Legal
Legal Basis
The lawful ground under which personal data may be processed — the GDPR defines six possible bases.
A legal basis (also called lawful basis) is the legal justification for processing personal data. Under the GDPR, every processing activity must have one of six legal bases.
The Six Legal Bases (Article 6(1))
| Basis | When It Applies |
|---|---|
| (a) Consent | The data subject has given clear, affirmative agreement |
| (b) Contract | Processing is necessary to perform a contract with the data subject |
| (c) Legal obligation | Processing is necessary to comply with the law |
| (d) Vital interests | Processing is necessary to protect someone's life |
| (e) Public task | Processing is necessary for a task in the public interest |
| (f) Legitimate interest | Processing is necessary for a legitimate interest that doesn't override the data subject's rights |
Choosing the Right Basis
- The legal basis must be determined before processing begins
- It must be documented and communicated in the privacy notice
- Changing the legal basis after the fact is generally not permitted