Lawful basis GDPR

The six lawful bases in the GDPR

A lawful basis is required for the processing of personal data for the processing to be lawful. The lawful basis must be determined by the company responsible for the processing (the controller) before the processing begins. It is about having a valid reason or legal basis for each specific processing activity. The GDPR sets out six different lawful bases: consent, contract, legal obligation, protection of vital interests, task carried out in the public interest or exercise of official authority, and legitimate interests.

A specific processing activity may fall within one or more of the lawful bases. However, each processing operation must be tied to one of these bases to be lawful; that is, even if the processing could fit within several of the GDPR legal bases, the controller must choose one of them.

The choice of lawful basis affects which rights the data subjects (for example, the controller’s customers) have and which obligations rest on the controller. It is therefore important to analyse and document carefully which lawful basis GDPR is used for each specific processing operation. Without a lawful basis, the processing of personal data is unlawful under the GDPR.

GDPR legal bases: In this text, we explain the six lawful bases. Morling Consulting assesses which legal basis may be relevant for a given processing activity and what the effect of the chosen lawful basis is.

Business professional standing at a crossroads in front of a signpost, symbolising choosing the correct lawful basis GDPR for data processing decisions.

Choosing the lawful basis GDPR

When an organisation selects a lawful basis for processing personal data, it is important to make a careful assessment. The choice affects both rights and obligations, and it is not always straightforward to change the basis afterwards. Key factors to consider include:

  • Purpose of the processing: The processing must always have a clear and specific purpose.
  • Necessity: Choose the legal basis GDPR that best corresponds to why the personal data needs to be processed — if several could apply.
  • Rights of data subjects: Consider the rights that follow from each GDPR legal basis, for example the right to withdraw consent or to object to processing.
  • Documentation: There must be clear documentation of which legal basis GDPR has been chosen and why.
  • Future needs: Assess whether the chosen basis is sustainable over time, or whether changed circumstances might affect its validity.

By analysing these factors, organisations reduce compliance risks and strengthen the protection of data subjects’ rights.

Support with the lawful basis GDPR

At Morling Consulting, we help companies with the GDPR, for example assessing the applicable legal basis. We support organisations with GDPR compliance and can assist with one-off engagements, projects or longer-term arrangements across Europe. We can help identify the appropriate legal basis GDPR for each processing activity and ensure the rationale is recorded.

Business professional in a suit reviewing a legal document outlining Lawful basis GDPR requirements for data processing.

Common questions and answers on lawful basis under the GDPR

A lawful basis is the legal ground required to process personal data lawfully under the General Data Protection Regulation (GDPR). Processing must always take place under one of the six lawful bases set out in the GDPR; otherwise the processing is unlawful.

  • Consent.
  • Contract.
  • Legal obligation.
  • Protection of vital interests.
  • Task carried out in the public interest or exercise of official authority.
  • Legitimate interests.

Yes. Without a lawful basis, processing is unlawful. The controller must have identified and documented a valid legal basis GDPR before personal data may be processed.

It depends on the purpose of the processing. You should consider:

  • What the purpose of the processing is.
  • Who the data subject is.
  • The relationship the company or organisation has with the data subject.
  • Whether there are statutory requirements to follow.
  • Whether consent is practical and legally appropriate.

The choice must be documented because it affects both obligations and data subjects’ rights. Data subjects must also be informed of the lawful bases applied and the rights associated with them, for example in a privacy notice.

Legitimate interests is appropriate when:

  • There is a clear, legitimate interest on the part of the controller.
  • The processing is necessary to achieve that legitimate interest.
  • The data subject’s rights and freedoms do not outweigh it.
  • Examples include certain types of marketing or fraud prevention.

Yes. Under the accountability principle in the GDPR, every processing operation must be justifiable and documented. The documentation must show which GDPR legal basis has been chosen and how the assessment was carried out (particularly for legitimate interests).

We offer:

  • Review and analysis of your personal data processing.
  • Advice on selecting and applying a lawful basis.
  • Support with documentation, for example legitimate interests assessments.
  • Help to adapt procedures, policies and contracts to the GDPR.

If an organisation processes personal data without a valid lawful basis, it breaches the GDPR. This can lead to:

  • Administrative fines.
  • Liability for damages towards data subjects.
  • Damage to trust and brand.
  • The Data Protection Agency issuing a reprimand or an order to stop the processing in question.

No. Each processing operation must be tied to a single lawful basis. It is not permitted to “back up” the same processing with multiple bases. However, different bases may apply to different parts of an organisation’s processing activities.

Consent should be avoided when:

  • There is an imbalance in the relationship, for example between employer and employee.
  • It is not practically possible to offer a genuinely free choice.
  • It is difficult to manage withdrawal in practice.

In these cases, it is better to consider other bases such as contract, legal obligation or legitimate interests.

For example, Morling Consulting may:

  • Analyse which lawful bases are suitable for specific processing within an organisation.
  • Prepare documentation for legitimate interests assessments.
  • Support the development of internal guidelines, templates and information for data subjects.
  • Assist with reviews ahead of new projects, systems or collaborations involving personal data.

Our advice is always tailored to your organisation’s needs, risk profile and legal context.

Contact us

If you prefer phone, please feel free to contact Felix Morling at +46 70 444 42 85

"*" indicates required fields