Laws · GDPR ·art-6-par-3 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
The basis for the processing referred to in point (c) and (e) of paragraph 1 shall be laid down by:
How it connects
Cited by
- Guidelines 02/2024 on Article 48 GDPR
- Guidelines 3/2019 on processing of personal data through video devices
- Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR
- Comune di Santo Stefano Belbo: Non-compliance with general data processing principles
- Comune di Luino: Non-compliance with general data processing principles
All 75
- Ministero dello Sviluppo Economico: Non-compliance with general data processing principles
- Comune di Conflenti: Insufficient legal basis for data processing
- Comune di San Marco in Lamis: Insufficient legal basis for data processing
- Comune di Castellanza: Insufficient legal basis for data processing
- Regione Lombardia: Non-compliance with general data processing principles
- Comune di Montalbano Jonico: Non-compliance with general data processing principles
- Brussels Airport Charleroi: Insufficient legal basis for data processing
- City of Rome (Roma capitale): Insufficient legal basis for data processing
- Region of Tuscany: Insufficient legal basis for data processing
- Territorial Administration of the Government of Genoa: Insufficient legal basis for data processing
- Santa Ninfa municipality: Insufficient legal basis for data processing
- Comune di Ustica: Non-compliance with general data processing principles
- hier
- Study on the secondary use of personal data in the context of scientific research
- Guidelines 02/2025 on processing of personal data through blockchain technologies
- EDPB contribution to the EBA public consultation on draft regulatory technical standards on AML/CFT
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- EDPB contribution to the EBA public consultation on draft regulatory technical standards on AML/CFT
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- BGH - V ZB 90/25
- EDPB-EDPS Joint opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence
- CJEU - C‑474/24 - NADA Austria and Others
- VG Düsseldorf: data subjects challenge district's sharing of personal data in water-law
- Garante per la protezione dei dati personali (Italy) - 10192784
- CJEU - C-247/23 - Deldits
- DPC (Ireland) - 06/SIU/2018
- DPA need not assess law's constitutionality or GDPR proportionality, only legal basis
- Guidelines on processing of personal data through blockchain technologies
- Statement 1/2025 on Age Assurance
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- Statement 02/2021 on new draft provisions of the second additional protocol to the Council of Europe Convention on Cybercrime (Budapest Convention)
- Recommendations 02/2020 on the European Essential Guarantees for surveillance measures
- Guidelines 04/2020 on the use of location data and contact tracing tools in the context of the COVID-19 outbreak
- Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)
- L. H. v Ministerstvo zdravotnictví
- Agentsia po vpisvaniyata v OL
- HTB Neunte Immobilien Portfolio geschlossene Investment UG & Co. KG and Ökorenta Neue Energien Ökostabil IV geschlossene Investment GmbH & Co. KG v Müller Rechtsanwaltsgesellschaft mbH and Others
- SO
- OQ v Land Hessen
- Gesamtverband Autoteile-Handel e.V. v Scania CV AB
- A. G. v Lietuvos Respublikos generalinė prokuratūra
- European Commission v Republic of Poland
- European Commission v Republic of Poland
- Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium v Minister des Hessischen Kultusministeriums
- Norra Stockholm Bygg AB v Per Nycander AB
- VS v Inspektor v Inspektorata kam Visshia sadeben savet
- Komisia za zashtita na lichnite danni and Tsentralna izbiratelna komisia v Koalitsia „Demokratichna Bulgaria - Obedinenie“
- OT v Vyriausioji tarnybinės etikos komisija
- Ligue des droits humains ASBL v Conseil des ministres
- SIA 'SS' v Valsts ieņēmumu dienests
- Criminal proceedings against HP
- European Commission v Republic of Poland
- European Commission v Republic of Poland
- Republic of Malta v European Commission
- Commission of the European Communities v Kingdom of the Netherlands
- CJEU - C‑258/23 to C‑260/23 - Imagens Médicas Integradas
- Hoge Raad - ECLI:NL:PHR:2023:935
- CJEU C-312/24 Darashev: Data subject's right to erasure of criminal investigation data
- IP Slovenia: ZEKom-1 governs legal basis for NIJZ #StayHealthy SMS to users
- OLG München - 36 U 1054/25 e
- VG Berlin - 42 K 73/25
- Finnish DPA examines anti-doping organization's GDPR compliance over public suspension
- Persónuvernd (Iceland) - 2025010364
- Garante per la protezione dei dati personali (Italy) - 551/2026
- CJEU - C-798/24 - Jautiva
- Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive
- BVwG - W298 2314952-1
- HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or
- Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data
- Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to
Related across sources
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines Jul 7, 2021 Controllers Processors IP Address
Guidelines 01/2022 data subject rights - Right of access Guidelines Apr 17, 2023 Right of Access Personal Data Right to Rectification
Guidelines 10/2020 restrictions under Article 23 GDPR Guidelines Oct 13, 2021 GDPR Subject-Matter and Objectives Right to Restriction Data Portability
Guidelines 06/2020 interplay of the Second Payment Services Directive and the GDPR Guidelines on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Guidelines Dec 15, 2020 International Transfer GDPR Article 5 Principles of Processing Personal Data
2018 Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) Guidelines on transparency Apr 11, 2018 Transparency Information Provision Modalities and Communication Methods Fairness & Transparency
Guidelines 1/2019 Codes of Conduct and Monitoring Bodies under Regulation 2016/679 Guidelines on codes of conduct and monitoring bodies Guidelines Jun 4, 2019 Accountability Codes of Conduct GDPR Article 5 Principles of Processing