Lawful basis for processing
Lawful basis for processing requires that every instance of personal data processing be justified by at least one of the six legal grounds defined in Article 6 of the GDPR. Organizations must identify, document, and communicate this specific justification before any processing begins.
What it means
Under the GDPR, processing personal data is prohibited by default unless a specific lawful basis allows it. The organization cannot simply choose a basis for convenience; the choice must accurately reflect the relationship between the data controller and the data subject, as well as the purpose of the processing.
The six available bases are consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task in the public interest, and legitimate interests. While some bases are straightforward—such as fulfilling a statutory tax requirement—others require specific conditions to be met to remain valid.
For those relying on "legitimate interests," there is an added requirement to balance the organization's business needs against the individual's rights and freedoms. If the individual's privacy rights outweigh the business interest, that basis cannot be used without another justification.
How to meet it
- Create a Record of Processing Activities (RoPA) that lists every data processing operation and maps it to one of the six lawful bases in Article 6.
- Implement a mechanism for capturing and recording "freely given, specific, informed, and unambiguous" consent where applicable.
- Conduct and document a Legitimate Interest Assessment (LIA) whenever "legitimate interests" is selected as the basis.
- Update external privacy notices to explicitly state which lawful basis is being used for each category of data processing.
- Ensure that if processing is based on a contract, the data collected is strictly necessary for the execution of that specific contract.
- Establish a process to review and update the lawful basis if the purpose of the processing changes over time.
Evidence an auditor asks for
- A completed Record of Processing Activities (RoPA) showing the mapping of activities to Article 6 bases.
- Signed or timestamped consent logs demonstrating how and when user consent was obtained.
- Documented Legitimate Interest Assessments (LIAs) including the purpose test, necessity test, and balancing test.
- Public-facing privacy policies that clearly disclose the legal grounds for processing.
Common pitfalls
- Using "consent" as a catch-all basis when a more stable basis, such as "legal obligation" or "contract," is actually the correct one.
- Relying on "legitimate interests" without having a written LIA to justify why the organization's interests override the individual's privacy rights.
- Failing to update the lawful basis when data originally collected for one purpose (e.g., contract fulfillment) is used for another (e.g., marketing).