Contract with the Data Subject
This is one of the reasons an organisation is allowed to use someone's personal data under data protection law: because it needs to do so to carry out a contract with that person. For example, when someone buys goods online, the seller can process their address in order to deliver the order. It applies where the person is a party to the contract, not where a contract exists only between two organisations.
Contract with the data subject is a lawful basis for processing personal data available under Article 6(1)(b) of the UK GDPR and EU GDPR. It applies in two situations: where processing is necessary for the performance of a contract to which the data subject is a party, or where processing is necessary in order to take steps at the data subject's request prior to entering into a contract. The 'necessity' test is central and, per ICO guidance, is generally interpreted objectively: the processing must be a targeted and proportionate means of achieving a specific purpose within the contract, not merely useful or referenced in the contract's terms. This basis is generally unavailable where the data subject is not a party to the contract or where a less intrusive means of achieving the purpose exists; in such cases a different Article 6 basis (for example, legitimate interests, subject to assessment) may need to be considered. Where the processing involves special category data under Article 9, an additional Article 9 condition is required beyond the Article 6 basis. This basis should not be confused with the contractual instruments governing controller-processor relationships (such as a Data Processing Agreement under Article 28); the position may also be affected by member state derogations and should be verified against the current official text.
Why it matters
Choosing the correct lawful basis is a foundational compliance decision under the UK GDPR and EU GDPR, and 'contract with the data subject' under Article 6(1)(b) is one of the most commonly relied upon. Getting it right matters because a lawful basis generally cannot be swapped retrospectively if the original choice proves unsound, and each basis carries different consequences for data subject rights, such as the right to erasure and the right to data portability. Selecting this basis when the processing is not genuinely necessary to perform the contract can leave an organisation without a valid basis at all.
The practical significance lies in the necessity test. Per ICO guidance, necessity is interpreted objectively: the processing must be a targeted and proportionate way of achieving a specific purpose within the contract, not merely something the organisation finds useful or has referenced in its terms. A common pitfall is treating a broad, bundled contract as a licence to process data for purposes that are only tangentially related to delivering what the individual actually agreed to. Where a less intrusive means exists, or where the individual is not a party to the contract, this basis is generally unavailable and another Article 6 basis, such as legitimate interests subject to assessment, may need to be considered.
The boundaries of this basis also help avoid a frequent conceptual error: confusing the lawful basis for processing an individual's data with the contractual instruments that govern relationships between organisations, such as a Data Processing Agreement under Article 28. These serve entirely different functions, and treating one as evidence of the other can undermine a compliance program. Where special category data under Article 9 is involved, this basis alone is not sufficient and an additional Article 9 condition is required.
Who it's relevant to
Inside Contract with the Data Subject
Common questions
Answers to the questions practitioners most commonly ask about Contract with the Data Subject.