What Is a Lawful Basis Under GDPR, and Why Can You Not Change It Later?
A lawful basis is one of the six grounds in Article 6(1) GDPR on which personal data may be processed at all: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, a task in the public interest, or legitimate interests. Processing "shall be lawful only if and to the extent that at least one" of them applies, and Recital 40 puts it the other way round: personal data "should be processed on the basis of the consent of the data subject concerned or some other legitimate basis". The contrarian point is the one that decides most real disputes. The basis is chosen per purpose, before collection, and the European Data Protection Board's consent guidelines state at paragraph 123 that "the controller cannot swap from consent to other lawful bases", giving as the forbidden example an attempt "to retrospectively utilise the legitimate interest basis in order to justify processing, where problems have been encountered with the validity of consent". Choose wrong, and the fix is not a memo. It is stopping.
This article covers the six grounds and what each actually requires, the rule against swapping and where it comes from, the three-step test the EDPB sets for legitimate interests, why consent is the wrong default for most business processing, the second layer for special-category data, and what has to be written down.
Key takeaways
- Six grounds in Article 6(1), one required per purpose. The Irish Data Protection Commission's guidance says there is "no hierarchy or preferred option within this list".
- The basis must be decided before collection and stated in the privacy notice under Article 13(1)(c). The EDPB says a controller "cannot swap from consent to other lawful bases" afterwards.
- Legitimate interests is a three-part test, documented before processing: a lawful, precisely articulated and present interest; necessity with no less intrusive means; and a balance the individual does not win.
- Consent carries the most obligations of any basis, must be as easy to withdraw as to give, and fails where there is a clear imbalance of power. It is rarely the safe default it is treated as.
- Special-category data needs an Article 9(2) condition on top of the Article 6 basis, and the two are separate questions.
The six grounds, and what each one actually asks of you
Article 6(1) lists them in six lettered points. Reading the operative words in each tells you what it demands.
| Basis | Article 6(1) wording | What it requires in practice | Rights consequence |
|---|---|---|---|
| Consent | The data subject "has given consent to the processing of his or her personal data for one or more specific purposes" | A freely given, specific, informed and unambiguous indication by statement or clear affirmative action (Article 4(11)); the controller must be able to demonstrate it (Article 7(1)) | Withdrawable at any time, and "it shall be as easy to withdraw as to give consent" (Article 7(3)) |
| Contract | Processing "is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract" | The data subject is a party, and the processing is necessary for that contract, not merely mentioned in it | No right to object under Article 21, which is why this basis is over-claimed |
| Legal obligation | Processing "is necessary for compliance with a legal obligation to which the controller is subject" | An obligation laid down by Union or Member State law (Article 6(3)); a contractual duty to a customer does not qualify | No right to object |
| Vital interests | Processing "is necessary in order to protect the vital interests of the data subject or of another natural person" | A life-or-safety situation; the DPC describes it as unlikely to apply where a less intrusive route exists | Narrow, emergency use |
| Public task | Processing "is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller" | A basis in Union or Member State law (Article 6(3)); mostly for public bodies | Right to object on grounds of the individual's particular situation (Article 21(1)) |
| Legitimate interests | Processing "is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject" | A documented three-step assessment, before processing; unavailable to public authorities performing their tasks | Right to object under Article 21(1); an unconditional right to object to direct marketing under Article 21(2) and (3) |
Three of those rows carry the word "necessary", and the Irish Data Protection Commission's guidance on legal bases, last updated December 2019, treats necessity as a genuine test rather than a label: for each basis that includes it, the processing must be "a reasonable and proportionate way" of achieving the purpose, and where a less intrusive way exists the basis is unlikely to be appropriate. The same guidance makes the point most teams miss in the first sentence they read: "there is no hierarchy or preferred option within this list, instead each instance of processing should be based on the legal basis which is most appropriate in the specific circumstances", and consent, "whilst perhaps the most well-known, is not the only legal basis for processing", nor "even the most appropriate in many cases".
One basis per purpose, chosen before you collect
The unit of analysis is the purpose, not the dataset and not the company. The EDPB's legitimate interest guidelines, Guidelines 1/2024 in the version published for public consultation on 8 October 2024, say at paragraph 10 that "when personal data are processed for different purposes the processing for each of those purposes must fall within one of the cases provided for in Article 6(1)", and that "the purpose and the legal basis of such processing must be identified from the outset of the processing and must be communicated to the data subject". The same customer record can therefore rest on contract for billing, legal obligation for tax retention, and legitimate interests for fraud prevention, and each of those is a separate line in the register with its own justification.
"From the outset" is the operative phrase. Article 13(1)(c) requires the notice given at collection to state "the purposes of the processing for which the personal data are intended as well as the legal basis for the processing", and 13(1)(d) adds that where the basis is legitimate interests, the notice must state "the legitimate interests pursued by the controller or by a third party". You cannot state a basis you have not chosen. That is the mechanism behind the no-swapping rule: the EDPB's consent guidelines, paragraph 123, reason that "because of the requirement to disclose the lawful basis, which the controller is relying upon at the time of collection of personal data, controllers must have decided in advance of collection what the applicable lawful basis is".
Why you cannot swap, and what happens when consent fails
Paragraph 122 of the consent guidelines states the principle in terms of fairness: "if a controller chooses to rely on consent for any part of the processing, they must be prepared to respect that choice and stop that part of the processing if an individual withdraws consent. Sending out the message that data will be processed on the basis of consent, while actually some other lawful basis is relied on, would be fundamentally unfair to individuals." Paragraph 123 draws the conclusion: no swap, and specifically no retrospective reach for legitimate interests when consent turns out to have been invalid.
The practical consequence is asymmetric. If you chose legitimate interests, ran the assessment properly and documented it, an individual's objection under Article 21(1) is met by showing "compelling legitimate grounds" that override their interests, and outside direct marketing that argument is sometimes available. If you chose consent and the consent was defective, the processing since collection had no basis, and the only clean repair the EDPB describes is refreshing consent in a compliant way. Article 6 is in the higher of the two fine tiers: Article 83(5) covers "the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9" and caps at 20,000,000 euros or 4 percent of total worldwide annual turnover, whichever is higher.
There is one door that is not a swap. Article 6(4) allows further processing for a purpose other than the one the data was collected for, where that new purpose is compatible with the original, judged on factors including the link between the purposes, the context of collection, the nature of the data, the possible consequences for the individual and the safeguards in place. That is a compatibility analysis for a new purpose, documented and notified under Article 13(3). It is not permission to re-label the basis for the original purpose.
Legitimate interests is a test, not a fallback
Most business processing that is not contract or legal obligation ends up on Article 6(1)(f), and the EDPB's 2024 guidelines exist because it is used carelessly in both directions. Paragraph 9 says the basis "cannot be considered as a legal basis 'by default'", should not be treated as "a last option if no other legal bases apply", and equally should not "be seen as a preferred option by controllers" or have its use "unduly extended to circumvent specific legal requirements or because it would be considered as less constraining than the other legal bases".
The guidelines set three cumulative conditions, assessed in order and, per paragraph 12, "at the outset of the processing, with the involvement of the Data Protection Officer (DPO) (if designated)", and "documented by the controller in line with the accountability principle set out in Article 5(2)".
A legitimate interest. Not every interest qualifies. The interest must be lawful, "clearly and precisely articulated", and "real and present, and not speculative". The guidelines note that the interest "must be present and effective at the date of the data processing and must not be hypothetical at that date". Recital 47 offers examples, including that a legitimate interest "could exist for example where there is a relevant and appropriate relationship between the data subject and the controller in situations such as where the data subject is a client or in the service of the controller", that processing "strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest", and that processing "for direct marketing purposes may be regarded as carried out for a legitimate interest". Paragraph 18 of the guidelines is explicit that the relationship example is "just an example of a possible indicator" and leaves the controller obliged to establish all three cumulative conditions.
Necessity. Per the executive summary, "it should be ascertained whether the legitimate interests pursued cannot reasonably be achieved just as effectively by other means less restrictive of the fundamental rights and freedoms of data subjects", and "if such other means exist, the processing may not be based on Article 6(1)(f)". This is where data minimisation does its work: the impact weighed in the balance has to be the impact of the minimum processing that achieves the interest.
The balance. The controller weighs its interest against the individual's interests, rights and freedoms, taking into account the impact of the processing and, per Recital 47, "the reasonable expectations of data subjects based on their relationship with the controller". Paragraph 55 states the outcome: if the individual's interests do not override the controller's, "the envisaged processing may take place". Paragraph 60 states the other outcome: if they do, "and no sufficient mitigating measures can be taken, the processing cannot be based on Article 6(1)(f)". Mitigating measures are allowed, with two constraints. Paragraph 57 says they cannot consist of things the controller must do anyway, such as meeting information, security, minimisation or rights obligations; they must "go beyond what is already necessary". And paragraph 58 says that after adopting them the controller "should perform the balancing test anew".
Paragraph 59 puts the burden where it belongs: "the duty is upon the controller to demonstrate that the balancing test has been conducted appropriately". Paragraph 68 adds a transparency step most notices omit: information to individuals "should make it clear that they can obtain information on the balancing test upon request". The DPC's guidance says the same in plainer words, that controllers "should keep a record of the assessment they undertook" and that "there is no set way in which controller have to do this, but it is important that they record their reasoning in some way".
Direct marketing: the basis that comes with an unconditional exit
Recital 47's last sentence is the one marketing teams quote, and it is true as far as it goes: direct marketing "may be regarded as carried out for a legitimate interest". What travels with it is Article 21(2): "the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing", and Article 21(3): where they object, "the personal data shall no longer be processed for such purposes". No balancing, no compelling grounds, no exceptions. Legitimate interests for marketing is workable only with an opt-out that actually works, which is why the guidelines' own first example is a marketer whose interest fails the "legitimate" test because the sector's rules on commercial communications override it.
Two things this article does not cover, because other pages own them. Whether a cookie or tracking technology needs prior consent is an ePrivacy question, not an Article 6 one, and the answer for US-facing sites is in do US websites need a cookie banner. Whether a browser signal has to be honoured as an opt-out under US state law is in do you have to honor Global Privacy Control. Choosing a lawful basis for marketing under the GDPR does not answer either.
Consent is not the safe default
Consent looks like the cautious choice and is usually the most fragile one. Article 7 attaches conditions no other basis carries: the controller "shall be able to demonstrate that the data subject has consented"; a request bundled into other matters must be "clearly distinguishable"; the individual "shall have the right to withdraw his or her consent at any time" and "it shall be as easy to withdraw as to give consent"; and in judging whether consent was freely given, "utmost account shall be taken" of whether a service was made conditional on consent to processing that was not necessary for it. Recital 43 adds that consent "should not provide a valid legal ground" where "there is a clear imbalance between the data subject and the controller", and presumes it is not freely given where separate consent cannot be given to separate operations.
Put those together and the pattern emerges. Consent is the right basis where the individual genuinely has a free choice and the processing is optional to them: a newsletter, an optional feature, research participation. It is the wrong basis for anything the service cannot run without, anything an employee is asked to agree to by an employer, and anything you would not actually stop doing if the person said no. In each of those cases contract, legal obligation or legitimate interests is the honest description, and choosing consent instead means the processing stops the day someone withdraws it, with no swap available.
The second layer: special-category data
Article 9(1) prohibits processing of data "revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership", genetic data, biometric data used for unique identification, health data, and data "concerning a natural person's sex life or sexual orientation", unless one of the ten conditions in Article 9(2) applies. Those conditions are separate from the Article 6 bases and sit on top of them. Explicit consent is the first of them; the others cover employment law obligations, a not-for-profit body's processing of its own members' data, vital interests where the person cannot consent, data manifestly made public, legal claims, substantial public interest under law, health and social care, public health, and research and archiving.
Two consequences. A legitimate interests assessment cannot on its own justify processing health data; an Article 9(2) condition is needed as well, and most of them require a basis in law rather than in the controller's judgement. And the presence of special-category data at scale is one of the three cases that always require a DPIA, which is covered in what is a DPIA and not restated here.
What has to be written down
The lawful basis register is the document this article has been describing without naming. For each purpose: the purpose itself, the categories of data, the basis chosen, the reason it fits, the legitimate interests assessment where 6(1)(f) is used, the Article 9(2) condition where special-category data is involved, the date, and who decided. That register is what the privacy notice is transcribed from, what the Article 30 record's "purposes" column points to, and what a supervisory authority reads first when it asks why a particular processing operation was lawful. The record it lives beside is covered in what is a RoPA.
The honest caveat: the basis can be right and the processing still wrong
Choosing a basis correctly satisfies Article 6. It does not satisfy Article 5. Processing still has to be fair, transparent, limited to its purpose, minimised, accurate, time-limited and secure, and the EDPB's paragraph 57 is a reminder that meeting those obligations is the floor, not a mitigation you can credit yourself with in a balancing test. A perfect legitimate interests assessment for a purpose you never told anyone about is a failure of Article 13, not a success under Article 6.
Against our own interest: for most business-to-business software companies the register is short and the decisions are not hard. Billing is contract, tax retention is legal obligation, security logging and fraud prevention are legitimate interests with an assessment, the newsletter is consent. That is an afternoon with the DPC guidance open, not an engagement. The judgment calls that justify help are the ones where the honest basis is legitimate interests and the balance is genuinely close, where the same data serves several purposes on different bases, or where a customer contract has already promised consent for something the product cannot run without.
Where Top Floor fits
We build the lawful basis register purpose by purpose, write the legitimate interests assessments in the three-step structure the EDPB sets out, and make sure the notice, the record and the consent flows all say the same thing, because a supervisory authority reads all three. That is GDPR work. Where the same processing is also subject to US state laws that use different vocabulary for similar decisions, global privacy keeps one register with jurisdiction-specific views. Where the register needs to stay true as purposes change, the review cadence sits inside compliance as a service.
How to decide this week
List every purpose for which you process personal data; if the list has fewer than ten lines you have missed some. Against each, write the basis and one sentence saying why it fits. Wherever you wrote consent, ask whether you would actually stop that processing if the person withdrew; if not, the honest basis is something else and it needs to be chosen now, before the next collection. Wherever you wrote legitimate interests, check whether an assessment exists in writing with the three steps visible; if it does not, the basis is not yet available to you. Then open your privacy notice and check that every line of the register appears in it, in the same words, because Article 13 is where the register becomes a public commitment.
Frequently asked questions
Can we change our lawful basis after we have collected the data?
Not as a repair. The EDPB's consent guidelines state that the controller cannot swap from consent to other lawful bases, and give the specific example that it is not allowed to retrospectively rely on legitimate interests to justify processing where problems have been found with the validity of consent, because the basis has to be disclosed at the time of collection and therefore decided before it. What the Regulation does allow is further processing for a new, compatible purpose under Article 6(4), which is a documented compatibility analysis for a different purpose rather than a re-labelling of the basis for the original one.
Is legitimate interests easier to rely on than consent?
It is different, not easier. The EDPB's guidelines say the basis cannot be treated as a default or as a last resort, and should not be chosen because it seems less constraining than the alternatives. It requires a documented three-step assessment before processing starts: a lawful, precisely articulated and present interest; necessity, meaning no less intrusive means would achieve the interest as effectively; and a balance in which the individual's interests, rights and freedoms do not override the controller's. The controller has to be able to show the assessment was done properly, has to name the interest in the privacy notice, and has to honour the right to object, which for direct marketing is unconditional.
Which lawful basis should we use for marketing emails?
Under the GDPR, direct marketing may be carried out on the basis of legitimate interests, as Recital 47 says, but only with the Article 21(2) right to object honoured absolutely: once a person objects, the data may no longer be processed for that purpose, with no balancing available. Consent is the alternative and is the right basis where the individual has a genuine free choice, such as an optional newsletter. Whether the sending itself, or any tracking attached to it, needs prior consent under electronic communications rules is a separate ePrivacy question that Article 6 does not answer, and the cookie and tracking rules are covered in our cookie banner article.
Do we need a lawful basis for each purpose or for each dataset?
For each purpose. The EDPB's legitimate interest guidelines state that when personal data are processed for different purposes, the processing for each purpose must fall within one of the Article 6(1) cases, and that the purpose and basis must be identified from the outset and communicated to the data subject. The same customer record can therefore rest on contract for billing, legal obligation for tax retention and legitimate interests for fraud prevention at the same time, with each purpose recorded separately in the register and stated separately in the privacy notice.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.