Skip to main content
Category: Lawful Basis for Processing

Grounds for Lawful Processing

Also known as: Legal Basis for Processing, Lawful Basis, Legal Grounds for Processing, Legal Bases for Data Processing
Simply put

Under the GDPR, an organisation must have a valid reason recognised by law before it can use someone's personal data. These recognised reasons are known as the grounds (or legal bases) for lawful processing, and at least one must apply for the processing to be lawful. Consent is only one of several possible grounds, so it is not always required.

Formal definition

The grounds for lawful processing are the legal bases a controller must identify and rely upon to process personal data lawfully. Article 6(1) GDPR sets out six bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests (the UK GDPR guidance from the ICO also references a 'recognised legitimate interest' basis reflecting UK-specific provisions). Processing is lawful only if, and to the extent that, at least one of these applies, and the appropriate basis should be determined before processing begins. Note that this concept concerns Article 6 alone; where special category (sensitive) data is involved, a separate additional condition (generally under Article 9) is also required, and member state law or national derogations may affect the position. Readers should verify the current article text and applicable jurisdiction (EU GDPR vs UK GDPR).

Why it matters

The grounds for lawful processing sit at the foundation of the GDPR's lawfulness principle: without a valid legal basis, processing of personal data is generally unlawful regardless of how well an organisation secures or documents the data. Identifying the appropriate basis before processing begins is therefore not a formality but a gating requirement, and the choice of basis shapes the rights available to individuals. For example, the right to erasure and the right to data portability apply differently depending on whether processing rests on consent, contract, or another basis, so an incorrect or unexamined choice can undermine an organisation's ability to respond correctly to data subject requests.

A common and costly misconception is that consent is always required. In fact, consent is only one of six bases under Article 6(1), and relying on it inappropriately, for instance where the relationship is imbalanced or where consent cannot be freely given or withdrawn, can leave processing without a defensible foundation. Selecting the most suitable basis at the outset avoids the difficulty of switching bases later, which regulators generally regard as problematic because it can confuse individuals about their rights.

The stakes rise where special category (sensitive) data is involved. In those cases an Article 6 basis alone is insufficient, and a separate additional condition, generally under Article 9, must also be satisfied. Because member state law and national derogations can vary the position, and because the UK GDPR framework references a 'recognised legitimate interest' basis not identically framed in the EU text, organisations operating across jurisdictions should confirm which regime applies rather than assuming a single uniform answer.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams are typically responsible for ensuring that each processing activity is mapped to an appropriate and documented legal basis before it begins. They need to guard against over-reliance on consent, confirm that any special category data has a valid additional Article 9 condition, and account for jurisdictional differences such as the UK GDPR's 'recognised legitimate interest' basis and any applicable national derogations.
Privacy and Data Protection Lawyers
Legal advisers assess whether a chosen basis is defensible for a given purpose and advise on the consequences of that choice, including the effect on data subject rights such as erasure and portability. They should verify the current article text and applicable regime (EU GDPR versus UK GDPR) rather than assuming a uniform position across member states.
Engineers and Product Teams
Because the appropriate basis should be determined before processing begins, engineers and product teams building systems that handle personal data benefit from involving privacy colleagues early. The legal basis can influence design decisions, for example whether consent mechanisms, withdrawal functionality, or particular data handling controls are needed for a given feature.
Controllers Operating Across the EU and UK
Organisations subject to both the EU GDPR and the UK GDPR should confirm which framework applies to a given processing activity, since the available bases and their framing can differ, and member state law or national derogations may affect the position. They should treat any snapshot of the rules as something to verify against the current official text.

Inside Grounds for Lawful Processing

Consent
A legal basis under Article 6(1)(a) requiring a freely given, specific, informed, and unambiguous indication of the data subject's wishes, given by a clear affirmative action. It is generally revocable, and controllers should be able to demonstrate that valid consent was obtained.
Contract
A legal basis under Article 6(1)(b) applying where processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the data subject's request prior to entering into a contract. The necessity threshold is typically interpreted narrowly.
Legal obligation
A legal basis under Article 6(1)(c) where processing is necessary to comply with a legal obligation to which the controller is subject. The obligation generally must derive from EU or member state law, and member state derogations may vary the position.
Vital interests
A legal basis under Article 6(1)(d) where processing is necessary to protect the vital interests of the data subject or another natural person. It is typically reserved for situations involving matters of life and death or serious threats to health.
Public task
A legal basis under Article 6(1)(e) where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. Its scope is generally shaped by EU or member state law.
Legitimate interests
A legal basis under Article 6(1)(f) where processing is necessary for the legitimate interests pursued by the controller or a third party, except where overridden by the interests or fundamental rights and freedoms of the data subject. This basis generally requires a balancing assessment and is subject to limitations, including for public authorities acting in the performance of their tasks.
Additional condition for special category data
Where personal data falls within the special categories under Article 9, an Article 6 legal basis alone is generally insufficient; a separate condition under Article 9 must also be satisfied. Member state law may impose further requirements.

Common questions

Answers to the questions practitioners most commonly ask about Grounds for Lawful Processing.

Is consent always required to process personal data lawfully?
No. Consent is only one of the six lawful bases set out in Article 6 of the GDPR, alongside contract, legal obligation, vital interests, public task, and legitimate interests. A controller must identify the most appropriate basis for the specific processing activity; in many operational contexts a basis other than consent will be more suitable. Treating consent as a universal requirement is a common misconception and can create difficulties, for example where consent would not be freely given or would be impractical to withdraw.
Does identifying an Article 6 lawful basis mean special category data can be processed too?
Not on its own. Where processing involves special category data (such as health, biometric, or data revealing racial or ethnic origin), an Article 6 lawful basis is necessary but not sufficient. An additional condition under Article 9 must also be satisfied, and national implementing law or member state derogations may impose further requirements. The two layers should be assessed and documented separately rather than assumed to follow automatically from one another.
How should a controller select the appropriate lawful basis for a processing activity?
Selection is generally made before processing begins by mapping the specific purpose to the most appropriate of the six Article 6 bases, considering the nature of the relationship with the data subject, the necessity of the processing for that purpose, and the practical consequences of each basis (for example, rights that attach differently depending on the basis chosen). The assessment is context and risk dependent, and where special category data is involved an Article 9 condition must also be identified. Regulators generally expect the basis to be settled in advance rather than changed later without good reason.
Can a controller switch lawful bases part-way through processing?
Switching bases is generally discouraged and, in most cases, should not be treated as a routine option, because the lawful basis is expected to be determined before processing starts and communicated in the information provided to data subjects. Changing basis can undermine transparency and affect the rights available to individuals. Where a controller believes a change may be necessary, it should assess the position carefully, document the reasoning, and consider whether fresh information to data subjects is required. Approaches can vary, so the position should be checked against current regulatory guidance.
Where should the chosen lawful basis be recorded and communicated?
The lawful basis typically needs to be reflected in internal accountability documentation (such as records of processing activities) and in the transparency information provided to data subjects, for example in a privacy notice. Where special category data is processed, the relevant Article 9 condition should also be recorded. The precise documentation expectations can be shaped by national implementing law and regulator guidance, so controllers should verify current requirements against the applicable official texts.
What practical difference does the choice of lawful basis make to data subject rights?
The lawful basis relied upon can affect which data subject rights apply and how they operate; for example, certain rights are more closely associated with some bases than others. Because the consequences differ, the choice of basis is not merely a formality and should be made with the downstream rights implications in mind. As the interaction between bases and rights can be nuanced and subject to guidance, controllers should assess the specific position for each processing activity rather than assume a uniform outcome.

Common misconceptions

Consent is required for all personal data processing.
Consent is only one of six legal bases under Article 6. In many cases another basis, such as contract, legal obligation, or legitimate interests, is more appropriate, and relying on consent where it cannot be freely given or withdrawn may be problematic.
Once a legal basis is chosen, it can be freely swapped later if it becomes inconvenient.
The appropriate basis should generally be identified before processing begins, and switching bases after the fact is typically difficult to justify and may undermine transparency obligations. The correct choice depends on the specific purpose and context.
Having an Article 6 basis is enough to process any type of personal data.
For special category data under Article 9, an Article 6 basis must generally be supplemented by a separate Article 9 condition, and member state implementing law may add further requirements.

Best practices

Identify and document the most appropriate Article 6 legal basis for each processing purpose before processing begins, rather than defaulting to consent.
Assess whether special category data under Article 9 is involved and, if so, identify a valid additional Article 9 condition alongside the Article 6 basis.
Where relying on legitimate interests, conduct and record a balancing assessment weighing the controller's or third party's interests against the data subject's rights and freedoms.
Where relying on consent, ensure it is freely given, specific, informed, and unambiguous, keep records demonstrating it, and provide an accessible mechanism to withdraw it.
Reflect the chosen legal basis in privacy information and internal records of processing to support transparency and accountability.
Check for relevant member state derogations or national implementing law, and verify positions against the current official text, as scope and conditions can vary.