skip to content

Lawful Bases for Processing

Every processing activity needs one of six bases, and consent is only one of them — contract, legal obligation and legitimate interests carry most real workloads. Interviewers ask you to pick and justify a basis, since defaulting to consent for everything is the common mistake.

part ofCompliance & governance standardsoverview, primer and where to startread it →
on this pageshow

questions

6

Under GDPR Art. 6(1), what are the six lawful bases for processing, and why is consent not the default?

level: juniorimportance: must knowfreq 74%

answer

  1. at least one must apply
  2. no hierarchy among them
  3. consent can be withdrawn
  4. decided before processing starts

basics

~20 s

GDPR Art. 6(1) lists consent, contract, legal obligation, vital interests, public task and legitimate interests. None ranks above the others; consent fits only when the person has a real choice, because it can be withdrawn and processing must then stop.

solid answer

~50 s

Under GDPR `Art. 6(1)`, processing is lawful only if and to the extent that at least one basis applies: **(a) consent**, **(b) necessity for a contract** with the data subject or pre-contract steps at their request, **(c) a legal obligation** of the controller, **(d) vital interests** of the data subject or another person, **(e) a public task** or official authority, and **(f) legitimate interests**, unless overridden by the data subject's interests or rights. The text sets no hierarchy. Consent is not a safe default: it fits only when the person has a genuine choice, it can be withdrawn and the processing built on it must then stop, and EDPB guidance says a controller cannot swap to another basis later to rescue it. The basis must be chosen per purpose before processing begins, recorded, and disclosed in the privacy notice (`Art. 13(1)(c)`).

go deeper

for a junior

Recall the six bases in Art. 6(1), and that at least one must apply to each purpose. Know that consent is one option among six, not the default.

for a middle

Explain why five bases require necessity, why (c) and (e) need a law under Art. 6(3), and why consent's withdrawability makes it a poor fit for essential processing.

for a senior

Show the procedure: split by purpose, test specific bases first, document the decision, disclose it under Art. 13(1)(c), and never plan to swap bases later.

for a principal

Set the organisation's rule that a lawful basis is decided per purpose at design time and recorded, so products do not default to consent banners that cannot carry core processing.

## What Art. 6 requires The GDPR (Regulation (EU) 2016/679) makes every processing of personal data unlawful unless it has a **lawful basis**. `Art. 6(1)` says processing is lawful *only if and to the extent that at least one* of six conditions applies. Two words in that sentence matter: - **"at least one"**: a processing purpose needs a basis; it does not need all of them, and there is no ranking. - **"to the extent that"**: the basis covers the processing only as far as its conditions reach. Data beyond what is necessary for a contract are not covered by the contract basis just because some data are. ## The six bases | Point | Basis | Key condition in the text | |---|---|---| | `6(1)(a)` | **Consent** | The data subject has consented for one or more specific purposes | | `6(1)(b)` | **Contract** | Necessary to perform a contract the data subject is party to, or for steps at their request before entering one | | `6(1)(c)` | **Legal obligation** | Necessary to comply with a legal obligation the controller is subject to | | `6(1)(d)` | **Vital interests** | Necessary to protect the vital interests of the data subject or another natural person | | `6(1)(e)` | **Public task** | Necessary for a task in the public interest or in the exercise of official authority vested in the controller | | `6(1)(f)` | **Legitimate interests** | Necessary for legitimate interests of the controller or a third party, unless overridden by the data subject's interests or rights, in particular where the data subject is a child | Several conditions follow from the rest of the Article: - **Five of the six require necessity.** Every basis except consent says *necessary for*. Convenience or usefulness is not necessity. - **Points (c) and (e) need a law.** `Art. 6(3)` requires the basis for them to be laid down in Union or Member State law. - **Public authorities cannot use (f)** for processing in the performance of their tasks (the subparagraph after `Art. 6(1)(f)`). - **Vital interests is narrow.** Recital 46 says processing based on the vital interest of *another* person should in principle take place only where no other basis manifestly applies. ## Why consent is not the default Engineers often assume that asking for consent is the safest option. Under the GDPR it frequently is not: 1. **Consent must be genuine.** Recital 43 says consent is not a valid ground where there is a clear imbalance between the data subject and the controller, and Recital 42 says it is not freely given if the person cannot refuse or withdraw without detriment. The detailed validity conditions are a subject of their own. 2. **Consent can be withdrawn.** When someone withdraws, the processing based on it must stop. Building an essential function, such as delivering an order or paying wages, on something the person can switch off makes the system fragile. 3. **You cannot swap later.** EDPB Guidelines 05/2020 on consent (paras. 122-123) say a controller relying on consent cannot retrospectively switch to legitimate interests when problems with the consent emerge, because it told people at collection which basis it relied on. 4. **Another basis often fits better.** Delivering a purchase is necessary for a contract; filing tax records is a legal obligation; screening for fraud can be a legitimate interest (Recital 47). Asking for consent there misdescribes the processing. ## Choosing and documenting a basis A defensible choice follows a short procedure: 1. **Split processing by purpose.** One system can have several purposes, each with its own basis. 2. **Test the specific bases first.** Is it genuinely necessary for the contract? Required by a law? Only then weigh legitimate interests or consent. 3. **Record the decision.** `Art. 5(2)` makes the controller responsible for, and able to demonstrate, lawfulness; a legitimate-interests choice needs a documented assessment. 4. **Tell people.** `Art. 13(1)(c)` requires the legal basis to be disclosed when data are collected from the data subject, and `Art. 13(1)(d)` requires the legitimate interests pursued where (f) is used. 5. **Decide before processing starts.** EDPB guidance says the basis must be established prior to the processing and in relation to a specific purpose. ## Special categories need more If the data fall into the special categories listed in `Art. 9(1)`, an `Art. 6` basis is necessary but not sufficient: one of the `Art. 9(2)` conditions must also apply. ## Common mistakes - Treating consent as the "gold standard" basis for everything. - Listing several bases "just in case" for one purpose, which makes the notice misleading and the rights that follow unclear. - Using the contract basis for anything mentioned in the terms of service. - Believing legitimate interests is a free-for-all because it has no form to sign.

  • Under the GDPR, can a controller list several lawful bases for one purpose to be safe?
    It should pick the basis that actually fits each purpose. The basis decides which rights apply, for instance the `Art. 21(1)` objection right attaches to processing based on (e) or (f), and `Art. 13(1)(c)` requires it to be disclosed. EDPB guidance on consent adds that a controller cannot swap from consent to another basis later, so hedging with a vague list undermines transparency rather than adding safety.
  • Under GDPR Art. 6(1), which bases require a legal text outside the GDPR itself?
    Points (c), legal obligation, and (e), public task. `Art. 6(3)` says the basis for them must be laid down by Union law or by Member State law to which the controller is subject, and that law must meet an objective of public interest and be proportionate. A controller cannot invoke (c) for an obligation that exists only in its own contracts or policies.
  • Under the GDPR, when may a public authority rely on legitimate interests?
    Not for processing carried out in the performance of its tasks: the subparagraph after `Art. 6(1)(f)` excludes it, and Recital 47 explains that the legislator should provide their basis by law. Such processing normally rests on (c) or (e). Processing outside its public tasks is not caught by that exclusion.

Choosing a lawful basis is like choosing the right key for a lock: several keys exist, each cut for a particular door, and a key labelled consent is a poor fit for a door that must stay open, because its holder can take it back at any moment.

saying these in an interview costs you the question

  • Consent is the strongest lawful basis and should be used whenever possible.
  • The GDPR ranks the six bases, and consent must be tried first.
  • A controller can switch from consent to legitimate interests if consent turns out invalid.
  • Anything written into the terms of service is covered by the contract basis.
  • Every processing activity needs all six conditions checked and satisfied.
open as a page

Under GDPR Art. 6(1)(f), how does a bank justify fraud-screening card payments on legitimate interests, and what must it record?

level: middleimportance: must knowfreq 60%

basics

~20 s

Under GDPR Art. 6(1)(f), the bank must show a legitimate interest (Recital 47 names fraud prevention), that the screening is necessary for it, and that customers' interests and rights do not override it, and document that assessment before screening starts.

open as a page

Under GDPR Art. 6(1)(b), can an online shop rely on contract necessity to use past purchases for product recommendations?

level: middleimportance: should knowfreq 50%

basics

~20 s

Usually not. Under GDPR Art. 6(1)(b), processing must be objectively necessary to perform the contract. A shop can sell and deliver without recommendations, so EDPB guidance treats that personalisation as outside the contract basis; another basis must carry it.

open as a page

Under the GDPR, a fitness app stores users' heart-rate data; why is an Art. 6 lawful basis alone not enough?

level: middleimportance: should knowfreq 48%

basics

~20 s

Heart-rate readings are data concerning health, a special category that GDPR Art. 9(1) prohibits processing by default. The app needs both an Art. 6(1) basis and one of the Art. 9(2) conditions, for a consumer app typically explicit consent under Art. 9(2)(a).

open as a page

Under GDPR Art. 6(4), can an online shop reuse order data collected for fulfilment to build sales analytics without a new basis?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Under GDPR Art. 6(4), reuse is allowed if the new purpose is compatible with the original, judged on the link, context, data nature, consequences and safeguards. Aggregate sales analytics usually passes; using the history to target individuals needs its own assessment.

open as a page

Under the GDPR, which lawful basis can an employer use to monitor staff laptops, and why does employee consent rarely work?

level: seniorimportance: should knowfreq 42%

basics

~20 s

Under the GDPR, employee consent is rarely valid because refusing an employer is risky (Recital 43; EDPB Guidelines 05/2020). Laptop monitoring usually rests on legitimate interests such as security, after documented necessity and balancing, or on a legal obligation.

open as a page