Skip to main content
Category: Lawful Basis for Processing

Necessary for the Purposes

Also known as: Necessity, Necessity Test, Necessary Processing
Simply put

Under data protection law, most legal grounds for using personal data require that the processing be 'necessary' to achieve a particular aim. This generally means that if you could reasonably reach the same result in a less intrusive way, or without using the personal data at all, then the processing is not considered necessary. The test looks at whether the processing is a proportionate and reasonably targeted way to meet the stated purpose, rather than merely convenient or useful.

Formal definition

'Necessary for the purposes' is a threshold that qualifies most of the Article 6(1) lawful bases (for example, contract, legal obligation, vital interests, public task, and legitimate interests), as well as certain Article 9 conditions for special category data. According to ICO guidance, 'necessary' does not mean absolutely essential or unavoidable, but it does mean the processing must be a targeted and proportionate means of achieving the specified purpose; if the same purpose can reasonably be achieved by less intrusive means or without the processing, the necessity requirement is generally not met. Consent (Article 6(1)(a)) is the principal basis that does not turn on necessity, as noted in the evidence. The assessment is fact-specific and typically involves proportionality analysis, and practitioners should note that the precise application can vary by context, purpose, and the specific basis relied upon; this entry does not address every basis or member state derogation, and readers should verify article references and conditions against the current official UK GDPR or EU GDPR text.

Why it matters

The necessity requirement acts as a gatekeeper for most lawful bases under the GDPR. Because five of the six Article 6(1) grounds, contract, legal obligation, vital interests, public task, and legitimate interests, are qualified by the word 'necessary', an organisation cannot rely on them simply because processing personal data would be useful or convenient. As ICO guidance explains, if the same purpose can reasonably be achieved without the processing, or by a less intrusive route, the basis generally will not hold. This means the necessity test is often where the real scrutiny of a processing activity takes place.

Getting necessity wrong tends to undermine the entire lawfulness of processing. If a controller claims, for example, legitimate interests but a regulator or court finds the processing was not a targeted and proportionate means to the stated end, the processing may lack a valid basis altogether, exposing the organisation to compliance risk. The requirement therefore encourages data minimisation and proportionality in practice, pushing organisations to consider whether they need the personal data at all, and if so, how much.

It is important to note that necessity is fact-specific and assessed against a clearly articulated purpose. The same processing activity can be necessary for one purpose and unnecessary for another, so the analysis depends heavily on how the purpose is defined and on the specific basis relied upon. Practitioners should verify the applicable article references and conditions against the current official UK GDPR or EU GDPR text, as application can vary by context and member state derogation.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams rely on the necessity test when documenting and defending the lawful basis for a processing activity. Because most Article 6(1) bases are qualified by necessity, records of processing and lawful basis assessments should articulate the purpose and explain why the processing is a targeted and proportionate means to that end rather than merely convenient.
Privacy and Data Protection Lawyers
Legal advisers apply the necessity threshold when advising on which lawful basis to rely upon and when conducting proportionality analysis. The fact-specific nature of necessity, and its interaction with less-intrusive-means reasoning, makes it central to opinions on legitimate interests, contract, and public task, as well as to certain Article 9 conditions for special category data. Advisers should confirm article references and conditions against the current official text.
Product and Engineering Teams
Engineers and product owners translate the necessity principle into system design by considering whether personal data is needed at all, and if so, how to minimise it. Because processing that could reasonably achieve the same result in a less intrusive way is generally not considered necessary, teams are encouraged to design for data minimisation and proportionality from the outset.
Organisations Relying on Legitimate Interests or Contract
Controllers using bases such as legitimate interests (Article 6(1)(f)) or contract face particular scrutiny under the necessity test, since these are among the grounds that require processing to be necessary for a specified purpose. Note that consent is the principal basis that does not turn on necessity, which affects how organisations choose between grounds.

Inside Necessary for the Purposes

Necessity Test
The assessment of whether the intended processing is genuinely required to achieve a specified purpose, rather than merely useful, convenient, or preferred. The test generally asks whether the purpose could reasonably be achieved by a less intrusive means or with less data.
Link to a Lawful Basis
The concept of necessity is embedded across several Article 6 legal bases (for example, processing necessary for the performance of a contract, for compliance with a legal obligation, to protect vital interests, for a public task, or for legitimate interests). Necessity is assessed in relation to the specific basis relied upon, not in the abstract.
Objective Character
Necessity is generally understood as an objective standard informed by regulatory guidance and case law, rather than solely the controller's subjective view that the processing is necessary. What the organization finds commercially desirable does not automatically make processing necessary.
Relationship to Data Minimisation
Necessity is closely connected to the data minimisation principle, under which personal data should be adequate, relevant, and limited to what is required for the purpose. Determining what is necessary typically also shapes how much data may be processed and for how long.
Purpose Specificity
Necessity cannot be evaluated without a clearly defined and specified purpose. The narrower and more precisely articulated the purpose, the more focused the necessity assessment becomes.

Common questions

Answers to the questions practitioners most commonly ask about Necessary for the Purposes.

Does "necessary" mean the processing must be absolutely indispensable or impossible to avoid?
No. In the data protection context, "necessary" is not interpreted as strictly indispensable or the only conceivable option. Guidance and case law from the Court of Justice of the EU have generally treated necessity as meaning that the processing must be a targeted and proportionate way of achieving the stated purpose, where that purpose cannot reasonably be achieved by a less intrusive means. The test sits between mere usefulness and absolute indispensability, and its precise application is fact-specific and subject to assessment.
If processing is convenient or beneficial for our business, does that make it "necessary"?
Not on its own. Convenience, commercial benefit, or general usefulness does not satisfy the necessity test. The relevant question is typically whether the processing is genuinely required to achieve the specified purpose, and whether a less intrusive alternative could reasonably achieve the same aim. Where a reasonable alternative exists, the processing may not be regarded as necessary. This is a proportionality-based assessment rather than a business-preference one.
How should we document that processing is necessary for a given purpose?
It is generally advisable to record, for each processing activity, the specific purpose, the personal data involved, and the reasoning showing why the data used is required to achieve that purpose. Documenting whether less intrusive alternatives were considered and why they were not adopted helps evidence the necessity and proportionality assessment. The appropriate level of detail typically scales with the sensitivity of the data and the risk to individuals, and should be verified against your organisation's accountability obligations.
How does the necessity test interact with the choice of legal basis under Article 6?
Necessity is a built-in element of several Article 6 bases: for example, the contract, legal obligation, vital interests, public task, and legitimate interests bases each require that the processing be necessary for the relevant purpose. Consent is structured differently and does not turn on a necessity test in the same way. Because necessity is assessed against the specific purpose tied to the chosen basis, the analysis differs depending on which basis is relied upon, and this should be worked through case by case.
How does the necessity assessment relate to data minimisation?
The two are closely connected but distinct. Necessity concerns whether the processing activity as a whole is required to achieve the purpose, while data minimisation concerns limiting the personal data to what is adequate, relevant, and limited to what is required for that purpose. In practice, assessing necessity typically involves examining whether each category of data being processed is genuinely required, which supports and overlaps with minimisation.
What should we do if a less intrusive alternative exists but is more costly or complex to implement?
The existence of a less intrusive alternative is a relevant factor, but the assessment generally considers whether that alternative could reasonably achieve the same purpose, taking practical feasibility into account. Cost and complexity may be part of what is reasonable, but they do not automatically justify a more intrusive approach. This is a proportionality judgement that is context-dependent and subject to assessment, and where the position is uncertain it is prudent to document the reasoning and, where appropriate, seek further guidance.

Common misconceptions

If processing is helpful or improves a service, it is necessary.
Usefulness or convenience is generally not the same as necessity. The assessment typically turns on whether the purpose could reasonably be achieved by less intrusive means or with less data. Something being beneficial to the organization does not, on its own, satisfy the necessity requirement.
Necessity applies only where consent is the legal basis.
Necessity is a criterion that features across several Article 6 bases (such as contract, legal obligation, vital interests, public task, and legitimate interests). Consent is a distinct basis that does not itself rely on a necessity test, so treating necessity as a consent-specific concept is inaccurate.
The controller's own judgment that processing is necessary is decisive.
Necessity is generally treated as an objective question informed by guidance and case law, subject to assessment and potential regulatory or judicial review. A controller's belief that processing is necessary is not conclusive and may diverge from how a supervisory authority interprets the standard.

Best practices

Define the processing purpose precisely before assessing necessity, since necessity cannot be evaluated meaningfully against a vague or overly broad purpose.
Test necessity against less intrusive alternatives, documenting whether the purpose could reasonably be achieved with less data or a lower-impact method.
Tie the necessity analysis to the specific Article 6 legal basis relied upon, rather than assessing necessity in the abstract, and remember that special category data under Article 9 requires an additional condition.
Apply data minimisation alongside necessity, limiting the categories, volume, and retention of personal data to what the assessment shows is genuinely required.
Record the reasoning behind the necessity determination so it can be demonstrated and revisited if the purpose, processing, or applicable guidance changes.
Use qualified, evidence-based conclusions and treat necessity as context-dependent and subject to review, verifying interpretations against current official text and regulatory guidance where positions may diverge.