Skip to main content
Category: Lawful Basis for Processing

Contract with the Data Subject

Also known as: Contractual necessity, Contract lawful basis, Performance of a contract
Simply put

This is one of the reasons an organisation is allowed to use someone's personal data under data protection law: because it needs to do so to carry out a contract with that person. For example, when someone buys goods online, the seller can process their address in order to deliver the order. It applies where the person is a party to the contract, not where a contract exists only between two organisations.

Formal definition

Contract with the data subject is a lawful basis for processing personal data available under Article 6(1)(b) of the UK GDPR and EU GDPR. It applies in two situations: where processing is necessary for the performance of a contract to which the data subject is a party, or where processing is necessary in order to take steps at the data subject's request prior to entering into a contract. The 'necessity' test is central and, per ICO guidance, is generally interpreted objectively: the processing must be a targeted and proportionate means of achieving a specific purpose within the contract, not merely useful or referenced in the contract's terms. This basis is generally unavailable where the data subject is not a party to the contract or where a less intrusive means of achieving the purpose exists; in such cases a different Article 6 basis (for example, legitimate interests, subject to assessment) may need to be considered. Where the processing involves special category data under Article 9, an additional Article 9 condition is required beyond the Article 6 basis. This basis should not be confused with the contractual instruments governing controller-processor relationships (such as a Data Processing Agreement under Article 28); the position may also be affected by member state derogations and should be verified against the current official text.

Why it matters

Choosing the correct lawful basis is a foundational compliance decision under the UK GDPR and EU GDPR, and 'contract with the data subject' under Article 6(1)(b) is one of the most commonly relied upon. Getting it right matters because a lawful basis generally cannot be swapped retrospectively if the original choice proves unsound, and each basis carries different consequences for data subject rights, such as the right to erasure and the right to data portability. Selecting this basis when the processing is not genuinely necessary to perform the contract can leave an organisation without a valid basis at all.

The practical significance lies in the necessity test. Per ICO guidance, necessity is interpreted objectively: the processing must be a targeted and proportionate way of achieving a specific purpose within the contract, not merely something the organisation finds useful or has referenced in its terms. A common pitfall is treating a broad, bundled contract as a licence to process data for purposes that are only tangentially related to delivering what the individual actually agreed to. Where a less intrusive means exists, or where the individual is not a party to the contract, this basis is generally unavailable and another Article 6 basis, such as legitimate interests subject to assessment, may need to be considered.

The boundaries of this basis also help avoid a frequent conceptual error: confusing the lawful basis for processing an individual's data with the contractual instruments that govern relationships between organisations, such as a Data Processing Agreement under Article 28. These serve entirely different functions, and treating one as evidence of the other can undermine a compliance program. Where special category data under Article 9 is involved, this basis alone is not sufficient and an additional Article 9 condition is required.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance leads must document the lawful basis for each processing activity and justify why contractual necessity applies rather than another Article 6 basis. They are typically responsible for scrutinising whether processing is genuinely necessary to perform the contract, and for ensuring that special category data processing carries an additional Article 9 condition where required.
Lawyers and privacy counsel
Legal advisers assess whether the individual is actually a party to the relevant contract and whether the necessity test is met objectively. They also help distinguish this lawful basis from contractual instruments such as a Data Processing Agreement under Article 28, which govern controller-processor relationships rather than provide a basis for processing.
Engineers and product teams
Those designing systems and data flows need to understand that processing an individual's data cannot be justified simply because it appears in a contract's terms. They should build processing that is targeted and proportionate to the contractual purpose, and flag where a less intrusive design could achieve the same outcome, which affects whether this basis is available.
E-commerce and service delivery organisations
Organisations that fulfil orders or deliver services directly to individuals frequently rely on this basis, for example to process a customer's address to deliver goods. They should ensure the scope of processing matches what is necessary to perform the specific contract the individual entered into.

Inside Contract with the Data Subject

Legal basis under Article 6(1)(b)
Processing is lawful where it is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract. This is one of the six distinct legal bases in Article 6 and is separate from consent.
Necessity requirement
The processing must be objectively necessary to deliver the contracted service or performance, not merely useful, convenient, or commercially desirable. Regulators and the EDPB generally interpret necessity narrowly, meaning the controller should be able to demonstrate that the purpose cannot reasonably be achieved by less intrusive means.
Pre-contractual steps
The basis extends to steps taken at the data subject's request before a contract is concluded, such as processing needed to provide a quote or assess an application. Steps initiated by the controller rather than at the data subject's request typically fall outside this limb and may require a different basis.
Data subject as a party
The contract must be with the data subject themselves. Where the individual is not a party to the contract (for example, an employee whose data is processed under a contract between two companies), this basis generally does not apply and another Article 6 basis should be assessed.
Relationship to special category data
Article 6(1)(b) addresses lawfulness of processing generally. Where special category data under Article 9 is involved, an additional Article 9 condition is required, as the contract basis alone does not authorise processing of such data.
Interaction with data subject rights
Reliance on the contract basis affects which rights apply. Notably, the right to data portability under the GDPR is generally available where processing is based on contract (or consent) and carried out by automated means, subject to the applicable conditions.

Common questions

Answers to the questions practitioners most commonly ask about Contract with the Data Subject.

Does relying on the contract legal basis mean I still need to obtain the data subject's consent?
Generally, no. Consent and contract are distinct legal bases under Article 6(1), and they should not be combined or conflated. If processing is genuinely necessary to perform a contract with the data subject (or to take steps at their request prior to entering into a contract), Article 6(1)(b) can serve as the standalone basis, and seeking consent on top would typically be inappropriate and potentially misleading. Relying on the correct single basis matters because consent carries specific conditions, such as the right to withdraw, that do not attach to the contract basis. Note that this addresses the Article 6 lawfulness question only; where special category data under Article 9 is involved, a separate Article 9 condition is still required.
Can this basis cover any processing mentioned or referenced in the contract terms?
Not generally. The contract basis is limited to processing that is objectively necessary to perform the contract with the data subject, not merely useful, convenient, or referenced in the contract document. Regulatory guidance has emphasised a necessity test focused on the substance and fundamental object of the specific contract, rather than on what a controller has drafted into its terms. Processing that goes beyond what is required to deliver the contracted service, such as certain profiling or service improvement activities, typically needs a different Article 6 basis, such as legitimate interests or consent, subject to assessment. The precise boundary can be a matter of interpretation, so it is prudent to verify against current guidance.
How should I document that a given processing activity is necessary for the contract?
In most cases it is advisable to record, for each processing activity, the specific contractual service being delivered and why the processing is necessary to deliver it, rather than asserting necessity in the abstract. This typically includes identifying the particular contract, the data involved, and how the activity relates to the fundamental object of that contract. Such reasoning generally sits within records of processing and privacy notices, and helps demonstrate accountability. Where necessity is not clear-cut, documenting the assessment and, where relevant, the alternative basis relied upon supports a defensible position.
What happens to processing under this basis when the contract ends?
Once the contract is performed or terminated, processing that was necessary only for its performance generally can no longer rely on the contract basis, because the necessity that justified it has ceased. Any continued processing, for example retention for record-keeping, handling disputes, or meeting statutory obligations, typically requires a separate lawful basis such as legal obligation or legitimate interests, assessed on its own terms. Retention periods should generally align with these distinct purposes rather than defaulting to indefinite storage. Where uncertainty exists about post-termination retention, it is prudent to define and document the applicable basis and period.
Can I use the contract basis when the data subject is a child or is not the contracting party?
The contract basis applies to a contract with the data subject or to pre-contractual steps taken at that data subject's request. Where the individual whose data is processed is not a party to the contract, this basis is generally not available for that individual, and another Article 6 basis should be considered. Where children are involved, the contract basis may be affected by capacity to enter into a contract, which can depend on national law, so the position can vary between member states. In these situations it is advisable to assess capacity and party status carefully and to verify the applicable national implementing rules.
How does relying on this basis affect the data subject rights I must honour?
The lawful basis chosen influences which rights apply. Where processing relies on the contract basis, the right to data portability under Article 20 can be engaged, whereas the right to object under Article 21 is generally associated with the legitimate interests and public task bases rather than the contract basis. The rights of access, rectification, and erasure typically remain relevant, though erasure operates subject to conditions and exemptions. It is advisable to map the applicable rights to each basis in advance so that request-handling processes respond correctly, and to verify the specific rights against the current text of the Regulation.

Common misconceptions

You always need consent to process a customer's personal data.
Consent is only one of six legal bases under Article 6. Where processing is genuinely necessary to perform a contract with the individual, Article 6(1)(b) can apply and consent is generally not required. Choosing the correct basis is a context-specific assessment, and relying on consent unnecessarily can create obligations that are difficult to meet.
Anything mentioned or bundled into the terms of a contract is covered by the contract basis.
The basis is limited by the necessity test. Processing that is not objectively necessary to perform the specific service the individual requested, such as certain marketing, profiling, or analytics, typically requires a separate legal basis rather than being justified simply because it appears in the contract.
The contract basis covers any processing involving personal data linked to a business deal.
The contract must be with the data subject. Where the individual is not a party, for example a third-party beneficiary or an employee of a contracting company, this basis generally will not apply and the controller should assess another Article 6 basis such as legitimate interests, subject to assessment.

Best practices

Document why the specific processing is necessary to perform the contract or to take pre-contractual steps requested by the data subject, and record less intrusive alternatives you considered.
Separate out processing activities that are not strictly necessary for performance (such as marketing or optional analytics) and identify an appropriate alternative legal basis for each rather than folding them into the contract basis.
Confirm that the data subject is genuinely a party to the contract before relying on this basis, and reassess where the individual is not a party (for example in business-to-business or employment scenarios).
Where special category data is involved, identify and record the additional Article 9 condition, since the contract basis alone does not authorise its processing.
Reflect the chosen legal basis accurately in your privacy notice and processing records, and review it if the nature or purpose of the processing changes.
Verify current article references and any regulator or EDPB guidance on the necessity test against the official text, as interpretation can evolve and may vary between EU member states and the UK GDPR.