Back to GDPR Hub
Data ProcessingAugust 2, 2026

The Six Lawful Bases Under the GDPR and How to Choose the Right One

If you run an agency, a SaaS product, or any modern business in the EU, you already know you can't just collect personal data because you feel like it. You need a "legal reason" to do so. Under the General Data Protection Regulation (GDPR), that reason is called a lawful basis.

There are six lawful bases GDPR provides. You've probably seen the list. But if you're like most founders and marketing managers, mapping those six abstract legal concepts to your actual day-to-day business activities—like sending a newsletter, processing a payment, or tracking website analytics—feels like throwing darts in the dark.

This isn't another legal textbook recitation of Article 6 of the GDPR. You don't need legalese; you need a decision framework. In this post, we'll break down exactly what each GDPR lawful basis means in plain English, provide concrete examples for when to use them, and show you how to avoid the most common trap businesses fall into: asking for consent when they shouldn't.

Why the Lawful Basis Matters Beyond Compliance

Picking a lawful basis isn't just about avoiding a fine. It's the foundational block of your entire data strategy. Here is why you need to get this right:

  1. You have to pick before you start processing: You cannot collect data first and figure out your lawful basis later. The basis must be established before the data is collected.
  2. You cannot easily switch: If you choose one lawful basis and it later turns out to be invalid, you can't just swap it out for another one retroactively. If you get it wrong, every piece of data you collected under that incorrect basis is potentially unlawful and might need to be deleted.
  3. It dictates data subject rights: The lawful basis you choose determines which rights your users have. For example, if you rely on consent, the user has the absolute right to have their data erased (the "right to be forgotten"). If you rely on a legal obligation, they don't.
  4. It lives in your documentation: Your lawful basis isn't just a mental note. It must be explicitly documented in your Privacy Policy and your Record of Processing Activities (ROPA).

Let's dive into the six lawful bases under the GDPR and how to apply them.

The Six Lawful Bases GDPR Provides

1. Consent

What it actually means: Consent is the gold standard for transparency, but it comes with the heaviest operational burden. For consent to be valid under the GDPR, it must be freely given, specific, informed, and unambiguous. It usually requires a clear affirmative action (like ticking an unchecked box). Crucially, the user must be able to withdraw their consent at any time, just as easily as they gave it.

Concrete business example:

  • Do use it for: Newsletter signups, non-essential marketing cookies (like Facebook Pixel or Google Analytics), or selling data to third parties.
  • Don't use it for: Processing a customer's payment or delivering the core service they just bought.

The Reality Check: If a user withdrawing their consent would break your service or make it impossible for you to fulfill a contract, consent was the wrong lawful basis. Never ask for consent if you aren't prepared to take "no" for an answer or if you're going to process the data anyway.

2. Contractual Necessity

What it actually means: You need to process the personal data to fulfill a contract with the data subject, or because they asked you to do something before entering into a contract (like providing a quote).

Concrete business example:

  • Do use it for: Processing a credit card for an e-commerce order, taking a shipping address to deliver a physical product, or holding an email address to provide access to your SaaS platform.
  • Don't use it for: You cannot stretch "contractual necessity" to cover marketing, profiling, or product analytics just because someone happens to be a paying customer.

The Reality Check: Ask yourself: Could I still deliver the core service promised in the contract without this specific piece of data? If the answer is yes, you cannot use contractual necessity for that data.

3. Legal Obligation

What it actually means: You are required by a specific law (EU or Member State law) to process the personal data. You don't have a choice in the matter.

Concrete business example:

  • Do use it for: Keeping employee tax records, financial reporting, complying with anti-money laundering (AML) regulations, or responding to a valid court order.
  • Don't use it for: "Industry best practices" or obligations under a contract with a third party. It must be a statutory legal requirement.

The Reality Check: This one is straightforward but narrow. If a government auditor or inspector asked why you have this data, could you point to a specific statute? If yes, this is your basis.

4. Legitimate Interest

What it actually means: Legitimate interest is the most flexible lawful basis, but also the most abused. It allows you to process personal data without consent, provided your business interests are not overridden by the fundamental rights and freedoms of the individual.

To use it, you must perform a three-part balancing test called a Legitimate Interest Assessment (LIA):

  1. Purpose test: Are you pursuing a legitimate interest? (e.g., growing your business, preventing fraud).
  2. Necessity test: Is the processing necessary for that purpose? (Could you achieve the goal with less data or in a less intrusive way?)
  3. Balancing test: Do the individual's interests override your legitimate interest? (Would they reasonably expect this processing, and does it cause them unjustified harm?)

Concrete business example:

  • Do use it for: B2B cold email outreach (where permitted by national ePrivacy laws), direct marketing to your existing customers about similar products, fraud prevention, and network security.
  • Don't use it for: Intrusive profiling, tracking users across the web, or anything that would genuinely surprise or creep out the data subject.

The Reality Check: Let's look at an LIA for B2B cold email outreach:

  • Interest: You want to sell your agency services to other businesses.
  • Necessity: You need to process their professional email address to contact them.
  • Balancing: As a B2B professional, receiving a relevant business pitch to a corporate email address is within reasonable expectations and poses minimal risk to their fundamental rights (provided you offer an easy opt-out). Note: The outcome of this balancing test can vary significantly by jurisdiction because national ePrivacy rules layer on top. For instance, Germany's UWG makes unsolicited B2B email much harder than in the UK or Netherlands, meaning an LIA alone won't automatically legalize your outreach there.

5. Vital Interests

What it actually means: You need to process the personal data to protect someone's life.

Concrete business example:

  • Do use it for: Providing a patient's medical history to a hospital during a life-threatening emergency when they are unconscious.
  • Don't use it for: Practically anything else.

The Reality Check: If you run an agency, a marketing firm, or a B2B SaaS, it is almost guaranteed you will never use this lawful basis. We mention it only so you know all six.

6. Public Task

What it actually means: You are processing data to carry out a specific task in the public interest or exercising official authority vested in you.

Concrete business example:

  • Do use it for: Government bodies processing tax returns, public schools keeping student records, or private companies exercising delegated state authority (like a private water company).
  • Don't use it for: Standard commercial activities.

The Reality Check: Like Vital Interests, this is generally not relevant for private, commercial businesses.

The Consent Trap: When Legitimate Interest is Better

Many agencies and small businesses fall into what we call the "Consent Trap." Because consent feels like the most polite and compliant option, they try to use it for everything.

In reality, defaulting to consent creates massive operational headaches:

  • You have to build systems to track exactly when and how consent was given.
  • You have to build mechanisms to allow users to easily withdraw it.
  • You have to periodically refresh it.
  • Crucially, consent is fragile. If a user withdraws their consent, you must immediately stop processing their data and often delete it. One withdrawn consent can break an entire workflow.

If you are processing data for network security, fraud prevention, or direct B2B marketing (where local laws allow), Legitimate Interest is often the far more appropriate choice. It accurately reflects the reality of the situation: you are running a business, you have a valid reason to process the data, you've ensured it doesn't harm the user, and you aren't pretending the user has absolute veto power over your internal security logs.

Don't ask for permission if you don't actually need it—rely on Legitimate Interest and document your LIA instead.

How This Connects to Your ROPA

Choosing the right GDPR lawful basis isn't just a mental exercise; it's a documentation requirement.

Under Article 30 of the GDPR, businesses must maintain a Record of Processing Activities (ROPA). Your ROPA is essentially an inventory of what data you collect, why you collect it, where it goes, and—crucially—the lawful basis for each activity.

Every single row in your ROPA needs a documented lawful basis. If you're using Legitimate Interest, your ROPA should reference the LIA you performed. If you can't articulate which of the six lawful bases applies to a specific processing activity, that activity is non-compliant and must be stopped.

Need help setting this up? Check out our guide on what a ROPA is and how to build one.

The Bottom Line

You don't need a law degree to map out your lawful bases. You just need to look critically at why you are collecting data and choose the basis that reflects reality.

  • Are they buying something? Contractual Necessity.
  • Are you legally required to have it? Legal Obligation.
  • Do you genuinely need their explicit permission for a non-essential activity? Consent.
  • Are you pursuing a valid business goal that doesn't harm them? Legitimate Interest.

If you're an agency operator looking at the broader picture of your compliance posture, mapping your lawful bases is step one. (For the rest of the steps, read our full GDPR compliance guide for agencies).

Find out your GDPR score

As part of our compliance scoring, Custodia's gap assessment automatically checks whether your processing activities have documented lawful bases.

Take free assessment