Under GDPR Art. 6(1)(b), can an online shop rely on contract necessity to use past purchases for product recommendations?
answer
- useful is not necessary
- what did the customer contract for
- objectively necessary, less intrusive options
- EDPB Guidelines 2/2019
basics
~20 sUsually not. Under GDPR Art. 6(1)(b), processing must be objectively necessary to perform the contract. A shop can sell and deliver without recommendations, so EDPB guidance treats that personalisation as outside the contract basis; another basis must carry it.
solid answer
~50 sUnder GDPR `Art. 6(1)(b)`, processing is lawful when it is **necessary for the performance of a contract** with the data subject, or for steps at their request before one. EDPB Guidelines 2/2019 read "necessary" strictly: it means **objectively necessary** for the service the person contracted for, not useful for the controller's business, and not merely written into the terms. If a realistic, less intrusive way to perform the contract exists, the processing is not necessary. A shop's contract is to sell and deliver goods, which it can do without profiling past purchases; the guidelines give an almost identical marketplace example and conclude that personalised suggestions cannot rely on (b). Processing the delivery address or payment details, by contrast, is necessary. The recommendation feature therefore needs another basis, typically legitimate interests or consent, chosen and disclosed before it runs.
go deeper
Recall that Art. 6(1)(b) covers processing necessary to deliver what the person contracted for, such as the delivery address, not everything the business would like to do.
Explain objective necessity and the less-intrusive-alternative test from EDPB Guidelines 2/2019, and apply it purpose by purpose to a shop's processing.
Distinguish a service whose promise is personalisation from one where it is an add-on, using the para. 57 factors, and name the basis that should carry the add-on.
Stop product teams from routing growth features through the contract basis; require a per-purpose basis decision before features that reuse purchase data ship.
## What Art. 6(1)(b) actually says `Art. 6(1)(b)` of the GDPR makes processing lawful where it is *necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract*. Recital 44 repeats that processing should be lawful where necessary in the context of a contract. Two conditions are built in: - **A contract with the data subject.** The person whose data are processed must be party to it, or be asking for pre-contract steps. - **Necessity.** The processing must be necessary to perform *that* contract. ## How the EDPB reads "necessary" EDPB Guidelines 2/2019 on `Art. 6(1)(b)` in the context of online services (regulator guidance, not the statute) set the reading used in practice: 1. **Objective necessity.** Processing must be *objectively necessary* for the performance of the contract (para. 22). 2. **An independent meaning.** Necessity is not simply what is permitted by or written into the contract (para. 23). 3. **Less intrusive alternatives defeat it.** If there are realistic, less intrusive alternatives, the processing is not necessary; (b) does not cover processing that is *useful but not objectively necessary*, even if necessary for the controller's other business purposes (para. 25). 4. **Small print does not help.** Merely mentioning processing in a contract is not enough (para. 27); the guidelines endorse earlier guidance that the basis must be interpreted strictly and does not cover processing unilaterally imposed on the data subject (para. 28). ## Applying it to an online shop Map each processing purpose against what the customer actually contracted for, which is buying and receiving goods: | Processing | Necessary to perform the purchase contract? | |---|---| | Delivery address to ship the order | Yes | | Payment details to take payment | Yes | | Order history shown in the customer's account for returns and invoices | Generally yes | | Profiling past purchases to recommend other products | Generally no | | Engagement metrics to improve the site | Generally no (paras. 48-49) | | Fraud screening of orders | Generally no under (b); may be legitimate interests or a legal obligation (para. 50) | The guidelines contain two near-identical examples. **Example 7**: a hotel search engine profiles past bookings to recommend hotels; the profiling is not objectively necessary, so (b) does not apply. **Example 8**: an online marketplace wants to show personalised product suggestions based on previously viewed listings; that personalisation *is not objectively necessary to provide the marketplace service* and cannot rely on (b). ## When personalisation can be necessary The guidelines do not say personalisation never fits (b). Para. 57 accepts that personalisation *may* be an intrinsic and expected element of some online services, depending on: - the **nature of the service** provided; - the **expectations of the average data subject**, in light of the terms and of how the service is promoted; - whether the service **can be provided without** personalisation. A service whose whole promise is a curated selection built for each subscriber is a different case from a shop that adds a "you may also like" row to raise basket size. ## What to do instead If (b) does not fit, the shop needs another basis for the recommendation feature: - **Legitimate interests (`Art. 6(1)(f)`)**, which requires identifying the interest, showing necessity and passing the balancing test, documented; Recital 47 notes that direct marketing *may* be regarded as a legitimate interest, and `Art. 21(2)` gives an unconditional right to object to direct marketing. - **Consent (`Art. 6(1)(a)`)**, where the processing is intrusive enough that the balance would fail. Whichever basis is chosen must be decided before the processing starts and disclosed at collection (`Art. 13(1)(c)`). If recommendations also rely on reading from or storing information on the user's device, separate device-access rules apply on top. ## Why interviewers ask this The question separates candidates who treat "it is in our terms" as a lawful basis from those who can test necessity against the service actually contracted for. The correct answer is rarely "never"; it is "not for this purpose, and here is why, and here is what carries it instead".
- Under GDPR Art. 6(1)(b), can a shop process a would-be customer's data before any contract exists?Yes, for steps taken at the data subject's request before entering into a contract, such as preparing a quote the person asked for or checking delivery to their postcode. The request must come from the data subject; unsolicited marketing to prospects is not a pre-contract step under (b).
- Under EDPB Guidelines 2/2019, does adding the recommendation processing to the terms of service make it necessary?No. The guidelines say merely referencing processing in a contract does not bring it within (b), and endorse the view that the basis must be interpreted strictly and does not cover processing unilaterally imposed on the data subject. Necessity has an independent meaning tested against the service contracted for, not against the wording of the terms.
saying these in an interview costs you the question
- If the terms of service mention the processing, the contract basis covers it.
- Anything that improves the customer's experience is necessary for the contract.
- Personalisation can never be necessary for any online service.
- The contract basis covers profiling as long as the customer has placed an order.
- Fraud screening of orders is automatically necessary for performing the sale.