Skip to main content
Category: Lawful Basis for Processing

Compatibility Assessment

Simply put

A compatibility assessment is the analysis an organisation carries out to decide whether it can use personal data it already holds for a new purpose that is different from the one for which the data was originally collected. In data protection terms, it helps determine whether the new use is close enough to the original purpose to be lawful, or whether a fresh legal basis or consent is needed. This is a context-dependent judgement rather than a fixed test with a guaranteed outcome.

Formal definition

Under the GDPR's purpose limitation principle, personal data collected for specified, explicit and legitimate purposes must generally not be further processed in a manner incompatible with those purposes. A compatibility assessment is the structured evaluation a controller undertakes to determine whether a proposed further processing purpose is compatible with the original purpose. Where processing is not based on consent or a legal obligation, this assessment typically considers factors such as any link between the original and new purposes, the context in which the data was collected and the reasonable expectations of data subjects, the nature of the data (including whether special category data is involved), the possible consequences of the further processing, and the existence of safeguards such as pseudonymisation or encryption. If the assessment concludes the new purpose is incompatible, the controller generally cannot rely on the original legal basis and would need a separate lawful basis or the data subject's consent. The precise article references, the treatment of processing for archiving, scientific or historical research, or statistical purposes, and any national derogations should be verified against the current official text of the applicable EU or UK GDPR and implementing law, as the position can vary by member state and evolve through regulator guidance.

Why it matters

The purpose limitation principle is a cornerstone of the GDPR: personal data collected for specified, explicit and legitimate purposes must generally not be further processed in a manner incompatible with those purposes. A compatibility assessment is the practical mechanism through which an organisation tests a proposed new use of data it already holds against this principle. Getting this judgement wrong can mean an organisation is processing personal data without a valid lawful basis, which exposes it to regulatory scrutiny and undermines the trust of the individuals whose data is involved.

The assessment matters because reusing existing datasets is a common operational reality, data collected for one service is frequently proposed for analytics, product development, or new features. Rather than assuming such reuse is automatically permitted or automatically prohibited, the compatibility assessment forces a documented, context-dependent evaluation. Where the assessment concludes the new purpose is incompatible, the organisation generally cannot rely on the original legal basis and would need a separate lawful basis or the data subject's consent before proceeding.

Because the outcome depends on factors such as the link between purposes, the reasonable expectations of data subjects, the nature of the data, and the safeguards in place, the assessment is a judgement rather than a fixed test with a guaranteed result. This means organisations should treat it as an ongoing compliance discipline, verifying their conclusions against the current official text of the applicable EU or UK GDPR and implementing law, and remaining alert to divergence between member states and evolving regulator guidance.

Who it's relevant to

Data Protection Officers and compliance leads
DPOs and compliance teams typically own the documentation and governance around further processing decisions. They are responsible for ensuring a structured compatibility assessment is carried out and recorded before existing data is reused for a new purpose, and for advising when a fresh lawful basis or consent is required instead.
Privacy and data protection lawyers
Legal advisers are often called on to interpret whether a proposed new use is compatible with the original purpose. They help frame the assessment factors, flag where special category data raises additional considerations, and confirm the position against the current applicable EU or UK GDPR text and relevant national implementing law and derogations.
Controllers proposing new uses of existing data
Business and product teams that want to repurpose personal data already held, for example for new features or analytics, are the practical starting point for a compatibility assessment. They should engage privacy functions early rather than assuming reuse is automatically permitted, since the outcome is context-dependent and may require a separate legal basis or consent.
Engineers and product teams implementing safeguards
Because safeguards such as pseudonymisation or encryption are among the factors weighed in an assessment, engineers can influence whether a further processing purpose is more likely to be considered compatible. Their design choices around data handling and technical protections feed directly into the assessment's conclusions.

Inside Compatibility Assessment

Purpose Limitation Anchor
A compatibility assessment starts from the purpose limitation principle: personal data collected for specified, explicit and legitimate purposes should generally not be further processed in a manner incompatible with those purposes. The assessment evaluates whether a new or additional processing purpose is compatible with the original purpose for which the data was collected.
Statutory Compatibility Factors
The GDPR sets out factors to weigh when judging compatibility, including any link between the original and intended new purposes, the context in which the data was collected and the reasonable expectations of data subjects, the nature of the data (particularly whether special category data under Article 9 is involved), the possible consequences of the further processing for data subjects, and the existence of safeguards such as encryption or pseudonymisation.
Relationship to the Legal Basis
A compatibility assessment concerns whether further processing is permitted for a new purpose without necessarily requiring a fresh legal basis. It should not be confused with the separate requirement to identify an Article 6 lawful basis. Where processing is based on consent or on a legal provision, the compatibility test may be approached differently, and further processing may need to rest on its own footing rather than a compatibility analysis.
Presumed-Compatible Purposes
Certain further processing purposes, such as archiving in the public interest, scientific or historical research, and statistical purposes, are generally treated as broadly compatible where appropriate safeguards are in place, subject to conditions and to any member state derogations that may vary the position.
Documented Outcome
The output is typically a reasoned, documented conclusion on whether the intended further processing is compatible, recording the factors considered and any safeguards applied. This supports the accountability principle and may inform related exercises such as a Data Protection Impact Assessment where the further processing is likely to result in high risk.

Common questions

Answers to the questions practitioners most commonly ask about Compatibility Assessment.

Does further processing for a new purpose always require fresh consent?
No. Fresh consent is one route, but it is not the only one. Where the original legal basis was not consent, a controller may generally rely on the compatibility assessment to determine whether the new purpose is compatible with the purpose for which the data was originally collected. If the new purpose is found compatible, further processing can typically proceed on the original legal basis without obtaining new consent. However, the position can differ where the original basis was consent, and where processing relies on a legal obligation or a task carried out in the public interest, member state law may frame the analysis differently. You should verify against the current official text and applicable guidance.
Is a compatibility assessment the same as a Data Protection Impact Assessment (DPIA)?
No, these are distinct exercises. A compatibility assessment addresses whether processing for a new purpose is compatible with the original collection purpose (the purpose limitation question). A DPIA under Article 35 is a broader exercise to assess and mitigate risks to individuals arising from processing likely to result in a high risk. The two can inform one another, but a compatibility assessment does not substitute for a DPIA where one is required, and completing a DPIA does not by itself resolve the compatibility question. Treat them as separate, potentially overlapping, obligations.
What factors should be weighed when carrying out a compatibility assessment?
The assessment is generally a multi-factor exercise rather than a single test. Factors typically considered include any link between the original and the new purpose, the context in which the data was collected and the reasonable expectations of the data subject, the nature of the data (with particular caution for special category data under Article 9), the possible consequences of the further processing for individuals, and the existence of safeguards such as encryption or pseudonymisation. These factors are weighed together; no single factor is usually decisive. Consult the current text and regulator guidance for the operative list.
How should the outcome of a compatibility assessment be documented?
As a matter of accountability, it is generally advisable to record the assessment in writing, capturing the original purpose, the proposed new purpose, the factors weighed, the conclusion reached, and any safeguards applied. This documentation supports the ability to demonstrate compliance if questioned by a supervisory authority. The GDPR does not prescribe a mandatory template for this record, so organisations typically integrate it into existing records of processing or purpose-change procedures. Verify any specific documentation expectations against applicable guidance, which can vary between regulators.
Who within an organisation should be responsible for conducting the assessment?
Responsibility generally sits with the controller determining the purposes of the processing. In practice, the assessment is often carried out by the business owner of the new processing activity with input from privacy, legal, or a Data Protection Officer where one is appointed. The role of a DPO, where one exists, is typically advisory rather than decision-making. Allocation of responsibility can depend on internal governance arrangements, so organisations should define this in their own policies.
What should happen if a proposed new purpose is found to be incompatible?
Where the assessment concludes that the new purpose is not compatible with the original purpose, the further processing generally cannot proceed on the original legal basis alone. In that situation the controller typically needs to identify a separate lawful basis for the new purpose, which may involve obtaining consent or relying on another Article 6 basis, and, for special category data, satisfying an additional Article 9 condition. Transparency obligations toward data subjects may also be triggered. The appropriate response is context-dependent and should be assessed case by case.

Common misconceptions

A compatibility assessment is the same thing as a Data Protection Impact Assessment (DPIA).
They are distinct. A compatibility assessment addresses whether further processing aligns with the original purpose under the purpose limitation principle, while a DPIA (Article 35) evaluates and mitigates the risks of processing likely to result in a high risk to individuals. A processing activity may require one, both, or neither depending on the circumstances.
If further processing is found compatible, no legal basis is needed for it.
Compatibility and lawful basis are separate questions. A favourable compatibility finding addresses purpose limitation but does not remove the need to satisfy the general lawfulness requirements, and special category data under Article 9 requires an additional condition regardless of the compatibility conclusion.
New consent is always required before data can be used for a different purpose.
This is not universally true. Where the new purpose is assessed as compatible with the original purpose, further processing may in many cases proceed without fresh consent, subject to assessment. Consent is one of several Article 6 bases, not a universal precondition, though where the original processing relied on consent the position may differ.

Best practices

Document the assessment before beginning any further processing, recording each statutory factor considered, including the link to the original purpose, the collection context, the nature of the data, potential consequences for data subjects, and any safeguards applied.
Distinguish clearly in your records between the compatibility question and the separate identification of an Article 6 lawful basis, and where Article 9 special category data is involved confirm that an additional condition is met.
Assess reasonable expectations of data subjects at the time of collection, and consider whether the original privacy information described purposes broadly enough to encompass the intended further use.
Apply and record concrete safeguards such as pseudonymisation, encryption, or access restrictions, as these can influence a compatibility conclusion in favour of the further processing.
Where the further processing is likely to result in a high risk to individuals, consider whether a DPIA is separately required, and treat the compatibility assessment as an input rather than a substitute.
Verify the treatment of research, archiving, and statistical purposes against the current official text and any applicable member state derogations, since national implementing law may vary the position.