Necessary for the Purposes
Under data protection law, most legal grounds for using personal data require that the processing be 'necessary' to achieve a particular aim. This generally means that if you could reasonably reach the same result in a less intrusive way, or without using the personal data at all, then the processing is not considered necessary. The test looks at whether the processing is a proportionate and reasonably targeted way to meet the stated purpose, rather than merely convenient or useful.
'Necessary for the purposes' is a threshold that qualifies most of the Article 6(1) lawful bases (for example, contract, legal obligation, vital interests, public task, and legitimate interests), as well as certain Article 9 conditions for special category data. According to ICO guidance, 'necessary' does not mean absolutely essential or unavoidable, but it does mean the processing must be a targeted and proportionate means of achieving the specified purpose; if the same purpose can reasonably be achieved by less intrusive means or without the processing, the necessity requirement is generally not met. Consent (Article 6(1)(a)) is the principal basis that does not turn on necessity, as noted in the evidence. The assessment is fact-specific and typically involves proportionality analysis, and practitioners should note that the precise application can vary by context, purpose, and the specific basis relied upon; this entry does not address every basis or member state derogation, and readers should verify article references and conditions against the current official UK GDPR or EU GDPR text.
Why it matters
The necessity requirement acts as a gatekeeper for most lawful bases under the GDPR. Because five of the six Article 6(1) grounds, contract, legal obligation, vital interests, public task, and legitimate interests, are qualified by the word 'necessary', an organisation cannot rely on them simply because processing personal data would be useful or convenient. As ICO guidance explains, if the same purpose can reasonably be achieved without the processing, or by a less intrusive route, the basis generally will not hold. This means the necessity test is often where the real scrutiny of a processing activity takes place.
Getting necessity wrong tends to undermine the entire lawfulness of processing. If a controller claims, for example, legitimate interests but a regulator or court finds the processing was not a targeted and proportionate means to the stated end, the processing may lack a valid basis altogether, exposing the organisation to compliance risk. The requirement therefore encourages data minimisation and proportionality in practice, pushing organisations to consider whether they need the personal data at all, and if so, how much.
It is important to note that necessity is fact-specific and assessed against a clearly articulated purpose. The same processing activity can be necessary for one purpose and unnecessary for another, so the analysis depends heavily on how the purpose is defined and on the specific basis relied upon. Practitioners should verify the applicable article references and conditions against the current official UK GDPR or EU GDPR text, as application can vary by context and member state derogation.
Who it's relevant to
Inside Necessary for the Purposes
Common questions
Answers to the questions practitioners most commonly ask about Necessary for the Purposes.