Artifact GuideUKLawful Bases

UK GDPR Lawful Bases

Choose the Article 6 lawful basis that fits the purpose and facts of each processing operation before the processing starts. Do not default to consent or legitimate interests.

A lawful basis does not remove the other UK GDPR duties. Special category data, criminal offence data, electronic marketing, and cookies can require separate conditions or rules.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Choose a for each distinct processing purpose before collecting or using personal data. Since 5 February 2026, Article 6 of the UK GDPR has seven bases: consent, contract, legal obligation, vital interests, public task, , and . Record why the selected basis applies, why the processing is necessary, and which additional data or sector rules apply.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How should a controller choose among the seven bases?

Start with the purpose, the controller's relationship with the person, and the legal or practical reason the processing is needed. Contract applies only where processing is objectively necessary to perform a contract with the person or take requested pre-contract steps. Legal obligation needs a duty imposed by UK law. Vital interests is narrow and protects a person's life. Public task requires a task in the public interest or official authority laid down by law.

Use consent only when the person has a genuine choice and can withdraw without detriment. Use ordinary only after the purpose, necessity, and balancing tests. Use only when every requirement of a specific Annex 1 condition is met; unlike ordinary legitimate interests, it does not require a separate balancing test.

  • Describe each purpose precisely. One system may need different bases for account delivery, fraud prevention, analytics, and marketing.
  • Test necessity: if a less intrusive reasonable method achieves the purpose, a necessity-based basis may not fit.
  • Do not treat contract terms or a privacy notice as proof that processing is necessary for a contract or legal obligation.
  • Tell people the and purpose in the privacy information, subject to any applicable exception.
Citations
ICO - A guide to lawful basis

Explains when each Article 6 basis may apply, the need to choose before processing, necessity, documentation, and privacy information.

Question 2

What additional checks are required?

Article 6 is only the first layer. Processing special category data also needs an Article 9 condition. Processing criminal offence data must satisfy Article 10 and usually a condition in the Data Protection Act 2018. If the activity uses cookies or similar storage and access technologies, PECR may require consent even where another UK GDPR basis might otherwise appear available.

The selected basis also changes the rights analysis. For example, the right to data portability is tied to consent or contract and automated processing, while the right to object is particularly relevant to public task and . No overrides fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, or accountability.

  • Record any Article 9 condition, Data Protection Act 2018 Schedule 1 condition, or Article 10 authority separately from the Article 6 basis.
  • Check PECR before the UK GDPR when storing information on or accessing information from a user's device.
  • Assess children's reasonable expectations and interests with extra care, especially under .
  • Complete a DPIA where the proposed processing is likely to result in a high risk to people's rights and freedoms.
Citations
ICO - Special category data

Explains that special category processing needs both an Article 6 lawful basis and an Article 9 condition, with further DPA 2018 requirements for some conditions.

Question 3

What evidence should the controller keep?

Keep a decision record that identifies the controller, data and people affected, each purpose, the chosen basis, the facts supporting it, the necessity analysis, and the approval date. Add the relevant contract clause, legal provision, consent record, public-task authority, Annex 1 condition, or assessment rather than relying on a label alone.

Update the record and privacy information when the purpose or processing changes. A controller should not switch basis after processing has started merely because the original choice became inconvenient. A genuine change in circumstances may justify a different basis, but the controller must document the change, assess fairness, and tell people where required.

  • Map every processing purpose in the record of processing activities to its Article 6 basis.
  • For consent, retain what the person saw, the affirmative action, the time, the scope, and any withdrawal.
  • For , name the Annex 1 condition and show how every element and the necessity test are met.
  • For , retain the purpose, necessity, and balancing assessment and the safeguards adopted.
Citations
Primary sources

References and citations

ico.org.uk
Referenced sections
  • Explains documentation, transparency, review, and the limits on changing a lawful basis after processing begins.
ico.org.uk
Referenced sections
  • Explains the Article 10 safeguards and DPA 2018 conditions for processing criminal offence data.
ico.org.uk
Referenced sections
  • Explains that PECR must be considered first for storage and access technologies and how PECR consent affects the UK GDPR basis.
ico.org.uk
Referenced sections
  • Explains the five Annex 1 conditions, necessity test, limits for public authorities, and difference from ordinary legitimate interests.
ico.org.uk
Referenced sections
  • Explains that special category processing needs both an Article 6 lawful basis and an Article 9 condition, with further DPA 2018 requirements for some conditions.
legislation.gov.uk
Referenced sections
  • Sets out the binding Article 6 lawful bases and the restriction on public authorities using Article 6(1)(ea) or (f) when performing their tasks.
Related guides

Explore more topics

UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.