Skip to main content
Category: Special Category Data

Legal Claims Basis

Also known as: establishment, exercise or defence of legal claims, legal claims condition
Simply put

Legal Claims Basis is a justification that lets an organisation process personal data when it is needed to bring, respond to, or defend a legal case or similar formal proceeding. It is commonly relied on when handling information for the purpose of establishing, exercising, or defending legal claims. Its precise availability and wording depend on the applicable data protection law and, in many cases, must be confirmed against the current official text.

Formal definition

Under EU and UK data protection frameworks, the establishment, exercise, or defence of legal claims functions in two distinct ways that should not be conflated. First, it can support a lawfulness assessment for ordinary personal data, typically as part of an Article 6 analysis (for example alongside legitimate interests or legal obligation), where the appropriate legal basis must be identified before processing. Second, and more specifically, it operates as an additional condition permitting the processing of special category data under the exception framework for such data, and can also feature in the assessment of certain data transfers. This entry describes GDPR-style data protection concepts and is separate from the general litigation sense of a 'legal claim' (a formal demand for compensation or an assertion by a claimant against a respondent) found in general legal usage. Practitioners should note that the availability, scope, and any associated conditions or safeguards can vary between the EU GDPR, the UK GDPR, and national implementing law, including member state derogations, and the exact article and condition numbers should be verified against the current official text and regulator guidance.

Why it matters

The establishment, exercise, or defence of legal claims occupies an important position in data protection compliance because organisations frequently need to process personal data in the course of litigation, regulatory proceedings, or the assertion and defence of rights, and doing so requires a defensible justification. Under GDPR-style frameworks, a controller must be able to identify an appropriate lawful basis before processing ordinary personal data, and this condition can form part of that analysis. It also carries particular weight for special category data, where processing is generally prohibited unless an additional condition applies, and the legal claims condition is one of the routes that may permit such processing subject to assessment.

Getting this distinction right matters because the legal claims condition operates at two different levels that should not be conflated. It is not itself an Article 6 lawful basis but can inform which basis (such as legitimate interests or legal obligation) is appropriate, while separately functioning as an additional condition for special category data and featuring in the assessment of certain data transfers. Treating it as a single, universal permission risks overstating its reach and omitting the legal basis or transfer analysis that must still be carried out.

Because availability, scope, and any associated safeguards can vary between the EU GDPR, the UK GDPR, and national implementing law, including member state derogations, practitioners cannot assume a uniform position across jurisdictions. The exact article and condition numbers, and the precise wording of the condition, should be verified against the current official text and regulator guidance rather than relied on from memory or a snapshot.

Who it's relevant to

Litigation and disputes lawyers
Lawyers handling claims, proceedings, or the defence of a client's position often need to process personal data, sometimes including special category data, to establish, exercise, or defend legal claims. They should understand how this condition interacts with the underlying lawful basis and any additional condition required for special category data, and verify the position under the applicable framework.
Data protection officers and privacy leads
DPOs and privacy teams advise on when the legal claims condition can be relied on, ensure it is not treated as a universal permission, and confirm that a separate Article 6 lawful basis is identified for ordinary personal data. They also assess whether the condition supports processing of special category data or informs a data transfer analysis, subject to jurisdiction-specific rules.
Compliance and risk teams
Compliance leads need to document the justification for processing personal data in the context of legal matters and to reflect the distinction between a lawful basis and an additional condition in their records. They should account for divergence between the EU GDPR, the UK GDPR, and national implementing law, and flag areas where the position should be verified against current guidance.
Engineers and system designers
Engineers building systems that retain or surface data for potential legal use benefit from understanding that reliance on the legal claims condition is generally tied to an actual or anticipated matter rather than open-ended retention. This affects how retention, access controls, and audit trails are designed to support a defensible position without overreaching the scope of the condition.

Inside Legal Claims Basis

Establishment, exercise or defence of legal claims
The specific condition under GDPR that permits certain processing where it is necessary in connection with actual or prospective legal proceedings, including bringing, defending, or preparing for claims. It functions both as an Article 9 condition for special category data and appears in related provisions such as restrictions on data subject rights.
Necessity requirement
The processing must be genuinely necessary for the legal claim in question, not merely convenient or precautionary. Necessity is assessed against the specific claim or proceeding, and controllers should generally be able to demonstrate the link between the data processed and the claim pursued or defended.
Relationship to legal bases under Article 6
This condition primarily addresses the additional requirement for special category data under Article 9. A controller relying on it should still identify and satisfy an appropriate Article 6 legal basis (for example legal obligation or legitimate interests), because the two layers operate separately and are not interchangeable.
Scope of covered proceedings
Typically understood to extend beyond formal court litigation to include administrative, regulatory, and out-of-court procedures where legal claims may be established, exercised, or defended. The precise breadth can depend on national implementing law and regulator guidance, so the boundary should be verified in the relevant jurisdiction.
Interaction with data subject rights
The existence of a legal claims context can affect how certain data subject rights apply, as some rights are subject to exemptions or restrictions where processing relates to legal claims. The availability and extent of such restrictions can vary and may be shaped by member state derogations and, for the UK, by UK GDPR and its implementing legislation.

Common questions

Answers to the questions practitioners most commonly ask about Legal Claims Basis.

Is 'legal claims' a standalone lawful basis under Article 6 that lets me process any personal data I want for litigation?
No. This is a common misconception. The establishment, exercise, or defence of legal claims is not one of the six Article 6 lawful bases (consent, contract, legal obligation, vital interests, public task, and legitimate interests). For ordinary personal data you still need to identify an Article 6 basis, which in practice is often legitimate interests, subject to a balancing assessment. The 'legal claims' concept functions primarily as a condition permitting the processing of special category data under Article 9 and as an exemption from certain data subject rights, rather than as a general licence to process. You should verify the specific provisions against the current official text.
Does the legal claims ground mean I never have to comply with data subject rights, such as erasure or access, during a dispute?
No. The legal claims ground does not switch off data subject rights wholesale. It operates as a targeted basis to restrict or refuse certain rights where processing is necessary for the establishment, exercise, or defence of legal claims, and its availability varies by right and can be shaped by member state implementing law. Each request should be assessed on its own facts, and the exemption is generally limited to what is necessary for the claim rather than a blanket exclusion. Where regulators diverge or national law adds conditions, you should check the applicable position.
How should I document reliance on the legal claims ground when handling special category data in a dispute?
Where you process special category data in connection with legal claims, you should record the relevant Article 9 condition you are relying on, identify the corresponding Article 6 lawful basis for the same processing, and note why the processing is necessary for the establishment, exercise, or defence of the claim. Documentation typically forms part of your record of processing activities and any legitimate interests assessment where that is the Article 6 basis. Because member state law may impose additional safeguards, confirm whether local conditions apply and verify article references against the current text.
How do I assess whether processing is 'necessary' for the establishment, exercise, or defence of legal claims?
Necessity is generally assessed against whether the processing genuinely relates to an actual or reasonably anticipated legal claim, dispute, or proceeding, and whether a less intrusive means would achieve the same purpose. In most cases you should be able to point to a specific claim or credible prospect of one, rather than a speculative or purely precautionary rationale. The assessment is context and risk dependent, and the boundary of what counts as 'reasonably anticipated' can be subject to interpretation, so record your reasoning at the time.
Can I retain personal data beyond my normal retention schedule because I might need it for potential legal claims?
Extended retention for potential legal claims can be defensible, but generally only where there is a credible basis to anticipate a claim and the retention period is proportionate to that purpose, for example aligned with applicable limitation periods. Indefinite or blanket retention justified by a vague possibility of litigation is harder to defend. You should tie the retention to a defined purpose and review it, and confirm the relevant limitation periods under the applicable national law, which can vary.
How does the legal claims ground interact with responding to a data subject access request during litigation?
Reliance on the legal claims ground does not automatically defeat an access request, and the interaction is fact specific. In many cases you must still respond, applying only those exemptions that are genuinely engaged, such as those protecting the establishment, exercise, or defence of legal claims or, separately, legally privileged material where applicable. The precise exemptions and their scope can depend on member state implementing law and on regulator and court guidance, which may diverge, so assess each request individually and verify the applicable provisions.

Common misconceptions

The legal claims condition on its own makes any related processing lawful and complete.
It is generally an additional condition rather than a standalone legal basis. For special category data it satisfies the Article 9 layer, but a separate Article 6 basis is still typically required, and the processing must independently meet other GDPR principles such as data minimisation and necessity.
It can be invoked to retain or process data indefinitely just in case a dispute might one day arise.
The condition depends on necessity in relation to actual or reasonably anticipated claims. Speculative or open-ended retention with no identifiable prospective claim is unlikely to be justified, and controllers should be prepared to demonstrate the connection to a genuine claim, subject to assessment.
Where a legal claim is involved, data subject rights no longer apply at all.
A legal claims context may support specific exemptions or restrictions on certain rights, but it does not switch off the regime wholesale. The scope of any restriction depends on the relevant provisions, national implementing law, and applicable guidance, which can diverge between regulators.

Best practices

Document, at the outset of processing, the specific actual or prospective legal claim relied upon and why the data processed is necessary to establish, exercise, or defend it.
Identify a separate Article 6 legal basis alongside this condition where special category data is involved, rather than treating the legal claims condition as sufficient on its own.
Apply data minimisation and defined retention criteria tied to the lifecycle of the claim, and review whether the necessity justification still holds as circumstances change.
Verify the scope of covered proceedings and any applicable rights restrictions against the current text of the relevant GDPR or UK GDPR provision and national implementing law, as member state derogations can vary the position.
Where relying on this condition to restrict a data subject right, assess and record the legal basis for the restriction case by case rather than applying a blanket exemption.
Consult current regulator guidance where the boundary of the condition is uncertain, and note in internal records that regulator interpretations may diverge and evolve.