Article 6 asks a concrete question: what authorises this specific processing purpose?
It does not ask which basis sounds safest. Consent is not automatically stronger than contract or legal obligation. The choice affects what you must tell people, which rights apply, how long you can keep data, and whether the processing can continue after an objection or withdrawal.
The six bases
Article 6(1) of the GDPR provides:
| Basis | Use it when | Evidence to keep |
|---|---|---|
| Consent | The person makes a freely given, specific, informed, unambiguous choice | What they saw, the action, time, scope, and withdrawal |
| Contract | Processing is objectively necessary to perform a contract with the person or take requested pre-contractual steps | Contract or request and necessity analysis |
| Legal obligation | EU or Member State law requires the controller to process | The applicable provision and required fields or period |
| Vital interests | Processing is necessary to protect a person’s life or another vital interest | Emergency context and why another basis was unavailable |
| Public task | Processing is necessary for an official-authority or public-interest task laid down by law | The legal basis and defined task |
| Legitimate interests | A controller’s or third party’s legitimate purpose is necessary and not overridden by the person’s interests or rights | Purpose, necessity, balancing, safeguards, and objection handling |
Public authorities cannot rely on legitimate interests for processing performed in their tasks. Member State law also shapes legal-obligation and public-task uses.
A decision sequence
- Define the purpose without combining unrelated outcomes.
- Identify the minimum data and operations needed.
- Check whether a law requires or authorises the operation.
- Check whether it is objectively necessary for a contract with the person.
- If consent is proposed, test whether refusal is a genuine option.
- If legitimate interests are proposed, document purpose, necessity, balancing, reasonable expectations, safeguards, and objection handling.
- Record the decision before processing.
Do not switch bases silently after collection because the original choice became inconvenient. The EDPB’s SME lawful-basis guide summarises the decision and stresses that the basis must be identified before processing.
Frequent category errors
- Contract means useful to the business. It does not. The operation must be objectively necessary for the requested contract, not merely placed in the terms.
- Consent is an acceptance of the privacy policy. A notice supplies information. Consent is a choice about a specified processing purpose.
- Legitimate interests means anything beneficial. It requires necessity and balancing, with particular attention to reasonable expectations and impact.
- A legal requirement exists somewhere. Identify the precise EU or Member State provision.
- Article 6 covers health data. Special-category processing also needs an Article 9 condition.
- One basis covers the company. Select by purpose and, where necessary, by operation.
Connect the basis to controls
Put the basis in the processing record and privacy notice. Configure the product around it:
- consent needs granular controls and withdrawal;
- contract needs data limited to delivery;
- legal obligation needs the statutory scope and retention;
- legitimate interests needs an objection route and review when context changes.
An unsupported basis can make the processing unlawful even if the privacy notice is beautifully written.
GDPR.Direct can help structure the record and draft public information from your selected bases. It does not determine which basis applies from a feature name. For contested, high-impact, special-category, children’s, or monitoring activities, obtain qualified review.
This article is educational information, not legal advice.