Compatibility Assessment
A compatibility assessment is the analysis an organisation carries out to decide whether it can use personal data it already holds for a new purpose that is different from the one for which the data was originally collected. In data protection terms, it helps determine whether the new use is close enough to the original purpose to be lawful, or whether a fresh legal basis or consent is needed. This is a context-dependent judgement rather than a fixed test with a guaranteed outcome.
Under the GDPR's purpose limitation principle, personal data collected for specified, explicit and legitimate purposes must generally not be further processed in a manner incompatible with those purposes. A compatibility assessment is the structured evaluation a controller undertakes to determine whether a proposed further processing purpose is compatible with the original purpose. Where processing is not based on consent or a legal obligation, this assessment typically considers factors such as any link between the original and new purposes, the context in which the data was collected and the reasonable expectations of data subjects, the nature of the data (including whether special category data is involved), the possible consequences of the further processing, and the existence of safeguards such as pseudonymisation or encryption. If the assessment concludes the new purpose is incompatible, the controller generally cannot rely on the original legal basis and would need a separate lawful basis or the data subject's consent. The precise article references, the treatment of processing for archiving, scientific or historical research, or statistical purposes, and any national derogations should be verified against the current official text of the applicable EU or UK GDPR and implementing law, as the position can vary by member state and evolve through regulator guidance.
Why it matters
The purpose limitation principle is a cornerstone of the GDPR: personal data collected for specified, explicit and legitimate purposes must generally not be further processed in a manner incompatible with those purposes. A compatibility assessment is the practical mechanism through which an organisation tests a proposed new use of data it already holds against this principle. Getting this judgement wrong can mean an organisation is processing personal data without a valid lawful basis, which exposes it to regulatory scrutiny and undermines the trust of the individuals whose data is involved.
The assessment matters because reusing existing datasets is a common operational reality, data collected for one service is frequently proposed for analytics, product development, or new features. Rather than assuming such reuse is automatically permitted or automatically prohibited, the compatibility assessment forces a documented, context-dependent evaluation. Where the assessment concludes the new purpose is incompatible, the organisation generally cannot rely on the original legal basis and would need a separate lawful basis or the data subject's consent before proceeding.
Because the outcome depends on factors such as the link between purposes, the reasonable expectations of data subjects, the nature of the data, and the safeguards in place, the assessment is a judgement rather than a fixed test with a guaranteed result. This means organisations should treat it as an ongoing compliance discipline, verifying their conclusions against the current official text of the applicable EU or UK GDPR and implementing law, and remaining alert to divergence between member states and evolving regulator guidance.
Who it's relevant to
Inside Compatibility Assessment
Common questions
Answers to the questions practitioners most commonly ask about Compatibility Assessment.