skip to content

Under GDPR Art. 6(1), what are the six lawful bases for processing, and why is consent not the default?

level: juniorimportance: must knowfreq 74%

answer

  1. at least one must apply
  2. no hierarchy among them
  3. consent can be withdrawn
  4. decided before processing starts

basics

~20 s

GDPR Art. 6(1) lists consent, contract, legal obligation, vital interests, public task and legitimate interests. None ranks above the others; consent fits only when the person has a real choice, because it can be withdrawn and processing must then stop.

solid answer

~50 s

Under GDPR `Art. 6(1)`, processing is lawful only if and to the extent that at least one basis applies: **(a) consent**, **(b) necessity for a contract** with the data subject or pre-contract steps at their request, **(c) a legal obligation** of the controller, **(d) vital interests** of the data subject or another person, **(e) a public task** or official authority, and **(f) legitimate interests**, unless overridden by the data subject's interests or rights. The text sets no hierarchy. Consent is not a safe default: it fits only when the person has a genuine choice, it can be withdrawn and the processing built on it must then stop, and EDPB guidance says a controller cannot swap to another basis later to rescue it. The basis must be chosen per purpose before processing begins, recorded, and disclosed in the privacy notice (`Art. 13(1)(c)`).

go deeper

for a junior

Recall the six bases in Art. 6(1), and that at least one must apply to each purpose. Know that consent is one option among six, not the default.

for a middle

Explain why five bases require necessity, why (c) and (e) need a law under Art. 6(3), and why consent's withdrawability makes it a poor fit for essential processing.

for a senior

Show the procedure: split by purpose, test specific bases first, document the decision, disclose it under Art. 13(1)(c), and never plan to swap bases later.

for a principal

Set the organisation's rule that a lawful basis is decided per purpose at design time and recorded, so products do not default to consent banners that cannot carry core processing.

## What Art. 6 requires The GDPR (Regulation (EU) 2016/679) makes every processing of personal data unlawful unless it has a **lawful basis**. `Art. 6(1)` says processing is lawful *only if and to the extent that at least one* of six conditions applies. Two words in that sentence matter: - **"at least one"**: a processing purpose needs a basis; it does not need all of them, and there is no ranking. - **"to the extent that"**: the basis covers the processing only as far as its conditions reach. Data beyond what is necessary for a contract are not covered by the contract basis just because some data are. ## The six bases | Point | Basis | Key condition in the text | |---|---|---| | `6(1)(a)` | **Consent** | The data subject has consented for one or more specific purposes | | `6(1)(b)` | **Contract** | Necessary to perform a contract the data subject is party to, or for steps at their request before entering one | | `6(1)(c)` | **Legal obligation** | Necessary to comply with a legal obligation the controller is subject to | | `6(1)(d)` | **Vital interests** | Necessary to protect the vital interests of the data subject or another natural person | | `6(1)(e)` | **Public task** | Necessary for a task in the public interest or in the exercise of official authority vested in the controller | | `6(1)(f)` | **Legitimate interests** | Necessary for legitimate interests of the controller or a third party, unless overridden by the data subject's interests or rights, in particular where the data subject is a child | Several conditions follow from the rest of the Article: - **Five of the six require necessity.** Every basis except consent says *necessary for*. Convenience or usefulness is not necessity. - **Points (c) and (e) need a law.** `Art. 6(3)` requires the basis for them to be laid down in Union or Member State law. - **Public authorities cannot use (f)** for processing in the performance of their tasks (the subparagraph after `Art. 6(1)(f)`). - **Vital interests is narrow.** Recital 46 says processing based on the vital interest of *another* person should in principle take place only where no other basis manifestly applies. ## Why consent is not the default Engineers often assume that asking for consent is the safest option. Under the GDPR it frequently is not: 1. **Consent must be genuine.** Recital 43 says consent is not a valid ground where there is a clear imbalance between the data subject and the controller, and Recital 42 says it is not freely given if the person cannot refuse or withdraw without detriment. The detailed validity conditions are a subject of their own. 2. **Consent can be withdrawn.** When someone withdraws, the processing based on it must stop. Building an essential function, such as delivering an order or paying wages, on something the person can switch off makes the system fragile. 3. **You cannot swap later.** EDPB Guidelines 05/2020 on consent (paras. 122-123) say a controller relying on consent cannot retrospectively switch to legitimate interests when problems with the consent emerge, because it told people at collection which basis it relied on. 4. **Another basis often fits better.** Delivering a purchase is necessary for a contract; filing tax records is a legal obligation; screening for fraud can be a legitimate interest (Recital 47). Asking for consent there misdescribes the processing. ## Choosing and documenting a basis A defensible choice follows a short procedure: 1. **Split processing by purpose.** One system can have several purposes, each with its own basis. 2. **Test the specific bases first.** Is it genuinely necessary for the contract? Required by a law? Only then weigh legitimate interests or consent. 3. **Record the decision.** `Art. 5(2)` makes the controller responsible for, and able to demonstrate, lawfulness; a legitimate-interests choice needs a documented assessment. 4. **Tell people.** `Art. 13(1)(c)` requires the legal basis to be disclosed when data are collected from the data subject, and `Art. 13(1)(d)` requires the legitimate interests pursued where (f) is used. 5. **Decide before processing starts.** EDPB guidance says the basis must be established prior to the processing and in relation to a specific purpose. ## Special categories need more If the data fall into the special categories listed in `Art. 9(1)`, an `Art. 6` basis is necessary but not sufficient: one of the `Art. 9(2)` conditions must also apply. ## Common mistakes - Treating consent as the "gold standard" basis for everything. - Listing several bases "just in case" for one purpose, which makes the notice misleading and the rights that follow unclear. - Using the contract basis for anything mentioned in the terms of service. - Believing legitimate interests is a free-for-all because it has no form to sign.

  • Under the GDPR, can a controller list several lawful bases for one purpose to be safe?
    It should pick the basis that actually fits each purpose. The basis decides which rights apply, for instance the `Art. 21(1)` objection right attaches to processing based on (e) or (f), and `Art. 13(1)(c)` requires it to be disclosed. EDPB guidance on consent adds that a controller cannot swap from consent to another basis later, so hedging with a vague list undermines transparency rather than adding safety.
  • Under GDPR Art. 6(1), which bases require a legal text outside the GDPR itself?
    Points (c), legal obligation, and (e), public task. `Art. 6(3)` says the basis for them must be laid down by Union law or by Member State law to which the controller is subject, and that law must meet an objective of public interest and be proportionate. A controller cannot invoke (c) for an obligation that exists only in its own contracts or policies.
  • Under the GDPR, when may a public authority rely on legitimate interests?
    Not for processing carried out in the performance of its tasks: the subparagraph after `Art. 6(1)(f)` excludes it, and Recital 47 explains that the legislator should provide their basis by law. Such processing normally rests on (c) or (e). Processing outside its public tasks is not caught by that exclusion.

Choosing a lawful basis is like choosing the right key for a lock: several keys exist, each cut for a particular door, and a key labelled consent is a poor fit for a door that must stay open, because its holder can take it back at any moment.

saying these in an interview costs you the question

  • Consent is the strongest lawful basis and should be used whenever possible.
  • The GDPR ranks the six bases, and consent must be tried first.
  • A controller can switch from consent to legitimate interests if consent turns out invalid.
  • Anything written into the terms of service is covered by the contract basis.
  • Every processing activity needs all six conditions checked and satisfied.