Skip to main content
ExplainerGDPR ComplianceExplainer· 5 min read· in Technology

The Legal Bases for Processing Personal Data Under GDPR

Under the General Data Protection Regulation, organizations cannot legally process personal data without establishing one of six specific lawful bases. Understanding the distinction between consent, legitimate interests, and contractual necessity defines the boundary between compliant operations and severe regulatory penalties.

By Elena Castillo

Privacy Advocates 35%Commercial Operators 35%Regulatory Authorities 30%
Privacy Advocates
Argue that explicit, informed consent should be the default mechanism for all non-essential data processing.
Commercial Operators
Rely heavily on legitimate interests and contractual necessity to maintain seamless user experiences without constant consent interruptions.
Regulatory Authorities
Focus on strict adherence to the definitions, requiring extensive documentation and balancing tests to prevent the abuse of flexible bases.

Perspectives this story doesn't cover

  • Small Business Owners
  • Open Source Developers

Why it matters

Every digital interaction, from opening an app to completing a purchase, relies on one of these legal bases to function legally. Misclassifying how data is processed exposes organizations to massive fines and forces them to delete entire datasets, directly impacting product viability.

Privacy advocates argue that explicit user consent is the only legitimate mechanism for processing personal data, demanding that individuals actively opt in before their information is touched. Commercial data brokers and marketing platforms counter that requiring active consent for every background operation would break the modern internet, relying instead on "legitimate interests" to justify passive data collection.[7]

Between these two absolute positions lies the actual framework of the General Data Protection Regulation (GDPR). Adopted in 2016 and enforced since May 2018, the regulation does not mandate consent for everything. Instead, Article 6 of the GDPR outlines six primary lawful bases for processing personal data, with a seventh often practically derived from the strict conditions applied to special category data under Article 9.[1][7]

Understanding these bases is not merely an academic legal exercise. The distinction between relying on a user's consent versus a company's legitimate interest defines the boundary between compliant operations and severe regulatory penalties, which can reach €20 million or 4% of a company's global annual turnover.[1]

The most recognized basis is Consent, defined under Article 6(1)(a). The European Commission explicitly requires this to be a "freely given, specific, informed and unambiguous" indication of the user's wishes. However, the technology industry frequently overuses consent, presenting users with exhaustive cookie banners that induce fatigue rather than genuine choice.[4]

The six primary lawful bases established by Article 6 of the General Data Protection Regulation.

When consent is withdrawn, processing must stop immediately. This fragility makes it highly unappealing for core business operations. As the Data Protection Commission (DPC) guidance notes, organizations should not rely on consent if there is a clear imbalance of power, such as in an employment context, because the consent cannot be considered freely given.[2]

The second basis is Contractual Necessity, found in Article 6(1)(b). This applies when processing is required to fulfill a contract with the individual. If a user purchases a physical product, the vendor does not need consent to process their shipping address; the processing is strictly necessary to deliver the goods.[1][3]

Companies often stretch this definition to cover behavioral tracking, claiming it is necessary to provide a "personalized" service. The European Data Protection Board (EDPB) explicitly rejected this in its Guidelines 2/2019, stating that processing must be objectively necessary for a purpose that is integral to the delivery of that specific service, not merely useful for the provider's business model.[3]

Companies often stretch this definition to cover behavioral tracking, claiming it is necessary to provide a "personalized" service.

The third basis is Legal Obligation under Article 6(1)(c). This covers scenarios where an organization is mandated by law to process data, such as retaining employee tax records or performing anti-money laundering checks. The processing is justified by statutory requirements rather than user preference or commercial desire.[1][4]

Vital Interests, outlined in Article 6(1)(d), serves as an emergency provision. It applies when processing is necessary to protect someone's life. If a hospital admits an unconscious patient, they do not need consent to access medical records. This basis is narrowly construed and rarely applies to standard commercial technology operations.[1]

Public Task, located in Article 6(1)(e), is utilized primarily by government entities and public authorities. It permits data processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.[1][4]

The most contested and flexible basis is Legitimate Interests, defined in Article 6(1)(f). This allows processing if the organization has a valid reason that is not overridden by the individual's rights and freedoms. It is the engine driving much of the modern data economy, from fraud prevention to direct marketing.[1][5]

Because it does not require active user consent, Legitimate Interests is highly attractive to technology firms. However, it requires a documented Legitimate Interests Assessment (LIA) comprising a three-part test: identifying the interest, showing the processing is necessary to achieve it, and balancing it against the individual's rights.[2][6]

Organizations relying on Legitimate Interests must document a three-part balancing test before processing begins.

Recent regulatory movements have targeted the abuse of this basis. As noted by legal analysts at JD Supra, the EDPB has issued updated guidelines tightening how legitimate interests can be applied, particularly emphasizing that commercial interests do not automatically trump user privacy expectations.[5]

Similarly, the UK's Information Commissioner's Office (ICO) has drafted specific guidance on legitimate interests, reinforcing that organizations cannot use it as a default fallback when consent is too difficult to obtain. The RPC analysis highlights that the balancing test must be rigorous and documented before any processing begins.[6]

The "seventh" basis often discussed in compliance circles refers to the explicit exceptions required for processing Special Category Data under Article 9. This includes race, biometrics, and health data. For these categories, standard Article 6 bases are insufficient unless paired with a specific Article 9 condition, such as explicit consent or substantial public interest.[7]

The technology industry's shift toward agentic AI and automated processing complicates these bases further. When an AI agent scrapes data to train a model, determining whether that constitutes a legitimate interest or requires explicit consent remains a heavily litigated frontier across European courts.[7]

The GDPR's framework forces organizations to justify their data architecture before they write the first line of code. The era of collecting data first and finding a legal justification later has closed, replaced by a regime where the chosen legal basis dictates the technical constraints of the system.[7]

What to know

  1. The GDPR prohibits the processing of personal data unless one of six specific legal bases is established.
  2. Consent is only one basis and is often inappropriate for core business operations due to its fragility.
  3. Contractual necessity only covers processing that is objectively required to deliver a specific service.
  4. Legitimate interests require a documented three-part balancing test before any data is collected.
  5. Special category data, such as health or biometric information, requires an additional legal exception under Article 9.

Key terms

Lawful Basis
One of the six specific conditions outlined in Article 6 of the GDPR that an organization must satisfy to legally process personal data.
Legitimate Interests Assessment (LIA)
A documented three-part test required when relying on legitimate interests, ensuring the organization's goals do not override the individual's privacy rights.
Special Category Data
Highly sensitive personal data, such as biometric, health, or racial information, which requires an additional explicit condition under Article 9 to process.
Data Controller
The entity that determines the purposes and means of processing personal data, and holds the responsibility for establishing the legal basis.

Reader questions

Can a company switch legal bases if one fails?

Generally, no. Regulatory guidance states that organizations must determine and document their lawful basis before processing begins. Switching bases retrospectively, especially after consent is withdrawn, is considered unfair and non-compliant.

Is consent always the best legal basis?

No. Consent is fragile because it can be withdrawn at any time, forcing processing to stop. For core services or legal obligations, bases like Contractual Necessity or Legal Obligation are much more robust.

What happens if no legal basis applies?

If an organization cannot establish at least one of the six lawful bases under Article 6, the processing of that personal data is illegal and must cease immediately, exposing the company to regulatory fines.

Sources

Source coverage

7 outlets

3 viewpoints surfaced

Privacy Advocates 35%Commercial Operators 35%Regulatory Authorities 30%
  1. [1]GDPR-info.eu

    Art. 6 GDPR – Lawfulness of processing

    Read on GDPR-info.eu →
  2. [2]Data Protection CommissionRegulatory Authorities

    Guidance on Legal Bases for Processing Personal Data

    Read on Data Protection Commission →
  3. [3]European Data Protection BoardRegulatory Authorities

    Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online servic

    Read on European Data Protection Board →
  4. [4]European CommissionRegulatory Authorities

    Legal grounds for processing data

    Read on European Commission →
  5. [5]JD Supra

    EDPB Issues Guidelines on Processing Personal Data for Legitimate Interests Purposes

    Read on JD Supra →
  6. [6]RPC

    ICO draft guidance: legitimate interests as a lawful basis for processing

    Read on RPC →
  7. [7]Factlen Editorial Team

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team →

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.