The Legal Bases for Processing Personal Data Under GDPR
Under the General Data Protection Regulation, organizations cannot legally process personal data without establishing one of six specific lawful bases. Understanding the distinction between consent, legitimate interests, and contractual necessity defines the boundary between compliant operations and severe regulatory penalties.
- Privacy Advocates
- Argue that explicit, informed consent should be the default mechanism for all non-essential data processing.
- Commercial Operators
- Rely heavily on legitimate interests and contractual necessity to maintain seamless user experiences without constant consent interruptions.
- Regulatory Authorities
- Focus on strict adherence to the definitions, requiring extensive documentation and balancing tests to prevent the abuse of flexible bases.
Perspectives this story doesn't cover
- Small Business Owners
- Open Source Developers
Why it matters
Every digital interaction, from opening an app to completing a purchase, relies on one of these legal bases to function legally. Misclassifying how data is processed exposes organizations to massive fines and forces them to delete entire datasets, directly impacting product viability.
Privacy advocates argue that explicit user consent is the only legitimate mechanism for processing personal data, demanding that individuals actively opt in before their information is touched. Commercial data brokers and marketing platforms counter that requiring active consent for every background operation would break the modern internet, relying instead on "legitimate interests" to justify passive data collection.[7]
Between these two absolute positions lies the actual framework of the General Data Protection Regulation (GDPR). Adopted in 2016 and enforced since May 2018, the regulation does not mandate consent for everything. Instead, Article 6 of the GDPR outlines six primary lawful bases for processing personal data, with a seventh often practically derived from the strict conditions applied to special category data under Article 9.[1][7]
Understanding these bases is not merely an academic legal exercise. The distinction between relying on a user's consent versus a company's legitimate interest defines the boundary between compliant operations and severe regulatory penalties, which can reach €20 million or 4% of a company's global annual turnover.[1]
The most recognized basis is Consent, defined under Article 6(1)(a). The European Commission explicitly requires this to be a "freely given, specific, informed and unambiguous" indication of the user's wishes. However, the technology industry frequently overuses consent, presenting users with exhaustive cookie banners that induce fatigue rather than genuine choice.[4]
When consent is withdrawn, processing must stop immediately. This fragility makes it highly unappealing for core business operations. As the Data Protection Commission (DPC) guidance notes, organizations should not rely on consent if there is a clear imbalance of power, such as in an employment context, because the consent cannot be considered freely given.[2]
The second basis is Contractual Necessity, found in Article 6(1)(b). This applies when processing is required to fulfill a contract with the individual. If a user purchases a physical product, the vendor does not need consent to process their shipping address; the processing is strictly necessary to deliver the goods.[1][3]
Companies often stretch this definition to cover behavioral tracking, claiming it is necessary to provide a "personalized" service. The European Data Protection Board (EDPB) explicitly rejected this in its Guidelines 2/2019, stating that processing must be objectively necessary for a purpose that is integral to the delivery of that specific service, not merely useful for the provider's business model.[3]
Companies often stretch this definition to cover behavioral tracking, claiming it is necessary to provide a "personalized" service.
The third basis is Legal Obligation under Article 6(1)(c). This covers scenarios where an organization is mandated by law to process data, such as retaining employee tax records or performing anti-money laundering checks. The processing is justified by statutory requirements rather than user preference or commercial desire.[1][4]
Vital Interests, outlined in Article 6(1)(d), serves as an emergency provision. It applies when processing is necessary to protect someone's life. If a hospital admits an unconscious patient, they do not need consent to access medical records. This basis is narrowly construed and rarely applies to standard commercial technology operations.[1]
Public Task, located in Article 6(1)(e), is utilized primarily by government entities and public authorities. It permits data processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.[1][4]
The most contested and flexible basis is Legitimate Interests, defined in Article 6(1)(f). This allows processing if the organization has a valid reason that is not overridden by the individual's rights and freedoms. It is the engine driving much of the modern data economy, from fraud prevention to direct marketing.[1][5]
Because it does not require active user consent, Legitimate Interests is highly attractive to technology firms. However, it requires a documented Legitimate Interests Assessment (LIA) comprising a three-part test: identifying the interest, showing the processing is necessary to achieve it, and balancing it against the individual's rights.[2][6]
Recent regulatory movements have targeted the abuse of this basis. As noted by legal analysts at JD Supra, the EDPB has issued updated guidelines tightening how legitimate interests can be applied, particularly emphasizing that commercial interests do not automatically trump user privacy expectations.[5]
Similarly, the UK's Information Commissioner's Office (ICO) has drafted specific guidance on legitimate interests, reinforcing that organizations cannot use it as a default fallback when consent is too difficult to obtain. The RPC analysis highlights that the balancing test must be rigorous and documented before any processing begins.[6]
The "seventh" basis often discussed in compliance circles refers to the explicit exceptions required for processing Special Category Data under Article 9. This includes race, biometrics, and health data. For these categories, standard Article 6 bases are insufficient unless paired with a specific Article 9 condition, such as explicit consent or substantial public interest.[7]
The technology industry's shift toward agentic AI and automated processing complicates these bases further. When an AI agent scrapes data to train a model, determining whether that constitutes a legitimate interest or requires explicit consent remains a heavily litigated frontier across European courts.[7]
The GDPR's framework forces organizations to justify their data architecture before they write the first line of code. The era of collecting data first and finding a legal justification later has closed, replaced by a regime where the chosen legal basis dictates the technical constraints of the system.[7]
What to know
- The GDPR prohibits the processing of personal data unless one of six specific legal bases is established.
- Consent is only one basis and is often inappropriate for core business operations due to its fragility.
- Contractual necessity only covers processing that is objectively required to deliver a specific service.
- Legitimate interests require a documented three-part balancing test before any data is collected.
- Special category data, such as health or biometric information, requires an additional legal exception under Article 9.
Key terms
- Lawful Basis
- One of the six specific conditions outlined in Article 6 of the GDPR that an organization must satisfy to legally process personal data.
- Legitimate Interests Assessment (LIA)
- A documented three-part test required when relying on legitimate interests, ensuring the organization's goals do not override the individual's privacy rights.
- Special Category Data
- Highly sensitive personal data, such as biometric, health, or racial information, which requires an additional explicit condition under Article 9 to process.
- Data Controller
- The entity that determines the purposes and means of processing personal data, and holds the responsibility for establishing the legal basis.
Reader questions
Can a company switch legal bases if one fails?
Generally, no. Regulatory guidance states that organizations must determine and document their lawful basis before processing begins. Switching bases retrospectively, especially after consent is withdrawn, is considered unfair and non-compliant.
Is consent always the best legal basis?
No. Consent is fragile because it can be withdrawn at any time, forcing processing to stop. For core services or legal obligations, bases like Contractual Necessity or Legal Obligation are much more robust.
What happens if no legal basis applies?
If an organization cannot establish at least one of the six lawful bases under Article 6, the processing of that personal data is illegal and must cease immediately, exposing the company to regulatory fines.
Sources
[1]GDPR-info.euArt. 6 GDPR – Lawfulness of processing
Read on GDPR-info.eu →
[2]Data Protection CommissionRegulatory AuthoritiesGuidance on Legal Bases for Processing Personal Data
Read on Data Protection Commission →
[3]European Data Protection BoardRegulatory AuthoritiesGuidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online servic
Read on European Data Protection Board →
[4]European CommissionRegulatory AuthoritiesLegal grounds for processing data
Read on European Commission →
[5]JD SupraEDPB Issues Guidelines on Processing Personal Data for Legitimate Interests Purposes
Read on JD Supra →
[6]RPCICO draft guidance: legitimate interests as a lawful basis for processing
Read on RPC →
[7]Factlen Editorial TeamSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
More in Technology
See all →Data Privacy Law
New Mexico Jury Finds Meta Liable for Privacy Violations in Cambridge Analytica Case
5 sources
Orbital Security
US Space Force Confirms Deployment of Orbital Weapons as China Warns of Space Arms Race
6 sources
Federal Data Breach
Hackers Claim 3TB Breach of FBI Employee Data via HR Software Flaw
5 sources
AI Safety
Resect AI Secures $25 Million to Intercept Large Language Model Hallucinations During Inference
6 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




