 2016/679 (GDPR). Before processing any personal data, a Data Controller must identify and document a valid lawful basis. Processing personal data without one is a breach of the GDPR.

Why It Matters

The GDPR prohibits the processing of personal data unless a lawful basis applies. This requirement sits at the heart of data protection compliance — every collection, use, sharing, or storage of personal data must be justified by one of the six lawful bases set out in the regulation.

Choosing the correct lawful basis is not simply a box-ticking exercise. It determines what rights data subjects can exercise, what obligations the controller must meet, and how the organisation must respond if individuals object to their data being processed. Getting this wrong can expose a business to enforcement action and undermine the validity of its entire data processing framework.

For businesses of all sizes, identifying and documenting a lawful basis for each processing activity is a fundamental step in GDPR compliance.

What is a Lawful Basis for Processing?

Key Requirements

What Are the Six Lawful Bases?

Under the GDPR, personal data may only be processed where one of the following lawful bases applies:

  • Consent – The data subject has given clear, freely given, specific, informed, and unambiguous consent to the processing.
  • Contract – Processing is necessary for the performance of a contract with the data subject, or to take steps at their request before entering a contract.
  • Legal Obligation – Processing is necessary to comply with a legal obligation to which the controller is subject.
  • Vital Interests – Processing is necessary to protect the vital interests of the data subject or another person.
  • Public Task – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
  • Legitimate Interests – Processing is necessary for the legitimate interests of the controller or a third party, except where those interests are overridden by the interests or rights of the data subject.

This requirement applies under:

Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR), Article 6

Responsibilities Relating to Lawful Basis

Data Controllers are responsible for meeting obligations that commonly include:

  • Identifying and documenting a lawful basis before processing begins
  • Communicating the lawful basis to data subjects in a privacy notice
  • Applying the most appropriate basis for each specific processing activity
  • Carrying out a balancing test where legitimate interests is relied upon
  • Ensuring consent is obtained in a manner that meets GDPR standards where consent is the chosen basis
  • Reviewing and updating lawful bases where processing activities change

Lawful Basis and Data Subject Rights

The lawful basis relied upon directly affects the rights available to data subjects. For example, where consent is the lawful basis, data subjects have the right to withdraw that consent at any time. Where legitimate interests are relied upon, data subjects have the right to object to the processing. Controllers must be aware of these implications when selecting their lawful basis.

Frequently Asked Questions

Generally, a single lawful basis should be identified for each processing activity. Switching between bases after the fact is not permitted. However, different activities within the same organisation may rely on different lawful bases.

No. Consent is one of six lawful bases and is not always the most appropriate choice. In many cases, contract performance or legitimate interests may be more suitable and more straightforward to rely upon.

Processing personal data without a valid lawful basis is a breach of the GDPR and can result in enforcement action by supervisory authorities, including fines of up to €20 million or 4% of total global annual turnover, whichever is higher.

Need GDPR Representative Services?

Euverify provides EU Representative services for organisations outside the European Union that are subject to the GDPR. Our team supports regulatory communication, documentation, and ongoing compliance management.