Personal data is collected for specified, explicit, and legitimate purposes. A later use must not simply appear because the data is available.
That does not mean every new use always requires consent. The correct path depends on the original basis, the source of authority for the new use, and whether the new purpose is compatible with the original one.
Start with the original record
Write down:
- the original purpose in operational terms;
- the lawful basis used for it;
- what the person was told;
- the data and context of collection;
- the Article 9 condition, where relevant; and
- any contractual, professional, or confidentiality restrictions.
If the original purpose was described vaguely, do not treat that wording as permission for unlimited reuse. Article 5(1)(b) of the GDPR is intended to make purposes specific and predictable.
Identify the legal route for the later use
Processing for archiving in the public interest, scientific or historical research, or statistical purposes receives specific treatment under Article 5(1)(b), subject to Article 89 safeguards.
For another new purpose:
- if the person gave valid consent for the new use, check that the consent is specific and can be withdrawn;
- if Union or Member State law provides the new purpose and meets Article 23 conditions, analyse that law; or
- otherwise apply the compatibility test in Article 6(4).
The compatibility test does not eliminate the need for a lawful basis. It answers whether further processing may be compatible; the controller must still identify and document the basis for the new operation.
Apply the Article 6(4) compatibility test
Consider all of these factors:
- Link between purposes. Is the later use a reasonably connected extension, or a different objective?
- Collection context. What relationship and expectations existed between the person and controller?
- Nature of the data. Does it include Article 9 special categories or Article 10 criminal-offence data?
- Consequences. Could the later use affect access, price, reputation, employment, health, or another important interest?
- Safeguards. Can pseudonymisation, aggregation, access limits, an opt-out, or separation reduce the risk?
Document the facts and conclusion. A sentence saying “compatible purpose” is not an assessment.
Examples
| Proposed reuse | Key issue |
|---|---|
| Use support tickets to fix the reported bug | Often closely linked, but remove unrelated personal details and control access |
| Add account emails to marketing | Electronic-marketing rules and the person’s expectations require a separate analysis |
| Train an AI model on customer documents | Different purpose, provider role, confidentiality, consequences, and opt-out all need review |
| Produce anonymous aggregate reliability statistics | Verify anonymisation rather than assuming aggregation is enough |
| Screen old customer data for fraud | Define the threat, necessity, impact, retention, and objection position |
If the later use is incompatible and no consent or legal provision authorises it, do not proceed with the existing data. Collect new data transparently under an appropriate basis, redesign the feature, or abandon the purpose.
Update the person before the new use
Articles 13(3) and 14(4) require the controller to provide information about a further purpose before processing for it. Update the notice and any just-in-time explanation. Also update the processing record, retention rule, processor terms, DPIA, and rights workflow where relevant.
GDPR.Direct can help update an editable notice draft. It cannot decide compatibility from a short label. Keep the written assessment and seek qualified review for high-impact, unexpected, special-category, or AI-related reuse.
This article is educational information, not legal advice.