# Lawful Basis — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/lawful-basis-article-6
> Sources are cited per item. Verify against the official texts before relying on them.

This topic is essential as Article 6 GDPR provides the specific legal bases that determine whether processing is lawful, which is the core requirement of the 'Lawfulness of processing' content.

## Overview

## Legal Framework
Article 6(1) GDPR establishes six independent lawful bases for processing personal data: consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. Processing is lawful only if at least one basis applies before processing begins. Recital 47 elaborates on legitimate interests under Article 6(1)(f), permitting processing when the controller's interests do not override the data subject's fundamental rights and reasonable expectations, particularly where a relevant relationship exists. Recital 46 clarifies that vital interests under Article 6(1)(d) generally apply only where processing cannot be based on another legal basis, typically involving life-threatening situations or humanitarian purposes. The controller bears the burden of documenting the applicable basis under the Article 5(2) accountability principle.

## Key Developments
The CJEU's ruling in Data Protection Commissioner v. Facebook Ireland (Schrems) underscores that supervisory authorities possess broad powers to scrutinize whether a lawful basis adequately protects data subjects, especially in cross-border contexts. While Schrems primarily addresses transfer mechanisms, it reinforces that national DPAs can independently assess the lawfulness of underlying processing operations. In Fashion ID v. Verbraucherzentrale NRW, the CJEU established that controllers must provide transparent information about the lawful basis relied upon, but only for processing operations where they actually determine purposes and means. This limits joint controllers' information duties to their respective roles. The EDPB's Guidelines 06/2020 on the interplay between PSD2 and the GDPR clarifies how sectoral laws may constrain the availability of certain bases, particularly in financial services. Recent enforcement actions, including the ICO's penalty against Allay Claims Ltd, demonstrate that failure to establish a valid lawful basis—particularly defective consent—triggers strict accountability and financial penalties.

## Practical Guidance
- **Map processing activities to specific bases:** Document which Article 6(1) basis applies to each processing operation before commencement, ensuring the basis is appropriate for the context and data subject relationship.
- **Conduct legitimate interest assessments (LIAs):** For Article 6(1)(f), perform and document a three-part test identifying the legitimate interest, necessity, and balancing against data subject rights and reasonable expectations per Recital 47.
- **Verify consent mechanisms:** Ensure consent under Article 6(1)(a) is freely given, specific, informed, and unambiguous, with clear opt-out mechanisms, as defective consent invalidates the basis entirely.
- **Limit vital interests to exceptional cases:** Reserve Article 6(1)(d) for genuine life-or-death scenarios where no other basis is viable, consistent with Recital 46.
- **Align transparency obligations:** Provide data subjects with information on the lawful basis relied upon at the time of collection, tailored to the controller's actual role in determining processing purposes, as clarified in Fashion ID.

## Legislation (full text of key provisions)

### Recital 47 — legitimate interests as processing legal basis

*Source: GDPR, gdpr-rec-47-en, 2016-04-27 — https://overview.legal/posts/91609*

The legitimate interests of a controller, including those of a controller to which the personal data may be disclosed, or of a third party, may provide a legal basis for processing, provided that the interests or the fundamental rights and freedoms of the data subject are not overriding, taking into consideration the reasonable expectations of data subjects based on their relationship with the controller. Such legitimate interest could exist for example where there is a relevant and appropriate relationship between the data subject and the controller in situations such as where the data subject is a client or in the service of the controller. At any rate the existence of a legitimate interest would need careful assessment including whether a data subject can reasonably expect at the time and in the context of the collection of the personal data that processing for that purpose may take place. The interests and fundamental rights of the data subject could in particular override the interest of the data controller where personal data are processed in circumstances where data subjects do not reasonably expect further processing. Given that it is for the legislator to provide by law for the legal basis for public authorities to process personal data, that legal basis should not apply to the processing by public authorities in the performance of their tasks. The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned. The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.

### Recital 46 — lawful processing vital interests protection

*Source: GDPR, gdpr-rec-46-en, 2016-04-27 — https://overview.legal/posts/91607*

The processing of personal data should also be regarded to be lawful where it is necessary to protect an interest which is essential for the life of the data subject or that of another natural person. Processing of personal data based on the vital interest of another natural person should in principle take place only where the processing cannot be manifestly based on another legal basis. Some types of processing may serve both important grounds of public interest and the vital interests of the data subject as for instance when processing is necessary for humanitarian purposes, including for monitoring epidemics and their spread or in situations of humanitarian emergencies, in particular in situations of natural and man-made disasters.

### Recital 41 — legal basis clarity and foreseeability

*Source: GDPR, gdpr-rec-41-en, 2016-04-27 — https://overview.legal/posts/91597*

Where this Regulation refers to a legal basis or a legislative measure, this does not necessarily require a legislative act adopted by a parliament, without prejudice to requirements pursuant to the constitutional order of the Member State concerned. However, such a legal basis or legislative measure should be clear and precise and its application should be foreseeable to persons subject to it, in accordance with the case-law of the Court of Justice of the European Union (the ‘Court of Justice’) and the European Court of Human Rights.

### Recital 112 — Public interest vital interests data transfer derogations

*Source: GDPR, gdpr-rec-112-en, 2016-04-27 — https://overview.legal/posts/91739*

Those derogations should in particular apply to data transfers required and necessary for important reasons of public interest, for example in cases of international data exchange between competition authorities, tax or customs administrations, between financial supervisory authorities, between services competent for social security matters, or for public health, for example in the case of contact tracing for contagious diseases or in order to reduce and/or eliminate doping in sport. A transfer of personal data should also be regarded as lawful where it is necessary to protect an interest which is essential for the data subject's or another person's vital interests, including physical integrity or life, if the data subject is incapable of giving consent. In the absence of an adequacy decision, Union or Member State law may, for important reasons of public interest, expressly set limits to the transfer of specific categories of data to a third country or an international organisation. Member States should notify such provisions to the Commission. Any transfer to an international humanitarian organisation of personal data of a data subject who is physically or legally incapable of giving consent, with a view to accomplishing a task incumbent under the Geneva Conventions or to complying with international humanitarian law applicable in armed conflicts, could be considered to be necessary for an important reason of public interest or because it is in the vital interest of the data subject.

### Recital 45 — legal basis for public interest processing

*Source: GDPR, gdpr-rec-45-en, 2016-04-27 — https://overview.legal/posts/91605*

Where processing is carried out in accordance with a legal obligation to which the controller is subject or where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, the processing should have a basis in Union or Member State law. This Regulation does not require a specific law for each individual processing. A law as a basis for several processing operations based on a legal obligation to which the controller is subject or where processing is necessary for the performance of a task carried out in the public interest or in the exercise of an official authority may be sufficient. It should also be for Union or Member State law to determine the purpose of processing. Furthermore, that law could specify the general conditions of this Regulation governing the lawfulness of personal data processing, establish specifications for determining the controller, the type of personal data which are subject to the processing, the data subjects concerned, the entities to which the personal data may be disclosed, the purpose limitations, the storage period and other measures to ensure lawful and fair processing. It should also be for Union or Member State law to determine whether the controller performing a task carried out in the public interest or in the exercise of official authority should be a public authority or another natural or legal person governed by public law, or, where it is in the public interest to do so, including for health purposes such as public health and social protection and the management of health care services, by private law, such as a professional association.

### Recital 113 — non repetitive limited data transfers

*Source: GDPR, gdpr-rec-113-en, 2016-04-27 — https://overview.legal/posts/91741*

Transfers which can be qualified as not repetitive and that only concern a limited number of data subjects, could also be possible for the purposes of the compelling legitimate interests pursued by the controller, when those interests are not overridden by the interests or rights and freedoms of the data subject and when the controller has assessed all the circumstances surrounding the data transfer. The controller should give particular consideration to the nature of the personal data, the purpose and duration of the proposed processing operation or operations, as well as the situation in the country of origin, the third country and the country of final destination, and should provide suitable safeguards to protect fundamental rights and freedoms of natural persons with regard to the processing of their personal data. Such transfers should be possible only in residual cases where none of the other grounds for transfer are applicable. For scientific or historical research purposes or statistical purposes, the legitimate expectations of society for an increase of knowledge should be taken into consideration. The controller should inform the supervisory authority and the data subject about the transfer.

### Recital 72 — profiling subject to regulation rules

*Source: GDPR, gdpr-rec-72-en, 2016-04-27 — https://overview.legal/posts/91659*

Profiling is subject to the rules of this Regulation governing the processing of personal data, such as the legal grounds for processing or data protection principles. The European Data Protection Board established by this Regulation (the ‘Board’) should be able to issue guidance in that context.

### Recital 69 — data subject right to object

*Source: GDPR, gdpr-rec-69-en, 2016-04-27 — https://overview.legal/posts/91653*

Where personal data might lawfully be processed because processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or on grounds of the legitimate interests of a controller or a third party, a data subject should, nevertheless, be entitled to object to the processing of any personal data relating to his or her particular situation. It should be for the controller to demonstrate that its compelling legitimate interest overrides the interests or the fundamental rights and freedoms of the data subject.

### Recital 50 — compatible further processing of personal data

*Source: GDPR, gdpr-rec-50-en, 2016-04-27 — https://overview.legal/posts/91615*

The processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected. In such a case, no legal basis separate from that which allowed the collection of the personal data is required. If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Union or Member State law may determine and specify the tasks and purposes for which the further processing should be regarded as compatible and lawful. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations. The legal basis provided by Union or Member State law for the processing of personal data may also provide a legal basis for further processing. In order to ascertain whether a purpose of further processing is compatible with the purpose for which the personal data are initially collected, the controller, after having met all the requirements for the lawfulness of the original processing, should take into account, inter alia: any link between those purposes and the purposes of the intended further processing; the context in which the personal data have been collected, in particular the reasonable expectations of data subjects based on their relationship with the controller as to their further use; the nature of the personal data; the consequences of the intended further processing for data subjects; and the existence of appropriate safeguards in both the original and intended further processing operations. Where the data subject has given consent or the processing is based on Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard, in particular, important objectives of general public interest, the controller should be allowed to further process the personal data irrespective of the compatibility of the purposes. In any case, the application of the principles set out in this Regulation and in particular the information of the data subject on those other purposes and on his or her rights including the right to object, should be ensured. Indicating possible criminal acts or threats to public security by the controller and transmitting the relevant personal data in individual cases or in several cases relating to the same criminal act or threats to public security to a competent authority should be regarded as being in the legitimate interest pursued by the controller. However, such transmission in the legitimate interest of the controller or further processing of personal data should be prohibited if the processing is not compatible with a legal, professional or other binding obligation of secrecy.

### Recital 88 — personal data breach notification rules

*Source: GDPR, gdpr-rec-88-en, 2016-04-27 — https://overview.legal/posts/91691*

In setting detailed rules concerning the format and procedures applicable to the notification of personal data breaches, due consideration should be given to the circumstances of that breach, including whether or not personal data had been protected by appropriate technical protection measures, effectively limiting the likelihood of identity fraud or other forms of misuse. Moreover, such rules and procedures should take into account the legitimate interests of law-enforcement authorities where early disclosure could unnecessarily hamper the investigation of the circumstances of a personal data breach.

## Case law

### Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy

*Source: CJEU, 2017-09-27 — https://overview.legal/posts/6137 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62015CJ0073&ref=6137*

Lawful basis (in general): Subject to the exceptions permitted under Article 13 of the Data Protection Directive, all processing of personal data must comply, first, with the principles relating to data quality (in Article 6 of that directive) and, have lawful basis (by complying with one criteria for making data processing legitimate listed in Article 7 of that directive) (see, Bara). The list of lawful basis in Article 7 is an exhaustive and restrictive list of cases in which the processing of

### Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde  v  Rīgas pašvaldības SIA ‘Rīgas satiksme’

*Source: CJEU, 2017-05-04 — https://overview.legal/posts/5953 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62015CJ0013*

setting out a test based on three criteria to decide whether a processing operation can rely on this ground. The Court reached a surprising conclusion, stating that while there is legitimate interest to process (disclose) data in the case at hand, the controller (a public authority) would also need a legal obligation to lawfully disclose the data.

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/5945 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311*

“the national supervisory authorities are responsible for monitoring compliance with the EU rules concerning the protection of natural persons with regard to the processing of personal data. Each of those authorities is therefore vested with the power to check whether a transfer of personal data from its own Member State to a third country complies with the requirements laid down in that regulation” / “The exercise of that responsibility is of particular importance where personal data is tra

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/6120 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=6120*

“[…] the standard data protection clauses adopted by the Commission on the basis of Article 46(2)(c) of the GDPR are solely intended to provide contractual guarantees that apply uniformly in all third countries to controllers and processors established in the European Union and, consequently, independently of the level of protection guaranteed in each third country. In so far as those standard data protection clauses cannot, having regard to their very nature, provide guarantees beyond a contrac

### Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy

*Source: CJEU, 2017-09-27 — https://overview.legal/posts/6138 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62015CJ0073&ref=6138*

Lawful Basis (Public Interest): Article 7(e) Directive 95/46 must be interpreted as not precluding the processing of personal data by the authorities of a Member State for the purpose of collecting tax and combating tax fraud such as that effected by drawing up the contested list in the main proceedings, without the consent of the data subjects, “provided that, first, those authorities were invested by the national legislation with tasks carried out in the public interest within the meaning of t

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6146*

Safe harbour: US public authorities are not required to comply with safe harbor principles. Decision 2000/520 specifies that safe harbor principles may be limited to the extent necessary to meet national security, public interest or law enforcement requirements, or statute, regulation or caselaw. Self-certified US organizations receiving personal data from the EU are thus bound to disregard safe harbor principles when they conflict with US legal requirements. Decision 2000/520 does not contain s

### RYNES V. ÚŘAD PRO OCHRANU OSOBNICH ÚDAJŮ, 11.12.2014 (“RYNES”)

*Source: CJEU, 2014-12-11 — https://overview.legal/posts/5961 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62013CJ0212*

Legitimate interest: Arts. 7(f), 11(2) and 13(1)(d) and (g) make it possible to take into account the legitimate interests of the controller in protecting the property, health and life of his family and himself. (¶34)

### GOOGLE SPAIN SL V. AEPD (THE DPA) & MARIO COSTEJA GONZALEZ, 13.May.2014 (“GOOGLE v. Spain”)

*Source: CJEU, 2014-05-13 — https://overview.legal/posts/6158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0131&ref=6158*

Legitimate interest balancing test: Legitimate interest requires balancing of the interest of the controller and third party with the interest of the data subject. In this particular case, having regard to the sensitivity for data subject’s private life of information contained in announcements and the fact that the initial publication occurred 16 years earlier, the data subject has established that the links should be removed. (¶¶ 70–75, 80-81, 98)

### ASOCIACION NACIONAL DE ESTABLECIMIENTOS FINANCIEROS DE CREDITO (ASNEF) AND FEDERACION DE COMERCIO ELECTRONICO Y MARKETING DIRECTO (FECEMD) V. ADMINISTRACION DEL ESTADO, 24.Nov.2011 (“ASNEF”)

*Source: CJEU, 2011-11-24 — https://overview.legal/posts/6174 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0468&ref=6174*

Valid purposes for processing: EU data protection law sets out an exhaustive and restrictive list of cases in which the processing of personal data can be regarded as lawful. Member States cannot add new principles relating to the lawfulness of processing or impose additional requirements. (¶¶ 29-32)

### V & EDPS V. EUROPEAN PARLAMENT, 5.7.2011 (“V v. European Parliament”)

*Source: CJEU, 2011-07-05 — https://overview.legal/posts/6179 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6179*

Lawful Basis: The applicant did not consent to the transfer of her medical file by the Commission to the European Parliament. The transfer was not “necessary for the purposes of complying with the specific rights and obligations of the controller in the field of employment law,” in accordance with Article 10(2)(b). The Parliament’s obligation to control fitness for duty could have been achieved by less intrusive means. Nor does Article 10(3) justify the transfer. (¶¶ 137–139)

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/6180 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6180*

Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their consent. (¶ 54)

### CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is

*Source: CJEU, 2010-06-29 — https://overview.legal/posts/6182 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62008CJ0028&ref=6182*

Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69)

## Guidance

### Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-derogations-of-article-49, 2018-05-25 — https://overview.legal/posts/38057 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22018-on-derogations-of-article-49-under-regulation-2016679_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2018 to provide interpretive guidance on the application of Article 49 derogations for international transfers of personal data under the GDPR. The guidelines emphasize that derogations under Article 49 are exceptions to the general rule requiring an adequacy decision or appropriate safeguards, and that controllers must first exhaust transfer mechanisms under Articles 45 and 46 before resorting to these derogations. The document details specific conditions and limitations for each derogation, including explicit consent, contractual necessity, public interest, vital interests, public registers, and compelling legitimate interests.

### Guidelines 02/2024 on Article 48 GDPR

*Source: EDPB, edpb-guidelines-022024-on-article-48-gdpr, 2025-06-05 — https://overview.legal/posts/38045 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022024-on-article-48-gdpr_en*

Article  48  GDPR  provides  that:  ' Any  judgment  of  a  court  or  tribunal  and  any  decision  of  an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data  may  only  be  recognised  or  enforceable  in  any  manner  if  based  on  an  international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer...

### Guidelines 06/2022 on the practical implementation of amicable settlements

*Source: EDPB, edpb-guidelines-on-the-practical-implementation-of-amicable-settlements, 2022-05-12 — https://overview.legal/posts/38072 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062022-on-the-practical-implementation-of-amicable-settlements_en*

The EDPB adopted Guidelines 06/2022 to provide practical guidance on the implementation of amicable settlements between supervisory authorities and controllers or processors under the GDPR. The guidelines address the scope and definition of amicable settlements, the legal basis for this power, and its procedural operation within the one-stop-shop mechanism, including the roles of the complaint-receiving competent supervisory authority and the lead supervisory authority. No fines are imposed as this is a guidance document rather than an enforcement decision.

### Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR

*Source: EDPB, edpb-guidelines-on-the-interplay-of-the-second-payment-services-directive-and-the-gdpr, 2020-12-15 — https://overview.legal/posts/38139 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062020-on-the-interplay-of-the-second-payment-services-directive-and_en*

The European Data Protection Board (EDPB) adopted Guidelines 06/2020 to clarify the interplay between the Second Payment Services Directive (PSD2) and the GDPR. The guidelines analyze the lawful grounds for processing personal data in payment services, the relationship between explicit consent under Article 94(2) PSD2 and GDPR consent requirements,

### Guidelines 3/2019 on processing of personal data through video devices

*Source: EDPB, edpb-guidelines-on-processing-of-personal-data-through-video-devices, 2020-01-30 — https://overview.legal/posts/38059 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-32019-on-processing-of-personal-data-through-video-devices_en*

The European Data Protection Board (EDPB) adopted Guidelines 3/2019 to provide comprehensive guidance on the processing of personal data through video devices,including CCTV and smart camera systems, under the GDPR. The guidelines address key issues such as the scope of application, the household exemption, lawfulness of processing under Article 6(1)(f) GDPR (legitimate interests), data subjects' rights, and obligations of controllers, while also clarifying the boundary with the Law Enforcement Directive (EU 2016/680). The guidelines were adopted on 29 January 2020 following public consultation and do not impose fines but serve as interpretative guidance for controllers and supervisory authorities.

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

*Source: EDPB, edpb-guidelines-on-technical-scope-of-art-53-of-eprivacy-directive, 2024-10-16 — https://overview.legal/posts/38063 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22023-on-technical-scope-of-art-53-of-eprivacy-directive_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2023 to clarify the technical scope of Article 5(3) of the ePrivacy Directive, focusing on its application to emerging tracking technologies that operate as alternatives to cookies. The guidelines establish three key elements—information, terminal equipment, and gaining access/storage—to determine whether specific technical operations require user consent. The document applies this framework to common use cases such as URL and pixel tracking, local processing, IP-based tracking, intermittent IoT reporting, and the use of unique identifiers.

### Guidelines 03/2021 on the application of Article 65(1)(a) GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-651a-gdpr, 2023-05-24 — https://overview.legal/posts/38137 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032021-on-the-application-of-article-651a-gdpr_en*

The European Data Protection Board (EDPB) adopted Guidelines 03/2021 to clarify the dispute resolution mechanism under Article 65(1)(a) GDPR, which governs the EDPB's authority to issue binding decisions when a Lead Supervisory Authority receives relevant and reasoned objections from Concerned Supervisory Authorities that it does not follow. The Guidelines address the procedural framework, the threshold for "relevant and reasoned" objections, the scope of the EDPB's substantive competence, and applicable procedural safeguards including the right to be heard, access to the file, and available judicial remedies.

## Enforcement decisions

### NAIH fines online store HUF 2M for unclear and incomplete privacy notice

*Source: NAIH (Hungary), 2026-07-22 — https://overview.legal/posts/156361 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-11443-3/2026*

Facts — The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The processing activities in question included, inter alia, cookies, registration, billing, shipping, consumer complaint, and processing of orders. The privacy notice of the company operating the online store had been in force unchanged from May 2018 to May 2025, and the period under investigation extended from 1 January 2020 to 27 June 2025. Holding — The DPA held that the controller had violated Articles 12(1), 13(1)(c), (d) and (f), and 13(2)(a) GDPR and issued the controller a fine of HUF 2,000,000 (€5,500). In addition, the DPA ordered the controller to bring its data processing operations into compliance with the GDPR and to amend the content of its privacy notice. First, the DPA found an infringement of Article 12(1) GDPR: the structure of the privacy notice was confusing and difficult to follow. The privacy notice also contained incomplete, incorrect, and unnecessary information as well as repetitive details. Based on this, the DPA concluded that the controller had failed to provide data subjects with information regarding the processing of personal data that was sufficiently concise, transparent, intelligible and easily accessible. Second, the DPA held that the controller had also violated Articles 13(1)(c), (d) and (f) GDPR by failing to specify a legal basis for certain processing operations such as the use of cookies, not specifying its legitimate interests when relying on Article 6(1)(f) GDPR as a legal basis, and not providing detailed information regarding the safeguards ensuring the lawfulness of data transfers to the United States. Finally, the DPA found a violation of Article 13(2)(a) GDPR as the controller had also failed to provide the data subjects information on the period for which the personal data processed would be stored.

### SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing

*Source: Spanish Data Protection Authority (aepd), 2022-09-16 — https://overview.legal/posts/47507 — original: https://www.enforcementtracker.com/ETid-1392*

The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram account without the customer's consent. For this reason, the DPA determined that the processing of the customer's personal data was unlawful.

### APD/GBA (Belgium) - 117/2022

*Source: APD/GBA (Belgium), 2022-07-26 — https://overview.legal/posts/6318 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_117/2022*

Facts — The data subject was a former customer of the controller (which remained unknown). The data subject received direct marketing from the controller. The data subject objected to the further processing of its personal data while also requesting access to all personal data processed by the controller and the legal basis used to send the direct marketing. The controller responded within 30 days, confirming that the data subject would no longer receive direct marketing and provided all processed data, including the applicable legal bases. The data subject then submitted a complaint at the DPA stating that the controller cannot rely on legitimate interest for processing its email adress as the data subject was a former, not current customer. Holding — The DPA held that a controller is allowed to rely on legitimate interest to send direct marketing, including former customers under certain conditions, pursuant to Recital 47 GDPR and its Guidance 01/2020 on Direct Marketing (nr. 168). In its Guidance, it was stated that when there was no relationship between the controller and data subject, or when it goes back a long time, legitimate interest cannot be invoked, as direct marketing is not part of the data subject's reasonable expectations. The DPA followed that because the relationship between the controller and the data subject ended not that long ago (around two years prior), a contrario, the data subject could reasonably expect that his data would still be used for direct marketing. Hence the controller could use legitimate interest as a legal basis. In addition, the controller confirmed that the processing for direct marketing is only done up to two years after the cancellation of the service. The DPA therefore held that the controller did not breach the GDPR and dismissed the case.

### APD/GBA (Belgium) - 115/2022

*Source: APD/GBA (Belgium), 2022-07-19 — https://overview.legal/posts/6317 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_115/2022*

Facts — During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor, stating that she was unfit to work and would leave the company. This statement was also included in the minutes of that meeting. When the data subject discovered this, she filed a complaint against the controller with the Belgian DPA for unlawfully disclosing health related personal data to third parties. She added that the minutes were then saved on the controller´s server, freely accessible to all its staff, including from other departments. Holding — The DPA noted that the data subject did not dispute the lawfulness of processing of the information that she was unfit to work, but the subsequent communication about her health to her colleagues and other staff members. The DPA noted that it was not able to verify whether the minutes were actually made available on the controller's server. However if that were the case, this would amount to an additional processing activity and the following findings of the infringement also apply. The DPA first assessed whether the further processing was compatible with the purpose of the original processing (Article 5(1)(b) GDPR). It found that the purpose of the original processing was personnel management. The DPA held that the data subject could not reasonably expect that the same data would be communicated widely beyond the persons authorised for personnel management. Especially considering the sensitive nature of the data. Therefore the DPA held that the further processing was incompatible with the purpose of the original processing. As the further processing was incompatible with the purpose of the original processing, the DPA noted that it could only be lawful if it had its own legal basis pursuant to Article 9(2) juncto Article 6(1). However the DPA found that this was also not present. Therefore, the DPA held that the controller did not have a proper legal basis for processing the data subject's health related data and thereby violated Article 5(1)(b) juncto Article 6(4) and Article 9(2). The DPA issued a reprimand against the controller. The DPA noted that it was not competent to issue a fine as the controller was a public authority.

### DSB (Austria) - 2021-0.698.184

*Source: DSB (Austria), 2021-10-08 — https://overview.legal/posts/262252 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2021-0.698.184*

Facts — The data subject was a shareholder and managing director of two companies. The controller operated a free online search platform that allowed users to look up companies registered in the Austrian companies register and see, for a given company, which natural persons held positions such as shareholder or managing director, as well as an overlay showing what other companies those persons were connected to. The controller obtained the underlying data from a commercial information provider, which in turn sourced it from the Federal Ministry of Justice under a data-reuse agreement covering companies register documents. The controller funded the free service through advertising displayed on the platform. The data subject had no contractual relationship with the controller. A direct name search for the data subject on the controller's platform returned no results, however, searching for a company in which he held a position returned his name together with his role (managing director, sole shareholder with a 100% stake) and through an „i“ icon, an overlay listing his positions in other companies. The data subject complained to the Austrian DPA, arguing that the controller published his name without any contract between them and without any identifiable legitimate interest justifying the publication. The controller argued that its processing pursued a legitimate commercial interest, enabling business participants to research potential contractual partners and pointed out that companies register data was already public and accessible to anyone under national law, including via other commercial and official information services. Holding — First, the DPA rejected the controller's argument that the data was already available and therefore outside the scope of a secrecy interest altogether. It held, citing CJEU case-law C-73/07, that a blanket assumption that lawfully published data cannot be subject to a legitimate secrecy interest is incompatible with EU law requirements. Second, the DPA held that the controller's processing constituted a new form of data use requiring independent justification, because the controller did not merely reproduce publicly accessible companies register data, but recombined and cross-linked it, thereby creating additional informational value beyond what a simple companies register search would reveal. Third, applying the balancing test under Article 6(1)(f) GDPR and Section 1(2) DSG, the DPA found that the controller had a legitimate interest in operating its platform, both a commercial interest of its own (generating advertising revenue) and a legitimate interest of platform users and market participants generally in being able to assess a business partner's other company affiliations. The DPA weighed this against the data subject's interest in secrecy and concluded that the balance favoured the controller, for three reasons: 1. the underlying data's general availability in the companies register reduced (though did not eliminate) its protection-worthiness 2. the data related exclusively to the data subject's professional sphere as someone who had voluntarily chosen to participate in commercial life as a shareholder and managing director 3. the resulting interference with his data protection rights was accordingly of low intensity. The DPA therefore rejected the complaint as unfounded.

### AEPD (Spain) - PS/00249/2025

*Source: AEPD (Spain), 2026-08-12 — https://overview.legal/posts/187487 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00249/2025*

Facts — MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November 2024, the data subject received a marketing call from an agent acting on behalf of the controller. The agent addressed the data subject by name and asked questions about the type of residence in which he lived. When the data subject asked whether the controller had checked the Robinson List, the agent stated that this was unnecessary because the call was based on a “database”. When the data subject subsequently asked about the source of his personal data, the call ended. The data subject later contacted the controller’s customer service to enquire about the source of his data and was told that the data had been obtained by its sales department and might originate from his acceptance of cookies. The data subject disputed this, stating that he had never visited the controller’s website. At the time of the call, his telephone number had been registered with the Robinson List since March 2024. The controller explained that it obtained databases from external marketing providers which guaranteed that the personal data had been lawfully collected. It claimed that the data subject had consented in June 2020 through an online form to the processing of his data, the receipt of marketing communications and the disclosure of his data to third parties. As evidence, the controller provided a record containing the data subject’s details, an IP address, a timestamp and consent indicators, as well as a generic version of the relevant online form. However, the form was blank and did not contain any information specifically identifying the data subject. The controller also acknowledged that it did not independently verify the validity of the consent provided by its external supplier. Holding — The DPA held that the controller violated Article 66(1)(b) LGTel and Article 14 GDPR. First, regarding the commercial call, the DPA considered that the controller had not demonstrated that the data subject had given valid consent within the meaning of Article 4(11) GDPR. The documentation provided did not establish that the data subject personally completed the registration, entered the telephone number or could be linked to the IP address contained in the record. Moreover, the controller did not provide the privacy policy applicable when the alleged consent was obtained, meaning that it could not establish the purposes or third parties covered by that consent. The DPA recalled that, pursuant to Articles 5(2) and 7 GDPR, it is for the controller to demonstrate that valid consent was obtained. This responsibility could not be transferred to the external data provider through contractual guarantees. The controller remained responsible for establishing a valid legal basis for using the purchased data for its own marketing campaign. This was particularly relevant because the data subject's telephone number was registered with the Robinson List. Although the registration, and as specific consent was not sufficiently demonstrated, the controller could not rely on the exception under Article 23(4) LOPDGDD. Consequently, the DPA found that the unsolicited call lacked a valid legal basis and violated Article 66(1)(b) LGTel. Second, the DPA found a violation of Article 14 GDPR. Since the controller had obtained the personal data from a third party, it was required to provide the information listed in Article 14 GDPR. During the call, the agent merely referred to an unspecified “database” and did not adequately inform the data subject about the source of the data, the controller's identity, the legal basis for the processing or his data protection rights. The duration or termination of the call did not relieve the controller of this obligation, and the controller had not demonstrated that the required information was provided through another channel. The DPA imposed a fine of €5,000 for the violation of Article 66(1)(b) LGTel and a further €5,000 for the violation of Article 14 GDPR, resulting in a total fine of €10,000.

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

### LfD (Lower Saxony) - Fine EUR 900,000 against bank

*Source: LfD (Lower Saxony), 2022-09-28 — https://overview.legal/posts/6319 — original: https://gdprhub.eu/index.php?title=LfD_(Lower_Saxony)_-_Fine_EUR_900,000_against_bank*

Facts — A commercial bank (controller) used personal data of current and former customers (data subjects) to identify customers with an affinity for digital media usage, in order to address them more intensely through electronic communication channels for further commercial communication (advertisement). A service provider analyzed digital usage behavior on behalf of the controller, including the total amount of app-store purchases, the usage frequency of bank statement printers as well as the total amount of transfers in online banking system (in comparison to the offline usage in their local branch offices). The results were compared and further enriched with data from a commercial credit reporting agency. Most customers were informed in advance, but no consent under Article 6(1)(a) GDPR was obtained. The controller based the data analysis, data enrichment and the subsequent creation of customer profiles on legitimate interest as per Article 6(1)(f) GDPR. Holding — The DPA found that the analysis of large amounts of data to create customer profiles could not be based on Article 6(1)(f). It followed that processing based on a legitimate interest requires a balancing act between the interest of the controller and the fundamental rights and freedoms if the data subject. The controller had to consider the reasonable expectations of the data subjects. The DPA argued that a data subject could not reasonably expect large amounts of its personal data to be analyzed by the controller to better target its advertising. Third-party data enrichment, like the use of commercial credit reporting agency data, further overrides the interest of the controller and tips the balancing test in favor of the data subject. The DPA held that in addition, data enrichment from a third-party source and linking it to profiles could also not be based on legitimate interest. This could potentially link data from all areas of life to an accurate customer profile, which could also not be reasonably expected by a customer. Customer consent (see Article 6(1)(a)) is required. The controller cooperated with the DPA throughout the process. For the violation, the DPA fined the controller €900,000.

## Recent developments

### UODO (Poland) - DKE.561.1.2026

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291290 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKE.561.1.2026*

The DPA reprimanded a company for refusing to cooperate with the supervisory authority: the controller had failed to provide information on the processing of personal data in two pending cases against it. English Summary. Facts. The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned processing that had taken place in January 2025, while the events giving rise to the second complai

### EDPB calls for legal basis for cross-regulatory information sharing

*Source: European Data Protection Board, 2026-07-17 — https://overview.legal/posts/125636 — original: https://www.edpb.europa.eu/news/edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing_en*

Dublin, 17 July– At a high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear legal basis for the sharing of information among regulators with different competences. The Board also discussed how to further expand efforts to support a consistent application of the General Data Protection Regulation (GDPR), including through more intense cooperation between Data Protection Authorities (DPAs).A clear legal basis for efficient cross-regulator

### Digital Omnibus: EU DPAs reject many proposed changes to the GDPR

*Source: noyb - European Center for Digital Rights, 2026-02-11 — https://overview.legal/posts/52485 — original: https://noyb.eu/en/digital-omnibus-eu-dpas-reject-many-proposed-changes-gdpr*

GDPR Policy The EDPB (combining all independent data protection authorities) and the European Data Protection Supervisor (EDPS) published a joint opinion expressing serious concerns about key elements of the proposed GDPR and ePrivacy changes in the so-called “Digital Omnibus” proposed by the European Commission. Specifically, the authorities strongly oppose the proposed narrowing of the definition of personal data. The opinion also question the need for various key proposals, such as the legal

### Austrian Supreme Court: Meta must give users full access to their data

*Source: noyb - European Center for Digital Rights, 2025-12-18 — https://overview.legal/posts/49120 — original: https://noyb.eu/en/austrian-supreme-court-meta-must-give-users-full-access-their-data*

Online & Mobile tracking Austrian Supreme Court (OGH): Meta must provide full access to all personal data of user within 14 days, including the sources, recipients and purposes for which each information was used. All of Meta's claims of trade secrets or other limitations were rejected, leading to unprecedented access to the inner workings of Meta. Meta was also illegally collecting data from third party apps and websites and may only provide personalised advertisement if a user provided “specif

### Like to play alone? Ubisoft is still watching you!

*Source: noyb - European Center for Digital Rights, 2025-04-24 — https://overview.legal/posts/53156 — original: https://noyb.eu/en/play-alone-ubisoft-still-watching-you*

Online & Mobile tracking Today, noyb filed a complaint against the French video game developer and publisher Ubisoft (known for Assassins Creed, Far Cry, Prince of Persia). The company forces its customers to connect to the internet every time they launch a single player game. This is the case even if the game doesn’t have any online features. This allows Ubisoft to collect people’s gaming behaviour. Among other things, the company collects data about when you start a game, for how long you play

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes

---
Generated by overview.legal · https://overview.legal/topics/lawful-basis-article-6 · 2026-08-22
