CHAPTER IIPRINCIPLES

Article 6Lawfulness of processing

Official text

(1)Processing shall be lawful only if and to the extent that at least one of the following applies:

(a)the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

(b)processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

(c)processing is necessary for compliance with a legal obligation to which the controller is subject;

(d)processing is necessary in order to protect the vital interests of the data subject or of another natural person;

(e)processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

(f)processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

Point (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks.

(2)Member States may maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with regard to processing for compliance with points (c) and (e) of paragraph 1 by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing including for other specific processing situations as provided for in Chapter IX.

(3)The basis for the processing referred to in point (c) and (e) of paragraph 1 shall be laid down by:

(a)Union law; or

(b)Member State law to which the controller is subject.

The purpose of the processing shall be determined in that legal basis or, as regards the processing referred to in point (e) of paragraph 1, shall be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. That legal basis may contain specific provisions to adapt the application of rules of this Regulation, inter alia: the general conditions governing the lawfulness of processing by the controller; the types of data which are subject to the processing; the data subjects concerned; the entities to, and the purposes for which, the personal data may be disclosed; the purpose limitation; storage periods; and processing operations and processing procedures, including measures to ensure lawful and fair processing such as those for other specific processing situations as provided for in Chapter IX. The Union or the Member State law shall meet an objective of public interest and be proportionate to the legitimate aim pursued.

(4)Where the processing for a purpose other than that for which the personal data have been collected is not based on the data subject’s consent or on a Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23 (1), the controller shall, in order to ascertain whether processing for another purpose is compatible with the purpose for which the personal data are initially collected, take into account, inter alia:

(a)any link between the purposes for which the personal data have been collected and the purposes of the intended further processing;

(b)the context in which the personal data have been collected, in particular regarding the relationship between data subjects and the controller;

(c)the nature of the personal data, in particular whether special categories of personal data are processed, pursuant to Article 9, or whether personal data related to criminal convictions and offences are processed, pursuant to Article 10;

(d)the possible consequences of the intended further processing for data subjects;

(e)the existence of appropriate safeguards, which may include encryption or pseudonymisation.

Commentary

Article 6 is the cornerstone of the GDPR. While Article 5 lays down the fundamental principles governing personal data processing, Article 6 determines when processing is lawful. Every processing activity must satisfy at least one of the six lawful bases contained in Article 6(1). If no lawful basis applies, the processing is unlawful regardless of whether the controller complies with the remaining provisions of the GDPR.

Article 6 therefore answers one of the most important questions under European data protection law-"Why is the controller legally entitled to process personal data?"

A common misconception is that consent is the default lawful basis under the GDPR. This is incorrect. Consent is only one of six equally valid lawful bases. In many situations, processing is more appropriately based upon contractual necessity, legal obligations, vital interests, public tasks or legitimate interests. Selecting an inappropriate lawful basis may invalidate the entire processing operation and may expose the controller to regulatory action.

Article 6 must be interpreted together with Recitals 40 to 50, Articles 5, 7, 9 and 10, the Charter of Fundamental Rights of the European Union, the CJEU's jurisprudence, and the EDPB Guidelines 2/2019 on Article 6(1)(b), Guidelines 05/2020 on Consent, Guidelines 06/2020 on the interplay between Article 3 and Chapter V, and Opinion 06/2014 of the former Article 29 Working Party on Legitimate Interests.

Article 6(1): General Rule

Article 6(1) establishes the general rule that processing shall be lawful only if and to the extent that at least one of the six lawful bases applies.

The wording "only if and to the extent that" is significant. It imposes two cumulative requirements.

First, the controller must identify an applicable lawful basis before commencing processing.

Secondly, the processing must remain within the scope of that lawful basis throughout its lifecycle. A controller cannot rely upon one lawful basis for collection and subsequently process the same data for an unrelated purpose without satisfying the conditions for further processing under the GDPR.

The lawful basis should therefore be identified before personal data is collected, documented as part of the controller's accountability obligations, communicated to data subjects through the privacy notice under Articles 13 and 14, and applied consistently throughout the processing operation.

Controllers cannot freely change the lawful basis once processing has begun merely because another basis later appears more convenient. The European Data Protection Board has repeatedly emphasised that changing the lawful basis retrospectively would undermine transparency, fairness and legal certainty.

Choosing the Appropriate Lawful Basis

The six lawful bases are not hierarchical. The GDPR does not suggest that consent should always be preferred over legitimate interests or contractual necessity. Instead, controllers must objectively determine which basis genuinely reflects the nature and purpose of the processing.

The selection depends upon factors such as:

  • the relationship between the controller and the data subject;
  • the purpose of processing;
  • the expectations of the data subject;
  • the applicable legal framework;
  • the nature of the personal data; and
  • the consequences of refusing the processing.

Selecting an inappropriate lawful basis may have significant legal consequences. For example, where processing is wrongly based on consent despite the existence of an imbalance of power, the consent may be invalid. Conversely, relying upon legitimate interests where a specific statutory obligation exists may also be inappropriate.

Controllers should therefore assess the lawful basis objectively rather than selecting whichever appears administratively convenient.

Article 6(1)(a): Consent

Processing is lawful where the data subject has given consent to the processing of personal data for one or more specific purposes.

Consent is often regarded as the most visible lawful basis because it places the decision directly in the hands of the data subject. However, it is also one of the most demanding lawful bases under the GDPR.

Consent under Article 6(1)(a) should always be read together with Article 4(11) and Article 7, which prescribe the conditions for valid consent.

For consent to be valid, it must be:

  • freely given;
  • specific;
  • informed;
  • unambiguous; and
  • communicated through a clear affirmative action.

Silence, inactivity or pre-ticked boxes do not constitute valid consent.

Similarly, consent obtained through coercion, imbalance of bargaining power or bundled acceptance of unrelated processing activities is unlikely to satisfy the GDPR.

Recitals 32, 42 and 43 explain that consent represents a genuine expression of free choice and should not be regarded as valid where the individual has no real or free opportunity to refuse or withdraw consent without detriment.

Consent is generally appropriate where the individual has a genuine and meaningful choice regarding whether processing should occur.

Examples

include:

  • subscribing to marketing newsletters;
  • agreeing to optional analytics cookies;
  • participating in voluntary research projects;
  • receiving promotional communications; or
  • sharing personal information with third parties for optional services. Conversely, consent is usually inappropriate where processing is objectively necessary for another lawful basis. For example, an employer should generally avoid relying upon employee consent for routine HR processing because the employment relationship creates an imbalance of power that may undermine the voluntary nature of consent. Similarly, a bank should not seek consent merely to process personal data necessary to maintain customer accounts where the processing is actually required for contractual performance.

One distinguishing feature of consent is that it may be withdrawn at any time.

Withdrawal must be:

  • as easy as giving consent;
  • free of charge;
  • effective immediately unless another lawful basis applies; and
  • respected without unnecessary delay.

Withdrawal does not affect processing lawfully undertaken before the withdrawal occurred. However, it prevents further processing based solely upon consent.

Controllers should therefore establish practical mechanisms enabling individuals to withdraw consent without undue difficulty.

Practical Issues:

Many enforcement actions under the GDPR have arisen because controllers relied upon consent where another lawful basis was more appropriate.

Common errors include:

  • requesting unnecessary consent;
  • bundling multiple purposes into a single consent request;
  • making consent a condition of receiving unrelated services;
  • failing to record consent; or
  • making withdrawal more difficult than giving consent.

Controllers should remember that consent is not a mechanism for legitimising otherwise unnecessary or excessive processing.

Illustration

A fitness application requests separate consent for:

  • receiving promotional emails;
  • sharing health information with research partners; and
  • receiving personalised advertisements. Each option is presented independently, none is pre-selected, and users may withdraw consent at any time through the application's privacy settings. The consent mechanism is likely to satisfy Article 6(1)(a) because it is specific, informed and freely given.

Article 6(1)(b): Performance of a Contract

Processing is lawful where it is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject prior to entering into a contract.

This lawful basis recognises that many processing activities are indispensable for entering into or performing contractual relationships.

The crucial word is "necessary."

The controller must demonstrate that the particular processing is objectively required to fulfil the contractual obligations or to complete pre-contractual measures requested by the individual.

The necessity assessment is objective rather than subjective. It is not sufficient that the controller considers processing commercially desirable or operationally convenient.

Scope of Contractual Necessity

Processing may be necessary for:

  • delivering goods purchased by a customer;
  • processing salary payments under an employment contract;
  • opening and maintaining a bank account;
  • processing hotel reservations;
  • issuing airline tickets; or
  • responding to a customer's request for insurance coverage before concluding the policy.

The contractual purpose itself must also be genuine. Controllers cannot artificially draft broad contractual terms merely to justify unrelated processing activities under Article 6(1)(b).

Recital 44 explains that processing should be regarded as lawful where it is necessary in the context of a contract or the intention to enter into a contract. The EDPB Guidelines 2/2019 further clarify that contractual necessity must be interpreted narrowly and objectively.

The EDPB has consistently emphasised that contractual necessity must not be interpreted expansively. Merely because a processing activity is mentioned in a contract does not automatically make it "necessary" under Article 6(1)(b). The controller must demonstrate that the principal object of the contract cannot reasonably be achieved without the particular processing activity.

The assessment therefore focuses upon the substance of the contractual obligation, rather than the wording chosen by the controller.

Example

a music streaming platform necessarily processes a subscriber's account credentials and payment details to provide the streaming service. However, the same platform cannot rely upon Article 6(1)(b) to profile users extensively for behavioural advertising merely because its terms of service mention personalised advertising.

The EDPB has clarified that activities undertaken for the controller's commercial interests, product improvement, fraud analytics beyond what is objectively necessary, or targeted advertising will ordinarily require another lawful basis.

Practical Issues

Controllers frequently misuse Article 6(1)(b) by attempting to justify processing that is merely useful rather than genuinely necessary.

Common examples include:

  • behavioural advertising;
  • customer profiling for marketing;
  • sharing customer information with affiliated companies;
  • developing new products using customer data;
  • AI model training unrelated to contractual performance; or
  • analysing customer behaviour for future commercial opportunities.

These activities may be commercially valuable, but they are generally not objectively necessary for performing the contract itself.

Controllers should therefore distinguish between:

-processing necessary to perform contractual obligations; and -processing undertaken for independent business purposes.

The latter will normally require another lawful basis.

Illustration

An online retailer collects a customer's delivery address, payment information and contact details to fulfil an order. This processing is necessary for performing the sales contract and falls within Article 6(1)(b). However, if the retailer subsequently analyses the customer's purchasing history to create personalised advertising profiles, that additional processing is not objectively necessary for fulfilling the sales contract and must be justified under another lawful basis, such as consent or legitimate interests.

Article 6(1)(c): Compliance with a Legal Obligation

Processing is lawful where it is necessary for compliance with a legal obligation to which the controller is subject.

Unlike contractual necessity, this lawful basis derives from external legal requirements, rather than agreements between private parties.

The legal obligation must arise under:

-Union law; -Member State law; or -another legally binding provision applicable to the controller.

Controllers cannot create their own legal obligation through internal policies or contractual arrangements.

Recital 45 explains that processing should have a basis in Union or Member State law where the controller is required by law to process personal data. The law should be clear, precise and foreseeable in its application.

Scope of Legal Obligation

Article 6(1)(c) commonly applies where legislation requires organisations to collect, retain or disclose personal data.

Examples

include:

  • tax reporting obligations;
  • anti-money laundering requirements;
  • employment law obligations;
  • social security reporting;
  • statutory audit requirements;
  • financial reporting obligations; or
  • mandatory disclosure to regulatory authorities. The processing must remain necessary for complying with the legal obligation. Where legislation merely permits processing without requiring it, Article 6(1)(c) may not apply. Practical Issues Controllers should carefully identify:
  • the specific legal provision;
  • the precise obligation imposed;
  • the categories of personal data required; and
  • the duration for which processing remains necessary. Reliance upon Article 6(1)(c) also does not eliminate compliance with the remaining GDPR principles. Controllers must still observe:
  • purpose limitation;
  • data minimisation;
  • storage limitation;
  • security; and
  • accountability.

Illustration

National tax legislation requires employers to retain payroll records for seven years and provide them to tax authorities upon request. The employer processes employee payroll information under Article 6(1)(c) because the processing is necessary to comply with a statutory legal obligation.

Article 6(1)(d): Protection of Vital Interests

Processing is lawful where it is necessary in order to protect the vital interests of the data subject or another natural person.

This lawful basis is intentionally narrow and is generally confined to situations involving threats to life, physical safety or essential health interests.

It should not be used merely because processing benefits the individual or promotes public welfare.

Recital 46 explains that processing may be justified where necessary to protect an interest essential for the life of the data subject or another natural person, particularly in humanitarian emergencies or natural disasters.

Scope of Vital Interests

Article 6(1)(d) generally applies where:

  • immediate medical treatment is required;
  • emergency services require access to personal information;
  • individuals are unconscious or otherwise incapable of providing consent;
  • humanitarian organisations process data during disasters; or
  • processing is necessary to prevent imminent harm.

The lawful basis is exceptional rather than routine.

Where another lawful basis is reasonably available, controllers should ordinarily rely upon that basis instead.

Practical Issues

Organisations sometimes invoke "vital interests" too broadly.

Routine healthcare administration, employment records or ordinary customer services generally do not involve threats to life or physical safety and therefore should not ordinarily rely upon Article 6(1)(d).

Controllers should reserve this lawful basis for genuinely exceptional circumstances involving immediate and significant risks.

Illustration

A hospital receives an unconscious accident victim who is unable to communicate. Doctors access the individual's medical history and allergy records to provide emergency treatment. The processing is lawful under Article 6(1)(d) because it is necessary to protect the patient's vital interests.

Article 6(1)(e): Performance of a Task Carried Out in the Public Interest or in the Exercise of Official Authority

Processing is lawful where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Unlike Article 6(1)(c), which applies where the controller is subject to a legal obligation, Article 6(1)(e) applies where the law confers a function or power upon the controller and processing personal data is necessary to discharge that function.

This lawful basis is primarily relied upon by public authorities, although private bodies entrusted with statutory public functions may also rely upon it where authorised by Union or Member State law.

Recitals 45 and 50 explain that processing under Article 6(1)(e) must have a basis in Union or Member State law, which should define the purpose of processing and provide appropriate safeguards.

Scope of Public Interest Processing

Article 6(1)(e) commonly applies where personal data is processed for:

  • public administration;
  • taxation;
  • social security;
  • public healthcare;
  • education;
  • electoral administration;
  • law enforcement support functions;
  • environmental protection; or
  • other statutory public functions.

The controller must demonstrate that the processing is objectively necessary for performing the relevant public task. Processing undertaken merely because it is administratively convenient will not satisfy Article 6(1)(e).

Relationship with Article 6(1)(c)

Although Articles 6(1)(c) and 6(1)(e) both require a legal basis under Union or Member State law, they serve different purposes.

Article 6(1)(c) applies where legislation requires the controller to process personal data.

Article 6(1)(e) applies where legislation empowers or authorises the controller to perform a public function for which processing is necessary.

The distinction is important because not every statutory power creates a legal obligation, and not every legal obligation involves the exercise of official authority.

Practical Issues

Public authorities should avoid relying upon consent where processing is inherently linked to the exercise of statutory powers.

Example

government agencies generally should not request consent to maintain tax records, issue licences or administer welfare schemes because individuals usually have no genuine freedom to refuse such processing.

Controllers relying upon Article 6(1)(e) should clearly identify:

  • the statutory function being exercised;
  • the legal provision conferring that function;
  • why the processing is necessary; and
  • the safeguards protecting data subjects.

Illustration

A municipal authority collects residents' personal information to administer property tax, maintain electoral registers and issue building permits under national legislation. The processing is necessary for exercising official authority and therefore falls within Article 6(1)(e).

Article 6(1)(f): Legitimate Interests

Processing is lawful where it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject, particularly where the data subject is a child.

Article 6(1)(f) is the most flexible lawful basis under the GDPR, but it is also one of the most carefully scrutinised. Unlike the other lawful bases, legitimate interests requires the controller to perform a balancing exercise between its own interests and the rights of the data subject.

The provision recognises that organisations may have genuine commercial, operational, security or societal interests in processing personal data even where consent has not been obtained and no statutory obligation exists.

However, those interests do not automatically prevail.

Recitals 47, 48, 49 and 50 explain that legitimate interests may constitute a lawful basis where the processing is necessary and the interests of the controller are not overridden by the rights and freedoms of the data subject. Particular regard should be had to the reasonable expectations of the data subject based upon the relationship with the controller.

The Three-Part Legitimate Interests Assessment

Controllers relying upon Article 6(1)(f) should conduct a Legitimate Interests Assessment (LIA) consisting of three stages.

Purpose Test

The controller must first identify a legitimate interest.

The interest may be:

  • commercial;
  • financial;
  • operational;
  • legal;
  • security-related;
  • humanitarian; or
  • societal.

The interest must be lawful, genuine and sufficiently specific. Mere curiosity or speculative business advantages are unlikely to satisfy this requirement.

Necessity Test

The controller must then demonstrate that the processing is necessary for achieving the identified legitimate interest.

The necessity requirement requires consideration of whether the objective can reasonably be achieved through less intrusive means.

Processing that is merely useful, efficient or profitable is not automatically necessary.

Controllers should therefore consider whether:

  • less personal data could be processed;
  • anonymised data would suffice;
  • pseudonymised data could achieve the same objective; or
  • alternative measures would adequately protect the legitimate interest.

Balancing Test

Finally, the controller must balance its legitimate interests against the rights and freedoms of the data subject.

Relevant considerations include:

  • the nature of the personal data;
  • the reasonable expectations of the data subject;
  • the relationship between the parties;
  • the potential impact upon individuals;
  • whether children are involved;
  • the safeguards implemented by the controller; and
  • the likelihood and severity of any harm.

No single factor is decisive. The assessment must consider the circumstances of the particular processing activity.

Reasonable Expectations of the Data Subject

One of the most important aspects of the balancing exercise is whether the processing falls within the reasonable expectations of the data subject.

Individuals are more likely to expect processing that is closely connected with an existing relationship.

Conversely, unexpected, intrusive or opaque processing is more likely to override the controller's legitimate interests.

Example

a customer may reasonably expect a retailer to retain purchase records for warranty purposes. The same customer may not reasonably expect those records to be shared with unrelated advertisers for behavioural profiling.

Legitimate Interests Recognised by the GDPR

Recitals 47 to 49 identify several examples that may constitute legitimate interests, including:

  • fraud prevention;
  • network and information security;
  • internal administrative transfers within a corporate group;
  • direct marketing; or
  • ensuring the security and integrity of information systems.

These examples do not create automatic lawful bases. Controllers must still satisfy the necessity and balancing tests in every case.

Legitimate Interests and Children

Article 6(1)(f) specifically requires particular consideration where the data subject is a child.

Children may be:

  • less aware of privacy risks;
  • less capable of understanding complex processing activities;
  • more susceptible to behavioural profiling; and
  • more vulnerable to adverse consequences.

Controllers processing children's personal data should therefore undertake a particularly rigorous balancing assessment.

Practical Issues

Legitimate interests is frequently relied upon for:

  • CCTV surveillance;
  • fraud prevention;
  • cybersecurity monitoring;
  • internal investigations;
  • corporate restructuring;
  • physical access controls;
  • limited direct marketing;
  • whistleblowing mechanisms;
  • prevention of financial crime; and
  • internal administrative purposes.

However, controllers should avoid using Article 6(1)(f) as a default lawful basis merely because obtaining consent appears inconvenient.

The balancing assessment should be documented as part of the controller's accountability obligations under Article 5(2).

Illustration

Article 6(2): Member State Provisions

Article 6(2) recognises that Member States may introduce more specific provisions adapting the application of Article 6(1)(c) and Article 6(1)(e).

Meaning and Scope

The GDPR establishes a common legal framework throughout the European Union. However, certain public-sector processing activities require additional national rules reflecting domestic legal systems.

Accordingly, Member States may adopt legislation specifying matters such as:

  • particular processing requirements;
  • categories of personal data;
  • categories of data subjects;
  • entities authorised to process data;
  • disclosure requirements;
  • retention periods; or
  • additional safeguards.

Article 6(2) therefore provides flexibility while preserving the GDPR's harmonised framework.

Article 6(3): Legal Basis Under Union or Member State Law

Article 6(3) specifies the requirements that must be satisfied where processing relies upon Article 6(1)(c) or Article 6(1)(e).

The relevant Union or Member State law should clearly define:

  • the purpose of processing;
  • the legal obligation or public task;
  • the categories of personal data involved;
  • the conditions governing disclosure;
  • appropriate safeguards; and
  • where necessary, storage periods.

The legislation should also pursue an objective of public interest and remain proportionate to the legitimate aim pursued.

This provision reflects the broader principle of legal certainty, ensuring that individuals can reasonably foresee when public authorities or private organisations may lawfully process their personal data pursuant to statutory obligations.