Skip to main content
Category: Lawful Basis for Processing

Necessity

Also known as: necessity test, necessary
Simply put

In data privacy, necessity is a test that asks whether processing personal data is genuinely needed to achieve a specific, legitimate purpose, rather than merely useful or convenient. If the same goal can reasonably be met in a way that uses less personal data or is less intrusive, the processing is generally not considered necessary. Necessity is assessed against the particular purpose and circumstances, so its application varies case by case.

Formal definition

Necessity is a threshold condition embedded across several legal bases and principles in data protection law, requiring that processing be objectively necessary for, and proportionate to, a defined lawful purpose rather than simply beneficial. It functions as a factual and legal assessment: a controller must be able to demonstrate that the processing is the least intrusive reasonable means of achieving the stated purpose, and that no realistic, less privacy-invasive alternative exists. The evidence packet provided contains only general-language and unrelated legal (criminal necessity defense) sources and does not supply GDPR text, article numbers, or regulator guidance; accordingly, the precise statutory framing of necessity within specific GDPR provisions and its interaction with the proportionality requirement should be verified against the current official Regulation text and competent supervisory authority guidance, which may diverge across jurisdictions and the UK GDPR.

Why it matters

Necessity operates as a gatekeeping test in data protection: it constrains processing to what is genuinely required for a defined, legitimate purpose rather than what is merely useful, convenient, or commercially attractive. Because the test asks whether a less intrusive or less data-hungry alternative could reasonably achieve the same goal, it directly limits the volume and sensitivity of personal data an organisation can lawfully process. Where a controller cannot demonstrate that processing was the least intrusive reasonable means of meeting its stated purpose, the processing generally fails the necessity threshold, regardless of any consent or business justification offered.

The practical significance is that necessity is not a one-time box-ticking exercise but a case-by-case, fact-sensitive assessment tied to a specific purpose and circumstances. This means the same activity may be necessary in one context and unnecessary in another, and controllers bear the burden of being able to show their reasoning. The evidence available for this entry consists only of general-language dictionary sources and an unrelated criminal-law necessity defence, and does not supply GDPR text, article numbers, or supervisory authority guidance. The precise statutory framing of necessity, and how it interacts with proportionality, should therefore be verified against the current official Regulation text and competent regulator guidance, which may diverge across EU member states and under the UK GDPR.

Who it's relevant to

Data Protection Officers and privacy leads
DPOs and privacy teams apply the necessity test when reviewing new or existing processing activities, checking whether the data used is genuinely required for the stated purpose or whether a less intrusive approach would suffice. They should document the reasoning behind necessity conclusions, since the test is fact-sensitive and controllers may need to demonstrate it.
Compliance and legal counsel
Lawyers and compliance leads rely on necessity as a threshold condition when assessing whether processing is defensible for a defined lawful purpose. Because the precise statutory framing and its interaction with proportionality are not established by the sources here, counsel should verify the applicable provisions against the current official Regulation text and relevant supervisory authority guidance, noting potential divergence across jurisdictions and the UK GDPR.
Engineers and product teams
Those designing systems and data flows encounter necessity when deciding what personal data to collect or retain. Building toward the least intrusive reasonable means of achieving a purpose, for example, avoiding collection of data that is merely convenient rather than required, helps align a product with the necessity test, which is assessed against the specific purpose and circumstances.

Inside Necessity

Necessity test
An objective assessment of whether processing is genuinely required to achieve a specified, legitimate purpose, rather than merely useful or convenient. Necessity is generally read together with proportionality in EU data protection law and draws on case law and regulatory guidance.
Link to a lawful basis
Several Article 6 legal bases are framed around necessity, for example processing necessary for the performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a public task, or the purposes of legitimate interests. The necessity requirement attaches to the specific basis relied upon and is assessed against that basis.
Less intrusive means
A core element is whether the purpose could reasonably be achieved by a less privacy-intrusive method, processing less data, or without the processing at all. If a reasonable alternative exists, the processing is typically not considered necessary.
Relationship to data minimisation
Necessity supports the data minimisation principle, under which personal data should generally be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. The two concepts are closely connected but distinct.
Contextual and evidential character
Necessity is context and risk dependent and generally requires documented reasoning tied to a defined purpose. It is not a fixed label that applies uniformly, and its assessment can vary with the facts and, where relevant, member state derogations.

Common questions

Answers to the questions practitioners most commonly ask about Necessity.

Does 'necessary' mean that processing is simply useful or convenient for our business?
No. In the GDPR context, necessity is generally interpreted more strictly than mere usefulness or convenience. Regulatory guidance and case law have indicated that processing is typically 'necessary' only where the purpose cannot reasonably be achieved by other, less intrusive means. A processing activity being helpful, efficient, or commercially preferable does not, on its own, satisfy the necessity requirement. The assessment is objective and tied to the specific purpose relied upon, so the reader should evaluate whether a genuine, proportionate link exists rather than assuming that any beneficial use qualifies.
Is necessity the same thing as having consent or another lawful basis?
Not quite. Necessity and lawful basis are distinct but connected concepts. Several Article 6 lawful bases (such as contract, legal obligation, vital interests, public task, and legitimate interests) are expressly framed around processing being 'necessary' for a stated purpose, so necessity forms part of the test for relying on them. Consent, by contrast, does not depend on a necessity test in the same way. Even where consent is the basis, the broader data minimisation principle still constrains processing to what is adequate, relevant, and limited to what is necessary. Necessity is therefore better understood as a condition woven through the framework rather than a synonym for any single lawful basis.
How do we document that a processing activity meets the necessity requirement?
Generally, organisations record their necessity analysis alongside the relevant lawful basis, often within records of processing, a legitimate interests assessment where that basis is used, or a data protection impact assessment for higher-risk processing. Useful documentation typically identifies the specific purpose, explains why the processing is required to achieve it, and notes the less intrusive alternatives considered and why they were insufficient. Because the accountability principle requires organisations to demonstrate compliance, contemporaneous and purpose-specific records are usually more defensible than generic statements. The appropriate format may vary by activity and risk level.
How does necessity interact with data minimisation when deciding what data to collect?
Necessity and data minimisation operate together in practice. Necessity tends to test whether a given processing operation is required for the purpose, while data minimisation asks whether the data involved is adequate, relevant, and limited to what is necessary for that purpose. In implementation, teams typically start from the defined purpose and work backwards to the minimum categories and volume of personal data needed. Collecting additional fields 'just in case' generally sits in tension with both concepts. Where a field's role in the purpose cannot be articulated, that usually signals a necessity and minimisation concern to revisit.
How should we assess whether a less intrusive alternative exists?
A necessity assessment typically involves identifying the intended purpose and then considering whether reasonably available alternatives could achieve it with less impact on individuals. Options to weigh may include using less data, using aggregated or pseudonymised data, shortening retention, or narrowing who has access. The alternative should be genuinely capable of meeting the purpose, not merely theoretical. Where a less intrusive option is both effective and reasonably practicable, the more intrusive approach is generally harder to justify as necessary. This evaluation is context and risk dependent and may benefit from being revisited as circumstances or available tools change.
Does the necessity assessment need to be repeated over time?
In most cases, necessity is not a one-off determination. Because the analysis is tied to a specific purpose and the surrounding circumstances, changes to the purpose, the data used, available less intrusive methods, or the risk profile can affect whether processing remains necessary. Many organisations therefore review their necessity and lawful basis analysis periodically and when a material change occurs, and retain updated records to support accountability. The appropriate frequency of review is context dependent, and readers should align it with their own risk management and governance arrangements.

Common misconceptions

Necessity means the same as helpful, efficient, or commercially desirable.
Necessity generally sets a higher bar than usefulness. Processing that merely improves convenience or efficiency is typically not necessary if the purpose can reasonably be achieved by less intrusive means or without the processing.
If processing is necessary, consent is still required from the individual.
Consent and necessity-based bases are distinct Article 6 legal bases. Where processing is genuinely necessary for, for example, a contract or a legal obligation, consent is generally not the appropriate basis, and treating consent as a universal requirement can be misleading.
Once necessity is established for a purpose, it holds indefinitely and for any related activity.
Necessity is assessed against a specific purpose and can change as circumstances, alternatives, or purposes change. It should typically be reviewed, and it does not automatically extend to further or incompatible processing.

Best practices

Define the specific, legitimate purpose before assessing necessity, and tie the necessity analysis to the particular Article 6 basis being relied upon rather than to necessity in the abstract.
Actively consider and document whether a less intrusive means, less data, or no processing could reasonably achieve the purpose, and record why any chosen approach is the least intrusive viable option.
Distinguish necessity from mere usefulness in your reasoning, and avoid absolute framing such as always necessary; use qualified, evidence-based language subject to the facts.
Apply necessity alongside data minimisation, limiting the categories, volume, and retention of personal data to what the purpose genuinely requires.
Document the necessity assessment so it can be produced to demonstrate accountability, and review it periodically or when purposes, alternatives, or circumstances change.
Where special category data is involved, remember that an additional Article 9 condition is required in addition to satisfying necessity under the relevant Article 6 basis, and verify the position against the current official text and applicable national derogations.