Skip to content
Topic Contested in court

Lawful Basis

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This topic is essential as Article 6 GDPR provides the specific legal bases that determine whether processing is lawful, which is the core requirement of the 'Lawfulness of processing' content.

169 linked items 10 Laws51 Case Law30 Guidance9 Enforcement69 News

Overview

13 sources · Jul 23, 2026

Legal Framework

Article 6(1) GDPR establishes six independent lawful bases for processing personal data: consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. Processing is lawful only if at least one basis applies before processing begins. Recital 47 elaborates on legitimate interests under Article 6(1)(f), permitting processing when the controller's interests do not override the data subject's fundamental rights and reasonable expectations, particularly where a relevant relationship exists. Recital 46 clarifies that vital interests under Article 6(1)(d) generally apply only where processing cannot be based on another legal basis, typically involving life-threatening situations or humanitarian purposes. The controller bears the burden of documenting the applicable basis under the Article 5(2) accountability principle.

Key Developments

The CJEU's ruling in Data Protection Commissioner v. Facebook Ireland (Schrems) underscores that supervisory authorities possess broad powers to scrutinize whether a lawful basis adequately protects data subjects, especially in cross-border contexts. While Schrems primarily addresses transfer mechanisms, it reinforces that national DPAs can independently assess the lawfulness of underlying processing operations. In Fashion ID v. Verbraucherzentrale NRW, the CJEU established that controllers must provide transparent information about the lawful basis relied upon, but only for processing operations where they actually determine purposes and means. This limits joint controllers' information duties to their respective roles. The EDPB's Guidelines 06/2020 on the interplay between PSD2 and the GDPR clarifies how sectoral laws may constrain the availability of certain bases, particularly in financial services. Recent enforcement actions, including the ICO's penalty against Allay Claims Ltd, demonstrate that failure to establish a valid lawful basis—particularly defective consent—triggers strict accountability and financial penalties.

Practical Guidance

  • Map processing activities to specific bases: Document which Article 6(1) basis applies to each processing operation before commencement, ensuring the basis is appropriate for the context and data subject relationship.
  • Conduct legitimate interest assessments (LIAs): For Article 6(1)(f), perform and document a three-part test identifying the legitimate interest, necessity, and balancing against data subject rights and reasonable expectations per Recital 47.
  • Verify consent mechanisms: Ensure consent under Article 6(1)(a) is freely given, specific, informed, and unambiguous, with clear opt-out mechanisms, as defective consent invalidates the basis entirely.
  • Limit vital interests to exceptional cases: Reserve Article 6(1)(d) for genuine life-or-death scenarios where no other basis is viable, consistent with Recital 46.
  • Align transparency obligations: Provide data subjects with information on the lawful basis relied upon at the time of collection, tailored to the controller's actual role in determining processing purposes, as clarified in Fashion ID.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 10
Art. 6(1) Processing shall be lawful only if and to the extent that at least one of the following applies: GDPR Art. 6(1)(d) processing is necessary in order to protect the vital interests of the data subject or of another natural person; GDPR Art. 6(1)(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are ov… GDPR Art. 6(3) The basis for the processing referred to in point (c) and (e) of paragraph 1 shall be laid down by: GDPR rec 46 Recital 46 — lawful processing vital interests protection GDPR Apr 2016 rec 47 Recital 47 — legitimate interests as processing legal basis GDPR Apr 2016 rec 45 Recital 45 — legal basis for public interest processing GDPR Apr 2016 rec 41 Recital 41 — legal basis clarity and foreseeability GDPR Apr 2016 rec 112 Recital 112 — Public interest vital interests data transfer derogations GDPR Apr 2016 rec 88 Recital 88 — personal data breach notification rules GDPR Apr 2016 rec 50 Recital 50 — compatible further processing of personal data GDPR Apr 2016 rec 69 Recital 69 — data subject right to object GDPR Apr 2016 rec 72 Recital 72 — profiling subject to regulation rules GDPR Apr 2016 rec 113 Recital 113 — non repetitive limited data transfers GDPR Apr 2016
Case Law 51
CJEU Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v Rīgas pašvaldības SIA ‘Rīgas satiksme’ CJEU May 2017 CJEU Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems CJEU Jul 2020 CJEU VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”) CJEU Nov 2010 CJEU Data Protection Commissioner v. Schrems and Facebook CJEU Oct 2015 CJEU WORTEN-EQUIPAMENTOS PARA O LAR SA V. ACT (AUTHORITY FOR WORKING CONDITIONS), 30.5.2013 (“WORTEN”) CJEU May 2013 CJEU Data Protection Commissioner v. Schrems and Facebook CJEU Oct 2015 CJEU Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy CJEU Sep 2017 CJEU GOOGLE SPAIN SL V. AEPD (THE DPA) & MARIO COSTEJA GONZALEZ, 13.May.2014 (“GOOGLE v. Spain”) CJEU May 2014 ECLI:EU:F:2011:101 V & EDPS v. EUROPEAN PARLAMENT CJEU Jul 2011 CJEU RYNES V. ÚŘAD PRO OCHRANU OSOBNICH ÚDAJŮ, 11.12.2014 (“RYNES”) CJEU Dec 2014 CJEU Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems CJEU Jul 2020 CJEU Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy CJEU Sep 2017 CJEU RYNES V. ÚŘAD PRO OCHRANU OSOBNICH ÚDAJŮ, 11.12.2014 (“RYNES”) CJEU Dec 2014 CJEU ASOCIACION NACIONAL DE ESTABLECIMIENTOS FINANCIEROS DE CREDITO (ASNEF) AND FEDERACION DE COMERCIO ELECTRONICO Y MARKETING DIRECTO (FECEMD) V. ADMINISTRACION DEL ESTADO, 24.Nov.2011 (“ASNEF”) CJEU Nov 2011 CJEU V & EDPS V. EUROPEAN PARLAMENT, 5.7.2011 (“V v. European Parliament”) CJEU Jul 2011 CJEU CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is CJEU Jun 2010 CJEU BUNDESVERBAND DER VERBRAUCHERZENTRALEN UND VERBRAUCHERVERBANDE —BERBRAUCHERZENTRALE BUNDESVERBAND V. PLANET49 GmbH (“PLANET49”) CJEU Oct 2019 CJEU FASHION ID GmbH & Co. KG v. VERBRAUCHERZENTRALE NRW eV CJEU Jul 2019 CJEU FASHION ID GmbH & Co. KG v. VERBRAUCHERZENTRALE NRW eV CJEU Jul 2019 CJEU SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”) CJEU Oct 2015 Show 31 more →
Guidance 30
guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines on the practical implementation of amicable settlements Guidelines 06/2022 on the practical implementation of amicable settlements EDPB May 2022 guidelines on the interplay of the second payment services directive and the gdpr Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR EDPB Dec 2020 guidelines on processing of personal data through video devices Guidelines 3/2019 on processing of personal data through video devices EDPB Jan 2020 guidelines on technical scope of art 53 of eprivacy directive Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive EDPB Oct 2024 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 guidelines on the application of article 651a gdpr Guidelines 03/2021 on the application of Article 65(1)(a) GDPR EDPB May 2023 guidelines for identifying a controller or processors lead supervisory authority Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority EDPB Apr 2023 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on deceptive design patterns in social media platform interfaces how to recognise Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them EDPB Feb 2023 guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 guidelines on relevant and reasoned objection under regulation 2016679 Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679 EDPB Mar 2021 Show 10 more →
Enforcement 9
NAIH (Hungary) NAIH fines online store HUF 2M for unclear and incomplete privacy notice NAIH (Hungary) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 ICO (UK) ICO (UK) - Allay Claims Ltd ICO (UK) Jan 2026 Spanish Data Protection Authority (aepd) SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) Sep 2022 LfD (Lower Saxony) LfD (Lower Saxony) - Fine EUR 900,000 against bank LfD (Lower Saxony) Sep 2022 APD/GBA (Belgium) APD/GBA (Belgium) - 117/2022 APD/GBA (Belgium) Jul 2022 APD/GBA (Belgium) APD/GBA (Belgium) - 115/2022 APD/GBA (Belgium) Jul 2022 DSB (Austria) DSB (Austria) - 2021-0.698.184 DSB (Austria) Oct 2021 AEPD (Spain) AEPD (Spain) - PS/00249/2025 AEPD (Spain) Aug 2026
News 69
GDPRhub UODO (Poland) - DKE.561.1.2026 GDPRhub Aug 2026 European Data Protection Board EDPB calls for legal basis for cross-regulatory information sharing European Data Protection Board Jul 2026 noyb - European Center for Digital Rights Digital Omnibus: EU DPAs reject many proposed changes to the GDPR noyb - European Center for Digital Rights Feb 2026 noyb - European Center for Digital Rights Austrian Supreme Court: Meta must give users full access to their data noyb - European Center for Digital Rights Dec 2025 European Data Protection Board AI-generated imagery and protection of privacy: EDPB supports joint Global Privacy Assembly’s statement European Data Protection Board Feb 2026 European Data Protection Board EDPB gives recommendations to make online shopping more respectful of users’ privacy, discusses the Digital Omnibus proposal and appoints new Deputy Chair European Data Protection Board Dec 2025 Electronic Frontier Foundation “Free” Surveillance Tech Still Comes at a High and Dangerous Cost Electronic Frontier Foundation Feb 2026 noyb - European Center for Digital Rights Like to play alone? Ubisoft is still watching you! noyb - European Center for Digital Rights Apr 2025 Electronic Frontier Foundation EFFecting Change: Get the Flock Out of Our City Electronic Frontier Foundation Feb 2026 Electronic Frontier Foundation The Homeland Security Spending Trail: How to Follow the Money Through U.S. Government Databases Electronic Frontier Foundation Jan 2026 noyb - European Center for Digital Rights Snap Election faster than German DPAs: Microtargeting continues to influence voters noyb - European Center for Digital Rights Feb 2025 SSRN Legacy Switches: A Proposal to Protect Privacy, Security, Competition, and the Environment from the Internet of Things SSRN Nov 2025 noyb - European Center for Digital Rights AG at CJEU: Facebook must "minimize" personal data for ads in EU noyb - European Center for Digital Rights Apr 2024 IAPP Court rules on Experian appeal of ICO enforcement notice IAPP Feb 2023 IT en Recht Court of Audit points out obstacles in implementation of GDPR in Netherlands in letter to Chamber IT en Recht Apr 2023 EDPB Record fine for Instagram following EDPB intervention EDPB Sep 2022 Hogan Lovells UK data protection reform: How the UK's GDPR may change Hogan Lovells Sep 2022 NL EU Court Expert CJEU clarifies GDPR principles of purpose limitation and storage limitation NL EU Court Expert Oct 2022 IAPP Greek SA fines Clearview AI for EUR 20M IAPP Oct 2022 AEPD AEPD publishes GDPR Risk Assessment AEPD Oct 2022 Show 49 more →