Lawful Basis
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic is essential as Article 6 GDPR provides the specific legal bases that determine whether processing is lawful, which is the core requirement of the 'Lawfulness of processing' content.
Overview
13 sources · Jul 23, 2026Legal Framework
Article 6(1) GDPR establishes six independent lawful bases for processing personal data: consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. Processing is lawful only if at least one basis applies before processing begins. Recital 47 elaborates on legitimate interests under Article 6(1)(f), permitting processing when the controller's interests do not override the data subject's fundamental rights and reasonable expectations, particularly where a relevant relationship exists. Recital 46 clarifies that vital interests under Article 6(1)(d) generally apply only where processing cannot be based on another legal basis, typically involving life-threatening situations or humanitarian purposes. The controller bears the burden of documenting the applicable basis under the Article 5(2) accountability principle.
Key Developments
The CJEU's ruling in Data Protection Commissioner v. Facebook Ireland (Schrems) underscores that supervisory authorities possess broad powers to scrutinize whether a lawful basis adequately protects data subjects, especially in cross-border contexts. While Schrems primarily addresses transfer mechanisms, it reinforces that national DPAs can independently assess the lawfulness of underlying processing operations. In Fashion ID v. Verbraucherzentrale NRW, the CJEU established that controllers must provide transparent information about the lawful basis relied upon, but only for processing operations where they actually determine purposes and means. This limits joint controllers' information duties to their respective roles. The EDPB's Guidelines 06/2020 on the interplay between PSD2 and the GDPR clarifies how sectoral laws may constrain the availability of certain bases, particularly in financial services. Recent enforcement actions, including the ICO's penalty against Allay Claims Ltd, demonstrate that failure to establish a valid lawful basis—particularly defective consent—triggers strict accountability and financial penalties.
Practical Guidance
- Map processing activities to specific bases: Document which Article 6(1) basis applies to each processing operation before commencement, ensuring the basis is appropriate for the context and data subject relationship.
- Conduct legitimate interest assessments (LIAs): For Article 6(1)(f), perform and document a three-part test identifying the legitimate interest, necessity, and balancing against data subject rights and reasonable expectations per Recital 47.
- Verify consent mechanisms: Ensure consent under Article 6(1)(a) is freely given, specific, informed, and unambiguous, with clear opt-out mechanisms, as defective consent invalidates the basis entirely.
- Limit vital interests to exceptional cases: Reserve Article 6(1)(d) for genuine life-or-death scenarios where no other basis is viable, consistent with Recital 46.
- Align transparency obligations: Provide data subjects with information on the lawful basis relied upon at the time of collection, tailored to the controller's actual role in determining processing purposes, as clarified in Fashion ID.