Skip to main content
Category: Lawful Basis for Processing

Exercise of Official Authority

Also known as: Official Authority, Exercise of Official Authority Vested in the Controller
Simply put

This is one of the reasons an organisation can lawfully use personal data. It generally applies where a body carries out official functions or powers, such as those exercised by public authorities, that are set out in law. In the UK GDPR, this concept sits alongside performing a task in the public interest under the broader 'public task' lawful basis.

Formal definition

The exercise of official authority is a component of the lawful basis found in Article 6(1)(e) GDPR, under which processing is lawful where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. It typically covers the exercise of public functions and powers that have a clear basis in law, and in most cases is relied upon by public authorities, though the position depends on how the relevant function is established in law. Under the UK GDPR, the ICO addresses this basis within its guidance on the 'public task' lawful basis, which encompasses both the exercise of official authority and the performance of a specific task in the public interest set out in law. The precise scope of what constitutes 'official authority' is context-dependent and may be shaped by national implementing law and member state provisions; readers should verify the applicable legal underpinning and any relevant regulator guidance. Note that where special category data under Article 9 is involved, a further Article 9 condition is required in addition to the Article 6 basis.

Why it matters

Selecting the correct lawful basis under Article 6 is a foundational compliance step, and the exercise of official authority is one that is typically most relevant to public authorities carrying out functions and powers set out in law. Choosing the wrong basis can undermine the lawfulness of an entire processing operation, and the basis relied upon must be identified before processing begins. Because this basis generally rests on a legal underpinning for the relevant function, organisations need to be able to point to the specific legal provision that establishes the official authority they are exercising.

The scope of what counts as 'official authority' is context-dependent and can be shaped by national implementing law and member state provisions, so the position may differ between jurisdictions. Under the UK GDPR, the ICO folds this concept into its broader 'public task' lawful basis guidance, which covers both the exercise of official authority and the performance of a specific task in the public interest set out in law. Readers should verify the applicable legal basis for their particular function against the current official text and relevant regulator guidance rather than assuming the basis applies automatically.

Getting this right also affects downstream obligations and the rights available to individuals, since the choice of lawful basis interacts with other parts of the compliance framework. Where special category data under Article 9 is involved, this Article 6 basis alone is not sufficient, and an additional Article 9 condition must also be identified. Treating the exercise of official authority as a blanket justification for any public-sector processing risks overreach, so the assessment should remain tied to the specific function and its legal foundation.

Who it's relevant to

Public Authorities and Public Bodies
Bodies exercising official functions and powers set out in law are, in most cases, the primary organisations relying on this basis. They should be able to identify the specific legal provision that establishes the relevant authority, as the applicability of the basis depends on that legal underpinning.
Data Protection Officers and Compliance Leads
Those responsible for documenting lawful bases need to distinguish the exercise of official authority from other Article 6 bases and record why it applies to each processing activity. They should also assess whether an additional Article 9 condition is needed where special category data is involved, and verify the position against current regulator guidance.
Privacy Lawyers and Advisers
Legal advisers assessing the scope of 'official authority' should account for the context-dependent nature of the concept and the influence of national implementing law and member state provisions, which can vary the position between jurisdictions such as the EU and the UK.
Organisations Carrying Out Functions on Behalf of Public Bodies
Entities performing public functions or tasks may need to consider whether the exercise of official authority applies to their processing, subject to how the function is established in law. The correct basis depends on assessment of the specific legal foundation rather than the sector alone.

Inside Exercise of Official Authority

Public Task Legal Basis
Under Article 6(1)(e) GDPR, processing may be lawful where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. The exercise of official authority is one of the two limbs of this legal basis, the other being performance of a task in the public interest.
Basis in Member State or Union Law
Article 6(3) GDPR generally requires that the task or authority be laid down in Union or member state law. The exercise of official authority is therefore typically not something a controller can self-declare; it must derive from a legal foundation. The precise content and clarity of that legal basis can vary between member states due to national implementing law and derogations.
Vested in the Controller
The official authority must be vested in the controller carrying out the processing. This typically points toward public authorities and bodies, but in some cases can extend to other entities where law confers relevant functions on them. The boundary of who qualifies is subject to assessment and may differ across jurisdictions.
Necessity Requirement
The processing must be necessary for the exercise of the official authority, not merely convenient or useful. Necessity is generally assessed against whether the objective could reasonably be achieved by less intrusive means.
Interaction with Data Subject Rights
Reliance on this basis affects which data subject rights apply. For example, the right to object under Article 21 is available where processing rests on Article 6(1)(e), and the right to data portability under Article 20 generally does not apply to this basis. Practitioners should verify the current text for the applicable rights framework.

Common questions

Answers to the questions practitioners most commonly ask about Exercise of Official Authority.

Does the exercise of official authority legal basis mean I need to obtain consent from data subjects?
Generally no. The exercise of official authority is a distinct legal basis under Article 6(1)(e) and does not require consent. Consent under Article 6(1)(a) and this public-interest/official-authority basis are separate and should not be treated as interchangeable. Where a controller is properly relying on official authority, layering consent on top can create confusion about the true basis for processing and may undermine the position, since a data subject cannot meaningfully withdraw a basis that does not depend on their agreement. You should identify a single, correct Article 6 basis rather than defaulting to consent as a universal requirement.
Is this basis available to any organisation that argues its processing serves the public good?
Not automatically. The basis is generally more constrained than a broad appeal to public benefit. Article 6(1)(e) refers to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. A general belief that an activity is socially useful is typically insufficient; there usually needs to be an identifiable underpinning in law, and member state law can shape and vary how this operates. Because national implementing law and regulator interpretation can diverge, the availability of this basis should be assessed against the specific legal framework applicable to the controller rather than assumed from the perceived worthiness of the purpose.
How do we establish that a processing activity qualifies under this basis?
In most cases you should be able to point to the task or authority and its basis in law, then confirm that the specific processing is necessary for that task rather than merely convenient. It is generally advisable to document the relevant legal underpinning, the nature of the official function, and the necessity assessment. Because the precise requirements can be shaped by member state or UK national law, verify the applicable framework and, where relevant, current regulator guidance rather than relying on a generic template.
What are the implications for data subject rights if we rely on this basis?
The choice of legal basis affects which rights apply. Where processing relies on the official authority basis, the right to data portability generally does not apply, and the right to erasure and the right to object operate differently than under consent or legitimate interests. In particular, the right to object can typically be raised in relation to processing on this basis, and the controller may need to assess whether compelling grounds exist to continue. You should map the applicable rights carefully against the basis actually relied upon, and note that the position can be affected by national derogations.
Can this basis be used to justify processing of special category data?
Not on its own. Article 6(1)(e) addresses the lawfulness of processing generally, but special category data under Article 9 requires an additional, separate condition to be met. Identifying an Article 6 basis does not by itself authorise processing of special category data; you would need to identify an applicable Article 9 condition as well. Because some of these conditions depend on member state or national law, confirm the specific condition and its legal underpinning before proceeding.
Should we still carry out a documented assessment even though this basis does not require a balancing test like legitimate interests?
It is generally advisable to document your reasoning even though this basis does not involve the same balancing exercise as legitimate interests. Recording the task or authority, its basis in law, the necessity of the processing, and how data subject rights are addressed supports accountability. Depending on the nature and risk of the processing, a Data Protection Impact Assessment under Article 35 may also be required; that is a separate exercise from selecting the legal basis and should be assessed against the applicable risk criteria and current guidance.

Common misconceptions

Exercise of official authority is the same as the public interest limb, so the two can be used interchangeably.
Both sit within Article 6(1)(e), but they are distinct limbs. The exercise of official authority refers to authority vested in the controller by law, while the public interest task limb is broader. In most cases the applicable law and the nature of the task determine which limb is engaged, and this should be identified specifically rather than treated as a single undifferentiated basis.
A public body relying on official authority must also obtain consent to be safe.
Consent and the exercise of official authority are separate Article 6 bases and are generally not combined for the same processing. Where a public authority relies on official authority, consent is typically not the appropriate or valid basis, particularly given the imbalance of power. Stacking consent on top can create confusion about the operative legal basis and about the rights that apply.
Invoking official authority alone is sufficient to process any category of data.
Article 6(1)(e) addresses only the lawfulness of processing under Article 6. Processing of special category data under Article 9 requires an additional and separate condition. The exercise of official authority does not by itself satisfy that further requirement, and a distinct Article 9 condition, often with a basis in member state law, is generally needed.

Best practices

Identify and document the specific Union or member state law that vests the relevant task or official authority in your organisation, rather than asserting the basis in general terms.
Specify which limb of Article 6(1)(e) you are relying on, distinguishing the exercise of official authority from the public interest task, and record the reasoning.
Carry out and document a necessity assessment, considering whether the objective could be achieved through less intrusive processing.
Where special category data is involved, separately identify and record an applicable Article 9 condition, checking any relevant national implementing law and derogations.
Map the data subject rights that apply under this basis, including handling of the right to object, and adjust privacy notices and internal procedures accordingly.
Verify the position against the current official GDPR text and applicable national law, and monitor for regulator guidance, as interpretation of who qualifies and how the basis applies can vary between jurisdictions.