Skip to main content
Category: Lawful Basis for Processing

Official Authority

Simply put

"Official authority" generally refers to power or responsibility that has been granted by government or another qualified source to carry out a particular function. Depending on the context, it can describe either an institution created to perform public functions or a person holding an official role. The exact meaning is highly context-dependent, and the evidence available here does not tie the phrase to a specific legal definition under data protection law.

Formal definition

As reflected in the general-reference sources provided, "official authority" denotes power or responsibility sanctioned through authorization by a qualified officer or entity, typically one created by or acting on behalf of government to perform specified public functions or services. The sources indicate the term can attach to either a natural person holding an official role or an institution, and that "authority" is used broadly for many kinds of government-created bodies. The evidence packet supplies only general dictionary and reference material and does not establish a defined meaning for this phrase within the GDPR or any specific privacy instrument; readers should note that in a data protection context the related concept of processing necessary for the exercise of official authority is treated separately and should be verified against the current official text of the applicable law, as none of the sources here address that usage.

Why it matters

"Official authority" is a phrase that surfaces across many legal and governmental contexts, and its precise meaning depends heavily on the setting in which it is used. The general-reference sources reviewed here treat it as power or responsibility sanctioned through authorization by a qualified officer or entity, typically one created by or acting on behalf of government. Because the term can describe either a person holding an official role or an institution created to perform public functions, practitioners should not assume a single fixed definition applies wherever the phrase appears.

For privacy and data protection professionals, the significance of getting this term right lies in avoiding conflation. The evidence available here consists only of general dictionary and reference material and does not tie "official authority" to any defined meaning within the GDPR or another specific privacy instrument. In a data protection context, there is a separate and distinct concept concerning processing that is necessary for the exercise of official authority, but none of the sources provided here address that usage. Treating a general-reference definition as if it settled the data protection question would risk misapplying a legal basis or public-task concept that must be assessed against the actual text of the applicable law.

The practical takeaway is one of caution: readers encountering "official authority" should identify the governing instrument and verify the term against the current official text of the applicable law rather than relying on a general definition. The boundary of this entry is that it describes the ordinary-language and general-legal meaning only, and it does not establish how the phrase operates within GDPR, UK GDPR, or national implementing law.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance leads may encounter "official authority" in materials touching on public-function processing and should be careful to distinguish the ordinary-language meaning described here from any defined concept under the applicable data protection law. The sources here do not establish a GDPR meaning, so the relevant instrument and its text should be consulted directly.
Lawyers advising public bodies
Legal advisers working with government-created entities or officials will find that the phrase can refer either to a person in an official role or to an institution created to perform public functions. Advisers should confirm which sense is intended in a given instrument, since the definition is context-dependent and not fixed by the general-reference sources reviewed.
Engineers and product teams
Technical teams building systems that interact with government or public-function bodies may see "official authority" used loosely to describe an authorized entity. They should not treat it as a defined legal basis or technical requirement without confirming its meaning in the governing law or specification, as none of the sources here address that usage.

Inside Official Authority

Public task legal basis (Article 6(1)(e))
Official authority is one strand of the 'public task' lawful basis under Article 6(1)(e) GDPR, which permits processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. It is a distinct legal basis and should not be conflated with consent or legitimate interests.
Basis in Member State or Union law
Reliance on official authority generally requires that the authority be grounded in Union or Member State law, as contemplated by Article 6(3). The specific legal foundation and its scope can vary between jurisdictions, so the position may differ across the EU and under the UK GDPR.
Necessity requirement
The processing must be necessary for the exercise of the official authority. Necessity is assessed against whether the objective could reasonably be achieved by less intrusive means, and is subject to case-by-case evaluation rather than being presumed.
Typical controllers
This basis is generally associated with public authorities and bodies exercising conferred powers, though private entities may in some cases exercise official authority where such authority is vested in them by law. The availability of the basis depends on the legal source of the authority, not merely the identity of the controller.
Interaction with data subject rights
Where processing relies on official authority, certain data subject rights operate differently; for example, the right to erasure and the right to data portability are generally limited, while a right to object may apply subject to conditions. Practitioners should verify the precise position against the current text.

Common questions

Answers to the questions practitioners most commonly ask about Official Authority.

Does relying on official authority mean my organisation must be a government body?
Not necessarily. The public task basis under Article 6(1)(e) covers processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This can, in some cases, extend to private bodies that have been entrusted with relevant functions or powers, rather than being limited to public authorities in a narrow sense. Whether it applies depends on the underlying basis in EU or member state law, so this should be assessed case by case and verified against the applicable national implementing rules.
Is the exercise of official authority the same legal basis as compliance with a legal obligation?
No, these are distinct Article 6 bases. Compliance with a legal obligation under Article 6(1)(c) generally applies where the law requires the controller to process. The public task or official authority basis under Article 6(1)(e) applies where processing is necessary for a task in the public interest or in the exercise of official authority. They should not be conflated, and the correct basis depends on how the underlying law is framed. Where the position is unclear, the distinction should be assessed carefully, since it affects data subject rights and other obligations.
Where should the underlying legal basis for our official authority processing be documented?
The basis in EU or member state law that establishes the task or authority should typically be identifiable and recorded, for example within records of processing and internal governance documentation. Documenting the specific legal source supports accountability and helps demonstrate that the processing falls within the scope of the authority being relied upon. The precise expectations can vary by member state, so verify against applicable national law and current regulator guidance.
How should a controller assess whether processing is necessary for the exercise of official authority?
A necessity assessment generally considers whether the processing is genuinely required to perform the relevant task, or whether a less intrusive means could achieve the same aim. Necessity is context dependent and subject to assessment rather than assumed. Documenting the reasoning supports the accountability principle. Where special category data under Article 9 is involved, an additional condition is generally required beyond the Article 6 basis.
Which data subject rights are affected when relying on official authority?
The availability of certain rights can differ depending on the legal basis relied upon. In general terms, the right to object and rights connected to portability may operate differently under the public task or official authority basis than under some other bases. The exact position depends on the applicable provisions and any member state derogations, so this should be confirmed against the current official text and relevant guidance rather than assumed.
Should organisations relying on official authority still carry out a Data Protection Impact Assessment?
A Data Protection Impact Assessment under Article 35 is a separate exercise from selecting a legal basis, and reliance on official authority does not remove the need to consider whether a DPIA is required. A DPIA is generally expected where processing is likely to result in a high risk to individuals. Whether the threshold is met should be assessed on the specific processing, taking account of applicable regulator guidance.

Common misconceptions

Any public body can rely on official authority for all of its processing.
The basis is confined to processing that is necessary for the specific official authority vested in the controller and grounded in Union or Member State law. Public bodies frequently carry out processing that falls outside that authority and must identify an appropriate alternative Article 6 basis for it.
Official authority and public interest are interchangeable labels for the same thing.
Article 6(1)(e) covers two related but distinct limbs: a task carried out in the public interest, and the exercise of official authority. The correct limb should be identified because the underlying legal source and analysis may differ, and this should not be treated as settled by using the terms loosely.
Relying on official authority removes the need for a lawful basis for special category data.
Special category data under Article 9 requires a separate condition in addition to an Article 6 basis. Official authority under Article 6(1)(e) does not by itself satisfy Article 9, so an applicable Article 9 condition must also be identified and documented.

Best practices

Identify and document the specific Union or Member State law that vests the official authority relied upon, rather than asserting the basis generically.
Record a necessity assessment showing that the processing is necessary for the official authority and could not reasonably be achieved by less intrusive means.
Where special category data is involved, separately identify and document an applicable Article 9 condition in addition to Article 6(1)(e).
Map how data subject rights apply under this basis, noting which rights are generally limited and where a right to object may arise, and reflect this in privacy notices.
Confirm the position under the applicable national implementing law and, where relevant, the UK GDPR, since the legal foundation and derogations can vary by jurisdiction.
Review the chosen basis periodically against the current official text and regulator guidance, as the interpretation of necessity and scope can evolve.