Skip to main content
Category: Lawful Basis for Processing

Compatible Purpose

Also known as: Compatible Further Processing, Purpose Compatibility
Simply put

A compatible purpose is a new reason for using personal data that is closely enough related to the original reason it was collected that the further use is generally permitted. Organisations typically assess this before reusing data for something other than the original stated purpose. Whether a new use is compatible depends on the facts and requires a case-by-case assessment.

Formal definition

Under the purpose limitation principle, personal data collected for specified, explicit and legitimate purposes should generally not be further processed in a manner incompatible with those original purposes. Where a controller proposes to reuse data for a new purpose, it typically must determine whether that new purpose is compatible with the original, applying a compatibility assessment that considers factors such as the link between the purposes, the context of collection, the nature of the data, possible consequences for data subjects, and the existence of safeguards. Certain further processing may be treated as compatible by operation of law, and Union or Member State law may specify tasks and purposes for which further processing is regarded as compatible and lawful; the position can therefore vary by jurisdiction and by specific national conditions (for example, a taxation-related compatibility condition recognised in UK guidance). This concept is distinct from identifying a separate Article 6 lawful basis, and analogous but not identical notions of compatibility appear in other regimes such as the CCPA; practitioners should verify the precise conditions and article references against the current official text.

Why it matters

The purpose limitation principle sits at the core of data protection: personal data collected for specified, explicit and legitimate purposes should generally not be reused in a way incompatible with those original purposes. The compatible purpose concept determines whether an organisation can lawfully repurpose data it already holds, or whether it must instead go back to data subjects, identify a fresh basis, or refrain from the new use altogether. Getting this wrong exposes a controller to challenge, because reuse that turns out to be incompatible can undermine the fairness and lawfulness of the entire processing operation.

The assessment matters practically because organisations frequently want to extract further value from data already collected, whether for analytics, new product features, or operational efficiencies. Compatibility is not a formality that can be assumed; it requires a case-by-case evaluation weighing the link between the old and new purposes, the context of collection, the nature of the data, possible consequences for data subjects, and any safeguards in place. Because outcomes depend on the specific facts, the same type of reuse may be compatible in one scenario and not in another.

Jurisdictional variation adds a further layer of importance. Union or Member State law may specify tasks and purposes that are regarded as compatible and lawful, and national conditions can alter the position, for example a taxation-related compatibility condition recognised in UK guidance permitting use of data to assess or collect a tax, duty or similar imposition. Analogous but not identical notions appear in other regimes such as the CCPA, so a compatibility conclusion reached under one framework should not be assumed to hold under another.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy teams are typically responsible for documenting compatibility assessments before data is reused for a new purpose. They must weigh the relevant factors on a case-by-case basis, check whether any national compatibility conditions apply, and ensure the analysis is distinguished from the separate question of identifying an Article 6 lawful basis.
Product and Data Teams
Teams launching projects that involve processing personal data previously collected for a different purpose need to engage the compatibility question early. Because the assessment turns on context, the link between purposes, and consequences for individuals, decisions about analytics, feature development, or operational reuse should be reviewed before build, not after.
Compliance and Legal Advisers
Advisers assessing whether lawfully collected data can be processed for a new purpose must apply the compatibility test and account for jurisdictional divergence, including Member State or UK-specific conditions such as the taxation compatibility condition recognised in UK guidance. They should verify precise conditions and article references against the current official text and avoid assuming that a conclusion under one regime transfers to another.
Organisations Operating Across GDPR and Other Regimes
Businesses subject to both the GDPR and frameworks such as the CCPA should note that analogous but not identical notions of compatibility exist across regimes. A finding that a purpose is compatible under one law does not establish compatibility under another, and the specific operational or business-purpose conditions must be checked separately.

Inside Compatible Purpose

Purpose Limitation Principle
Compatible purpose is an aspect of the purpose limitation principle under GDPR Article 5(1)(b), which requires that personal data be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
Compatibility Assessment Factors
GDPR Article 6(4) sets out factors a controller should generally consider when determining whether a further processing purpose is compatible with the original purpose. These typically include the link between the original and new purposes, the context of collection, the nature of the data (including whether special category data under Article 9 is involved), the possible consequences for data subjects, and the existence of safeguards such as encryption or pseudonymisation.
Presumed Compatible Purposes
Article 5(1)(b) indicates that further processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes is, subject to appropriate safeguards under Article 89(1), not generally considered incompatible with the original purposes.
Relationship to Legal Basis
A finding of compatibility concerns whether further processing is permitted under the purpose limitation principle; it does not by itself establish an Article 6 legal basis. The interaction between compatibility and the need for a lawful basis is subject to assessment and interpretation, and readers should verify the current position against official text and guidance.
Consent and Legal Obligation Carve-outs
Where the further processing is based on the data subject's consent or on a Union or member state law that constitutes a necessary and proportionate measure, the Article 6(4) compatibility test does not apply in the same way, as further processing may proceed on that separate footing.

Common questions

Answers to the questions practitioners most commonly ask about Compatible Purpose.

Does further processing for a new purpose always require fresh consent?
No. Consent is only one of the Article 6 legal bases, and further processing does not automatically require obtaining fresh consent. Where the new purpose is compatible with the original purpose for which the data was collected, further processing can generally proceed without a separate legal basis, subject to the compatibility assessment. Fresh consent is one route where processing is based on consent or required by member state law, but treating it as a universal requirement is a misconception. The position should be assessed against the specific facts and any applicable national derogations.
Is a purpose either identical to the original or incompatible, with nothing in between?
No. Compatibility is not a binary match to the original purpose. A purpose can differ from the one originally specified yet still be compatible following an assessment of relevant factors, such as the link between the purposes, the context in which the data was collected, the nature of the data, the possible consequences for the data subject, and the existence of safeguards. Compatibility is therefore a spectrum evaluated case by case rather than a simple same-or-different test.
What factors should be documented when assessing whether a new purpose is compatible?
The assessment typically documents the link between the original and intended new purpose, the context and relationship in which the data was collected, the nature of the personal data (including whether special category data is involved), the possible consequences of the further processing for data subjects, and any safeguards applied such as encryption or pseudonymisation. Recording the reasoning supports accountability, though the precise documentation approach should be tailored to the risk and verified against current regulatory guidance.
How does a compatibility assessment interact with the transparency and information obligations owed to data subjects?
Where further processing for a compatible purpose is envisaged, controllers generally need to provide data subjects with information about that further purpose and relevant details before undertaking it, consistent with the transparency principle. In practice this often means updating privacy information. The exact obligations depend on how and when the data was obtained and on any applicable exemptions, so the specific notice requirements should be confirmed against the relevant provisions.
Does the compatibility route apply to special category data in the same way as other personal data?
Not automatically. Even where a further purpose is assessed as compatible under Article 6, processing of special category data under Article 9 requires a separate applicable condition. The compatibility analysis does not remove the need for that additional Article 9 condition, and member state law may impose further requirements. This should be assessed carefully and verified against the current text and any national implementing provisions.
Are there processing purposes that are generally treated as compatible without a full assessment?
Certain purposes, such as archiving in the public interest, scientific or historical research, and statistical purposes, are generally regarded as compatible further processing, typically subject to appropriate safeguards for the rights of data subjects. This does not remove the need to apply safeguards or to consider member state derogations, which can vary. Reliance on this position should be confirmed against the current official text and applicable national law.

Common misconceptions

If a purpose is found compatible, no further lawfulness analysis is needed.
Compatibility addresses the purpose limitation principle, but a controller must still consider whether the processing satisfies other GDPR requirements, and the precise relationship to establishing an Article 6 legal basis is a matter of assessment and ongoing interpretation. Special category data under Article 9 would additionally require a separate Article 9 condition.
Research and statistical purposes are automatically permitted without conditions.
Further processing for archiving in the public interest, scientific or historical research, or statistical purposes is generally not treated as incompatible, but this is expressly conditioned on appropriate safeguards under Article 89(1). It is not an unconditional exemption, and member state law may vary the position.
Compatibility is a fixed determination that applies broadly once made.
Compatibility is a context-dependent assessment based on the factors in Article 6(4), including the specific relationship between purposes, the data involved, and the consequences for data subjects. A conclusion reached for one processing scenario does not necessarily hold for a different context.

Best practices

Document a compatibility assessment that works through the Article 6(4) factors, including the link between the original and intended purposes, the context of collection, the nature of the data, potential consequences for data subjects, and any safeguards in place.
Where special category data is involved, treat the compatibility question as distinct from, and additional to, the need to identify an appropriate Article 9 condition, and record both analyses.
Where further processing relies on data subject consent or a specific Union or member state law, note that the standard compatibility test may not apply in the same way and confirm the correct footing before proceeding.
For research, statistical, or archiving purposes, implement and record the appropriate safeguards contemplated by Article 89(1), such as pseudonymisation, rather than assuming an unconditional exemption.
Revisit compatibility assessments when the context, data types, or intended uses change, since a prior conclusion may not transfer to a new scenario.
Verify article references, presumptions, and the interaction between compatibility and legal basis against the current official GDPR text and applicable regulator guidance, and note any member state derogations that may vary the position.