In one sentence. GDPR Article 6 lists the six lawful bases that authorize the processing of personal data: (a) consent, (b) contract performance, © legal obligation, (d) vital interests, (e) public task / official authority, (f) legitimate interests. At least one must apply for any processing activity to be lawful. Selecting and documenting the correct basis is the first compliance question on every Record of Processing Activity entry.
Every processing of personal data needs an applicable Article 6 basis. The assessment should identify the particular purpose and the actual necessity of the processing, rather than select a label for an entire database. The same customer record can support different operations whose legal justifications differ.
Key takeaways
- Article 6(1) lists six exhaustive lawful bases. At least one must apply.
- The bases are not interchangeable — the right choice depends on the actual processing context, not commercial preference.
- Identify the basis or bases that actually apply to each purpose. Do not list alternatives merely as a fallback if the preferred basis fails.
- For special category data (health, biometrics, etc.), Article 9 adds a second-layer condition on top of Article 6.
- The basis must be identified before processing starts and documented in the Record of Processing Activity.
1. Article 6(1) text and the six bases
The official Article 6 text requires at least one applicable condition. In practical terms, paragraph (1) covers consent, necessary contractual processing, legal obligations, vital interests, legally grounded public tasks or authority, and legitimate interests subject to a balancing assessment. Paragraphs (2) and (3) address relevant EU and national legal provisions; paragraph (4) addresses assessment of a new purpose in the circumstances it describes.
Article 6(1)(f): what legitimate interests requires
For the query “GDPR Article 6(1)(f)”, the direct answer is that a controller or third party may pursue a legitimate interest through necessary processing only where the individual’s interests and fundamental rights do not override it. Children receive particular attention. Public authorities cannot use this ground when performing their public tasks.
The three questions are cumulative: identify a lawful and concrete interest; assess whether the processing is necessary for that interest; then weigh its effects on the people concerned. Calling an activity useful, commercially valuable or standard in the industry does not answer those questions.
A documented legitimate-interest assessment should explain the alternatives considered, people’s reasonable expectations, possible harms and effective safeguards. Reconsider the conclusion if the purpose, data, population or impact changes. The legal basis is not a one-time permission for every future use of the same dataset.
2. (a) Consent
When to use: marketing emails, optional cookies, optional features the user opts into, sharing data with partners.
When NOT to use: employment relationships where the power imbalance prevents a genuinely free choice, service-essential processing (use contract instead), legal obligations.
3. (b) Contract performance
Processing necessary to perform a contract the data subject is party to, or take pre-contract steps at their request.
When to use: shipping an order, processing a payment, providing the actual service the user signed up for, handling customer support.
Limit: only data strictly necessary for the contract qualifies. “Improving our service” rarely qualifies on its own — see legitimate interest.
4. © Legal obligation
Processing required by EU or Member State law to which the controller is subject.
When to use: tax records for the period required by the applicable tax law, AML/KYC checks for regulated entities, employee data required by social security law, court orders.
Limit: a contractual obligation isn’t a legal obligation. The law must require the specific processing.
5. (d) Vital interests
Processing necessary to protect the vital interests of the data subject or another person.
When to use: medical emergencies (the unconscious patient at the ER), humanitarian aid, missing persons.
Limit: rarely the right basis for routine processing. EDPB has clarified this is for life-threatening situations, not “important business needs.”
6. (e) Public task
Processing necessary for a task carried out in the public interest or under official authority.
When to use: by public authorities (administrations, public hospitals, public schools) for their statutory missions.
Limit: the public task or authority must have a basis in EU or Member State law under Article 6(3). A private organisation may perform a legally grounded public task; its ownership alone does not decide eligibility.
7. (f) Legitimate interests
The most flexible — and most contested — basis. Three-part test required (the “balancing test”):
- Purpose test: is there a legitimate interest pursued?
- Necessity test: is the processing necessary to achieve it?
- Balancing test: do the individual’s interests, rights or freedoms override the legitimate interest, considering reasonable expectations and actual effects?
When to use: fraud prevention, IT security monitoring, B2B prospecting (in some EU countries), basic analytics, internal administration.
When NOT to use: special category data (Article 9 forbids it as standalone basis), processing children’s data without extra care, where consent would be more appropriate (e.g., marketing emails).
8. Choosing the right basis: decision matrix
| Processing | Recommended basis | Why |
|---|---|---|
| Newsletter sign-up | Consent (a) | Marketing, opt-in |
| Order fulfillment | Contract (b) | Necessary to deliver |
| Payroll | Legal obligation © | Tax + social security law |
| AML/KYC | Legal obligation © | Regulated by law |
| Medical emergency | Vital interests (d) | Life-saving |
| Public school enrollment | Public task (e) | Statutory mission |
| Fraud detection | Legitimate interests (f) | With balancing test |
| Job application | Pre-contract steps (b) | At candidate’s request |
| Behavioral advertising | Consent (a) | High-impact processing |
| IT security logs | Legitimate interests (f) | With balancing test |
| Customer support tickets | Contract (b) | Part of service |
| Internal administration | Legitimate interests (f) | Light, balancing test |
9. Special categories of data: Article 6 + Article 9
Processing special category data (health, biometrics, religion, political opinions, sexual orientation, etc.) requires both:
- A lawful basis under Article 6, AND
- An additional condition under Article 9(2) (e.g., explicit consent, employment law, vital interests, important public interest)
10. Documentation requirements
Record the purpose, applicable basis, reasoning and owner before processing starts. For legitimate interests, keep the assessment and its review triggers. For a legal obligation or public task, identify the relevant law. For consent, retain evidence of the choice and an effective withdrawal route.
Communicate the basis in the relevant direct-collection notice or indirect-collection notice. Recording the basis alongside a processing register is useful for accountability, although it is not an express field in Article 30(1).
11. Changes of purpose and withdrawal of consent
Do not retroactively change the stated basis to rescue invalid consent or defeat a withdrawal. A withdrawal stops the consent-based operation for the future; separate processing required by law may continue where that separate basis actually applies. Explain these distinctions in the notice instead of treating every record as having one universal fate.
A proposed new purpose requires its own review. Article 6(4) identifies factors for assessing compatibility where its conditions apply, including the relationship between purposes, collection context, nature of the data, consequences and safeguards. Other duties, including informing people before further processing under Articles 13(3) or 14(4), must also be addressed. Compatibility should not be asserted solely because both purposes are commercially useful.
12. Hypothetical Article 6(1)(f) decision record
A service provider wants to retain failed-login events to investigate account takeover. Its stated interest is protecting customer accounts and service availability. The team limits the proposed fields to account identifier, event time, source information needed for investigation and result. It rejects recording passwords or message contents because these are not necessary for that task.
The necessity assessment compares the proposed logging with shorter retention and less granular data. The team documents why its chosen period is needed for the actual investigation process. It does not borrow a universal number from a generic retention table. The balancing assessment considers whether users reasonably expect security logging, the harm from misuse of the records, access restrictions and the procedure for handling objections.
The decision record contains the purpose, interest holder, fields, necessity reasons, less intrusive alternatives, affected groups, risks, safeguards, conclusion, owner and review trigger. If the same logs are later proposed for measuring employee productivity, that is a new use requiring fresh analysis. The original security interest does not automatically justify it.
Use the storage-limitation guide to connect the decision to deletion and the Article 14 guide where the records come from another organisation. Where children or sensitive data are involved, assess the additional protections explicitly.
A review should also check whether another rule independently requires consent or limits the operation. Article 6(1)(f) cannot set aside electronic-marketing rules or the Article 9 conditions for special categories. Record an unresolved issue as unresolved and assign the work needed before processing begins.
The primary legal source is Article 6 GDPR. The EDPB’s Guidelines 1/2024 consultation material provides additional context; check the version and adoption status before treating a consultation document as final guidance.
FAQ
What are the six lawful bases under GDPR Article 6?
(a) Consent, (b) Contract performance, © Legal obligation, (d) Vital interests, (e) Public task, (f) Legitimate interests. At least one must apply for any processing of personal data to be lawful.
Can I rely on multiple lawful bases simultaneously?
Article 6 says at least one basis must apply. Distinct purposes involving the same data can have different bases, and more than one provision may be relevant. The controller must identify what actually applies and explain it clearly. Listing every basis indiscriminately does not satisfy that assessment.
Is consent always the safest choice?
No. Consent is appropriate only where the person can make a free, informed and specific choice and withdraw it. Employment power imbalances often prevent that freedom, though consent is not categorically impossible. Withdrawal stops the consent-based operation; independently justified legal retention requires separate analysis.
Do I need a legitimate interest assessment (LIA)?
If you invoke Article 6(1)(f), yes. The three-part test (purpose, necessity, balancing) must be documented before processing starts. The LIA is the document you’ll be asked for during a CNIL inspection.
What’s the difference between Article 6 and Article 9 GDPR?
Article 6 covers the lawful basis for all personal data processing. Article 9 adds a second condition for processing special categories of data (health, biometrics, religion, etc.). Both must be satisfied to process special categories.