Performance of a Contract
In data protection, 'performance of a contract' is one of the recognised reasons an organisation can lawfully use someone's personal data. It generally applies when using the data is genuinely needed to deliver a contract that the individual is a party to, or to take steps the individual has asked for before entering into a contract. Note that the evidence provided here describes contract performance in a general commercial and contract-law sense rather than in the specific data protection context, so the details below should be verified against the current official regulatory text and guidance.
As a general contract-law concept, performance of a contract refers to the fulfilment by the parties of the obligations they undertook in an agreement, to a standard acceptable under the terms and applicable law. In the data protection context it is typically invoked as a lawful basis for processing personal data, which generally requires that the processing be objectively necessary either to perform a contract to which the data subject is a party, or to take pre-contractual steps at the data subject's request. The precise scope, the necessity threshold, and the specific article on which this basis rests should be confirmed against the current GDPR text and regulator guidance, as the evidence supplied does not address the data protection framing; this basis is also distinct from consent and from the other lawful bases, and processing of special category data would require an additional condition beyond a lawful basis. Member state implementing law and UK GDPR positions may vary and should be checked.
Why it matters
Performance of a contract is one of the recognised lawful bases an organisation may rely on to process personal data, and choosing it correctly matters because the lawful basis frames what an organisation can and cannot do with the data. This basis generally applies only where the processing is objectively necessary to deliver a contract to which the individual is a party, or to take pre-contractual steps at that individual's request. Selecting it when it does not genuinely fit, for example, where the processing is merely useful rather than necessary, can leave an organisation without a valid basis and exposed to challenge. The evidence supplied here describes contract performance in a general commercial and contract-law sense rather than in the specific data protection context, so the precise scope and threshold should be verified against the current GDPR text and regulator guidance.
The distinction also matters because relying on contractual necessity is different from relying on consent or the other lawful bases, and it carries different consequences for individuals' rights and for how the organisation must justify its processing. Where the processing involves special category data, an additional condition beyond the lawful basis is generally required. Getting the basis wrong at the outset can undermine an entire processing activity, since the basis typically cannot simply be swapped after the fact.
Because positions can differ between the EU GDPR, the UK GDPR, and national implementing law, and because the necessity threshold has been the subject of regulator guidance, organisations should treat the framing here as a starting point and confirm the applicable article, scope, and interpretation against current official sources rather than relying on a general contract-law description.
Who it's relevant to
Inside Performance of a Contract
Common questions
Answers to the questions practitioners most commonly ask about Performance of a Contract.